Backport patches for the following Bugzilla security bugs: https://bugzilla.mozilla.org/show_bug.cgi?id=1074812 CVE-2014-1572 https://bugzilla.mozilla.org/show_bug.cgi?id=1075578 CVE-2014-1573 https://bugzilla.mozilla.org/show_bug.cgi?id=1064140 CVE-2014-1571 https://bugzilla.mozilla.org/show_bug.cgi?id=1054702
Created attachment 239497 [details] Patch
Comment on attachment 239497 [details] Patch Looks sane to me.
Rescoping this bug - we're going to upgrade straight to 4.2.11, which will include the above
We've tested 4.2 database migration and most of the WebKit-specific stuff works, with one exception: there is a quick search form leaking onto the PrettyPatch review page, which causes a harmless but annoying JS alert that you're trying to search for the empty string, although changes to the review go through. That will be fixed before uploading a patch for review.
We'll do more stress testing on the test instance, of course.
Already completed - https://lists.webkit.org/pipermail/webkit-dev/2014-October/026946.html