SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for firefox-esr-10.0.6-1.1.x86_64.rpm :
Sat Jul 14 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.6esr (bnc#771583)

* MFSA 2012-42/CVE-2012-1948
Miscellaneous memory safety hazards

* MFSA 2012-43/CVE-2012-1950
Incorrect URL displayed in addressbar through drag and drop

* MFSA 2012-44/CVE-2012-1951/CVE-2012-1954/CVE-2012-1953/CVE-2012-1952
Gecko memory corruption

* MFSA 2012-45/CVE-2012-1955 (bmo#757376)
Spoofing issue with location

* MFSA 2012-46/CVE-2012-1966 (bmo#734076)
XSS through data: URLs

* MFSA 2012-47/CVE-2012-1957 (bmo#750096)
Improper filtering of javascript in HTML feed-view

* MFSA 2012-48/CVE-2012-1958 (bmo#750820)
use-after-free in nsGlobalWindow::PageHidden

* MFSA 2012-49/CVE-2012-1959 (bmo#754044, bmo#737559)
Same-compartment Security Wrappers can be bypassed

* MFSA 2012-51/CVE-2012-1961 (bmo#761655)
X-Frame-Options header ignored when duplicated

* MFSA 2012-52/CVE-2012-1962 (bmo#764296)
JSDependentString::undepend string conversion results in memory
corruption

* MFSA 2012-53/CVE-2012-1963 (bmo#767778)
Content Security Policy 1.0 implementation errors cause data
leakage

* MFSA 2012-54/CVE-2012-1964 (bmo#633691)
Clickjacking of certificate warning page

* MFSA 2012-55/CVE-2012-1965 (bmo#758990)
feed: URLs with an innerURI inherit security context of page

* MFSA 2012-56/CVE-2012-1967 (bmo#758344)
Code execution through javascript: URLs
- require NSS 3.13.5

Fri Jun 1 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.5esr (bnc#765204)

* MFSA 2012-34/CVE-2012-1939/CVE-2012-1937/CVE-2011-3101
Miscellaneous memory safety hazards

* MFSA 2012-36/CVE-2012-1944 (bmo#751422)
Content Security Policy inline-script bypass

* MFSA 2012-37/CVE-2012-1945 (bmo#670514)
Information disclosure though Windows file shares and shortcut
files

* MFSA 2012-38/CVE-2012-1946 (bmo#750109)
Use-after-free while replacing/inserting a node in a document

* MFSA 2012-40/CVE-2012-1947/CVE-2012-1940/CVE-2012-1941
Buffer overflow and use-after-free issues found using Address
Sanitizer
- require NSS 3.13.4

* MFSA 2012-39/CVE-2012-0441 (bmo#715073)

Sat Apr 21 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.4esr (bnc#758408)

* MFSA 2012-20/CVE-2012-0467/CVE-2012-0468
Miscellaneous memory safety hazards

* MFSA 2012-22/CVE-2012-0469 (bmo#738985)
use-after-free in IDBKeyRange

* MFSA 2012-23/CVE-2012-0470 (bmo#734288)
Invalid frees causes heap corruption in gfxImageSurface

* MFSA 2012-24/CVE-2012-0471 (bmo#715319)
Potential XSS via multibyte content processing errors

* MFSA 2012-25/CVE-2012-0472 (bmo#744480)
Potential memory corruption during font rendering using cairo-dwrite

* MFSA 2012-26/CVE-2012-0473 (bmo#743475)
WebGL.drawElements may read illegal video memory due to
FindMaxUshortElement error

* MFSA 2012-27/CVE-2012-0474 (bmo#687745, bmo#737307)
Page load short-circuit can lead to XSS

* MFSA 2012-29/CVE-2012-0477 (bmo#718573)
Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues

* MFSA 2012-30/CVE-2012-0478 (bmo#727547)
Crash with WebGL content using textImage2D

* MFSA 2012-31/CVE-2011-3062 (bmo#739925)
Off-by-one error in OpenType Sanitizer

* MFSA 2012-33/CVE-2012-0479 (bmo#714631)
Potential site identity spoofing when loading RSS and Atom feeds
- this package replaces MozillaFirefox for distributions older
than 11.3

Sun Mar 4 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.3esr (bnc#750044)

* added mozilla-system-nss.patch (bmo#710268)
- changed package name to firefox-esr
- require updated minimal NSPR and NSS versions
- ported and reenabled KDE integration (bnc#746591)
- explicitely build-require X libs

Fri Feb 17 13:00:00 2012 pcernyAATTsuse.com
- better plugin directory resolution (bnc#747320)

Thu Feb 16 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.2 (bnc#747328)

* CVE-2011-3026 (bmo#727401)
libpng: integer overflow leading to heap-buffer overflow

Thu Feb 9 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.1 (bnc#746616)

* MFSA 2012-10/CVE-2012-0452 (bmo#724284)
use after free in nsXBLDocumentInfo::ReadPrototypeBindings

Tue Feb 7 13:00:00 2012 dvaleevAATTsuse.com
- Use YARR interpreter instead of PCRE on platforms where YARR JIT
is not supported, since PCRE doesnt build (bmo#691898)
- fix ppc64 build (bmo#703534)

Mon Jan 30 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0 (bnc#744275)

* MFSA 2012-01/CVE-2012-0442/CVE-2012-0443
Miscellaneous memory safety hazards

* MFSA 2012-03/CVE-2012-0445 (bmo#701071)