* Sat Nov 12 2011 dvaleevAATTsuse.com- fix ppc64 build * Sun Nov 06 2011 wrAATTrosenauer.org- update to Firefox 8 (bnc#728520) * MFSA 2011-47/CVE-2011-3648 (bmo#690225) Potential XSS against sites using Shift-JIS * MFSA 2011-48/CVE-2011-3651/CVE-2011-3652/CVE-2011-3654 Miscellaneous memory safety hazards * MFSA 2011-49/CVE-2011-3650 (bmo#674776) Memory corruption while profiling using Firebug * MFSA 2011-52/CVE-2011-3655 (bmo#672182) Code execution via NoWaiverWrapper- rebased patches * Thu Oct 20 2011 wrAATTrosenauer.org- enable telemetry prompt * Fri Sep 30 2011 wrAATTrosenauer.org- update to minor release 7.0.1 * fixed staged addon updates- set intl.locale.matchOS=true in the base package as it causes too much confusion when it\'s only available with branding-openSUSE * Fri Sep 23 2011 wrAATTrosenauer.org- update to Firefox 7 (bnc#720264) including * Improve Responsiveness with Memory Reductions * Instant Sync * WebSocket protocol 8 * MFSA 2011-36/CVE-2011-2995/CVE-2011-2996/CVE-2011-2997 Miscellaneous memory safety hazards * MFSA 2011-39/CVE-2011-3000 (bmo#655389) Defense against multiple Location headers due to CRLF Injection * MFSA 2011-40/CVE-2011-2372/CVE-2011-3001 Code installation through holding down Enter * MFSA 2011-41/CVE-2011-3002/CVE-2011-3003 (bmo#680840, bmo#682335) Potentially exploitable WebGL crashes * MFSA 2011-42/CVE-2011-3232 (bmo#653672) Potentially exploitable crash in the YARR regular expression library * MFSA 2011-43/CVE-2011-3004 (bmo#653926) loadSubScript unwraps XPCNativeWrapper scope parameter * MFSA 2011-44/CVE-2011-3005 (bmo#675747) Use after free reading OGG headers * MFSA 2011-45 Inferring keystrokes from motion data- removed obsolete mozilla-cairo-lcd.patch- rebased patches- removed XLIB_SKIP_ARGB_VISUALS=1 from environment in mozilla.sh.in (bnc#680758) * Fri Sep 16 2011 wrAATTrosenauer.org- fixed loading of kde.js under KDE (bnc#718311) * Wed Sep 14 2011 wrAATTrosenauer.org- add dbus-1-glib-devel to BuildRequires (not pulled in automatically anymore on 12.1)- increase minversions for NSPR and NSS * Fri Sep 09 2011 wrAATTrosenauer.org- recreated source archive to get correct source-stamp.txt * Wed Sep 07 2011 pcernyAATTsuse.com- security update to 6.0.2 (bnc#714931) * Complete blocking of certificates issued by DigiNotar (bmo#683449) * Fri Sep 02 2011 pcernyAATTsuse.com- security update to 6.0.1 (bnc#714931) * MFSA 2011-34 Protection against fraudulent DigiNotar certificates (bmo#682927) * Fri Aug 12 2011 wrAATTrosenauer.org- update to 6.0 (bnc#712224) included security fixes MFSA 2011-29 * CVE-2011-2989/CVE-2011-2991/CVE-2011-2992/CVE-2011-2985 Miscellaneous memory safety hazards * CVE-2011-2993 (bmo#657267) Unsigned scripts can call script inside signed JAR * CVE-2011-2988 (bmo#665934) Heap overflow in ANGLE library * CVE-2011-0084 (bmo#648094) Crash in SVGTextElement.getCharNumAtPosition() * CVE-2011-2990 Credential leakage using Content Security Policy reports * CVE-2011-2986 (bmo#655836) Cross-origin data theft using canvas and Windows D2D- removed obsolete curl header dependency (mozilla-curl.patch) * Fri Jul 22 2011 wrAATTrosenauer.org- update to 6.0b3 * removed obsolete patches - firefox-shellservice.patch - mozilla-gio.patch - mozilla-ppc-ipc.patch - firefox-linkorder.patch - firefox-no-sync-l10n.patch- recognize linux3 as platform for symbolstore.py * Fri Jul 01 2011 vuntzAATTopensuse.org- Add x-scheme-handler/ftp to the MimeType key in the .desktop, to let desktops know that Firefox can deal with ftp: URIs. * Fri Jul 01 2011 wrAATTrosenauer.org- create upstream branding package again (supposedly empty) (bnc#703401)- fix build on SLE11 (changes do not affect/are not applied for later versions) * Wed Jun 22 2011 wrAATTrosenauer.org- enable startup notification (bnc#701465) * Mon Jun 20 2011 wrAATTrosenauer.org- update to 5.0 final- included fixes for security issues: (bnc#701296, bnc#700578) * MFSA 2011-19/CVE-2011-2374 CVE-2011-2375 Miscellaneous memory safety hazards * MFSA 2011-20/CVE-2011-2373 (bmo#617247) Use-after-free vulnerability when viewing XUL document with script disabled * MFSA 2011-21/CVE-2011-2377 (bmo#638018, bmo#639303) Memory corruption due to multipart/x-mixed-replace images * MFSA 2011-22/CVE-2011-2371 (bmo#664009) Integer overflow and arbitrary code execution in Array.reduceRight() * MFSA 2011-25/CVE-2011-2366 Stealing of cross-domain images using WebGL textures * MFSA 2011-26/CVE-2011-2367 CVE-2011-2368 Multiple WebGL crashes * MFSA 2011-27/CVE-2011-2369 (bmo#650001) XSS encoding hazard with inline SVG * MFSA 2011-28/CVE-2011-2370 (bmo#645699) Non-whitelisted site can trigger xpinstall * Mon Jun 20 2011 wrAATTrosenauer.org- update to 5.0b7 * updated supported locales- do not build dump_syms static (not needed for us) - > fix build for openSUSE 12.1 and above * Wed Jun 15 2011 wrAATTrosenauer.org- update to 5.0b6- include proper revision information into the build- speedier find-external-requires.sh * Tue May 31 2011 wrAATTrosenauer.org- update to 5.0b3- transformed to standalone Firefox (not xulrunner based) (with new Firefox rapid release cycle it makes no sense anymore) * imported all relevant xulrunner patches- do not compile in build timestamp * Fri Apr 15 2011 wrAATTrosenauer.org- security update to 4.0.1 (bnc#689281) * MFSA 2011-12/ CVE-2011-0069 CVE-2011-0070 CVE-2011-0079 CVE-2011-0080 CVE-2011-0081 Miscellaneous memory safety hazards * MFSA 2011-17/CVE-2011-0068 (bmo#623791) WebGLES vulnerabilities * MFSA 2011-18/CVE-2011-1202 (bmo#640339) XSLT generate-id() function heap address leak * Wed Mar 30 2011 wrAATTrosenauer.org- add all available icon sizes * Tue Mar 29 2011 cfarrellAATTnovell.com- license update: MPLv1.1 or GPLv2+ or LGPLv2+ Sync licenses with Fedora. MPL does not state ^or later^ * Fri Mar 18 2011 wrAATTrosenauer.org- update to version 4.0rc2- fixed rpm macros delivered with devel package (bnc#679950) * Wed Feb 23 2011 wrAATTrosenauer.org- update to version 4.0b12- rebased patches * Fri Feb 04 2011 wrAATTrosenauer.org- update to version 4.0b11 * loads of bugfixes compared to last beta * added \"Do Not Track\" option- rebased patches- disable testpilot * Fri Jan 28 2011 wrAATTrosenauer.org- set correct desktop file name within KDE for 11.4 and up- add devel package with macros for extensions (from lnusselAATTsuse.de) * Sat Jan 22 2011 wrAATTrosenauer.org- update to version 4.0b10- removed obsolete firefox-shell-bmo624267.patch- testpilot moved to distribution/extensions- updated locale provides and removed bn-IN from locales * Tue Jan 11 2011 wrAATTrosenauer.org- update to version 4.0b9- added x-scheme-handler for http and https to desktop file for newer Gnome environments- fixed default browser check/set for GIO (bmo#611953) (mozilla-shellservice.patch)- removed obsolete firefox-appname.patch (integrated into shellservice patch)- renamed desktop file to firefox.desktop for 11.4 and newer (bnc#664211)- removed support for 10.3 and older from the spec file- removed obsolete \"Ximian\" categories from desktop file * Mon Jan 03 2011 meissnerAATTsuse.de- Mirror ac_add_options --disable-ipc from xulrunner for PowerPC. * Wed Dec 15 2010 wrAATTrosenauer.org- update to version 4.0beta8 * Tue Nov 30 2010 wrAATTrosenauer.org- major update to version 4.0beta7 * based on mozilla-xulrunner20 * far too many internal changes to list * Wed Oct 27 2010 wrAATTrosenauer.org- security update to 3.6.12 (bnc#649492) * MFSA 2010-73/CVE-2010-3765 (bmo#607222) Heap buffer overflow mixing document.write and DOM insertion * Wed Oct 06 2010 wrAATTrosenauer.org- security update to 3.6.11 (bnc#645315) * MFSA 2010-64/CVE-2010-3174/CVE-2010-3175/CVE-2010-3176 Miscellaneous memory safety hazards * MFSA 2010-65/CVE-2010-3179 (bmo#583077) Buffer overflow and memory corruption using document.write * MFSA 2010-66/CVE-2010-3180 (bmo#588929) Use-after-free error in nsBarProp * MFSA 2010-67/CVE-2010-3183 (bmo#598669) Dangling pointer vulnerability in LookupGetterOrSetter * MFSA 2010-68/CVE-2010-3177 (bmo#556734) XSS in gopher parser when parsing hrefs * MFSA 2010-69/CVE-2010-3178 (bmo#576616) Cross-site information disclosure via modal calls * MFSA 2010-70/CVE-2010-3170 (bmo#578697) SSL wildcard certificate matching IP addresses * MFSA 2010-71/CVE-2010-3182 (bmo#590753) Unsafe library loading vulnerabilities * MFSA 2010-72/CVE-2010-3173 Insecure Diffie-Hellman key exchange * Wed Sep 15 2010 wrAATTrosenauer.org- update to 3.6.10 * fixing startup topcrash (bmo#594699) * Thu Aug 26 2010 wrAATTrosenauer.org- security update to 3.6.9 (bnc#637303) * MFSA 2010-49/CVE-2010-3169 Miscellaneous memory safety hazards * MFSA 2010-50/CVE-2010-2765 (bmo#576447) Frameset integer overflow vulnerability * MFSA 2010-51/CVE-2010-2767 (bmo#584512) Dangling pointer vulnerability using DOM plugin array * MFSA 2010-53/CVE-2010-3166 (bmo#579655) Heap buffer overflow in nsTextFrameUtils::TransformText * MFSA 2010-54/CVE-2010-2760 (bmo#585815) Dangling pointer vulnerability in nsTreeSelection * MFSA 2010-55/CVE-2010-3168 (bmo#576075) XUL tree removal crash and remote code execution * MFSA 2010-56/CVE-2010-3167 (bmo#576070) Dangling pointer vulnerability in nsTreeContentView * MFSA 2010-57/CVE-2010-2766 (bmo#580445) Crash and remote code execution in normalizeDocument * MFSA 2010-59/CVE-2010-2762 (bmo#584180) SJOW creates scope chains ending in outer object * MFSA 2010-61/CVE-2010-2768 (bmo#579744) UTF-7 XSS by overriding document charset using