Partial fix for CVE-2015-4495/pdf.js in Jessie?

Moritz Mühlenhoff jmm at inutil.org
Sun Aug 16 08:49:54 UTC 2015


On Sat, Aug 15, 2015 at 11:27:34PM +0200, David Prévot wrote:
> Le 15/08/2015 12:29, Moritz Mühlenhoff a écrit :
> > On Wed, Aug 12, 2015 at 10:05:14PM +0200, David Prévot wrote:
> >> Le 12/08/2015 19:49, Moritz Mühlenhoff a écrit :
> >>
> >>> What is the use case of xul-ext-pdf.js, TTBOMK there is no other browser
> >>> in Debian capable of running Xul extensions other than Iceweasel?
> >>
> >> I honestly wonder (since it’s already built-in Iceweasel).
> > 
> > Rule of thumb: If you as the maintainer don't know the use case, get rid
> > of it :-)
> 
> Sure! Should the removal of the xul-ext-pdf.js binary happen via the
> security.d.o repository, or should I follow up with the release time?

Since it's broken with 38 anyway, please drop the binary package for the
8.2 point release.

Cheers,
        Moritz



More information about the pkg-mozilla-maintainers mailing list