SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for MozillaFirefox-31.4.0esr-21.14.x86_64.rpm :
Wed Jan 14 13:00:00 2015 pcernyAATTsuse.com
- update to Firefox 31.4.0 ESR (bsc#910669)

* MFSA 2015-01/CVE-2014-8634/CVE-2014-8635
(bmo#1109889, bmo#1111737, bmo#1026774, bmo#1027300,
bmo#1054538, bmo#1067473, bmo#1070962, bmo#1072130,
bmo#1072871, bmo#1098583)
Miscellaneous memory safety hazards (rv:35.0 / rv:31.4)

* MFSA 2015-03/CVE-2014-8638
(bmo#1080987)
sendBeacon requests lack an Origin header

* MFSA 2015-04/CVE-2014-8639
(bmo#1095859)
Cookie injection through Proxy Authenticate responses

* MFSA 2015-06/CVE-2014-8641
(bmo#1108455)
Read-after-free in WebRTC
- fix broken install scripts in some locales (bsc#909563)

Wed Dec 3 13:00:00 2014 pcernyAATTsuse.com
- update to Firefox 31.3.0 ESR (bnc#908009)

* MFSA 2014-83/CVE-2014-1587/CVE-2014-1588
(bmo#1042567, bmo#1072847, bmo#1079729, bmo#1080312,
bmo#1089207, bmo#1013001, bmo#1023158, bmo#1026037,
bmo#1037830, bmo#1048517, bmo#1064835, bmo#1073577,
bmo#1075546, bmo#1077687, bmo#1086842, bmo#1096026)
Miscellaneous memory safety hazards (rv:34.0 / rv:31.3)

* MFSA 2014-85/CVE-2014-1590
(bmo#1087633)
XMLHttpRequest crashes with some input streams

* MFSA 2014-87/CVE-2014-1592
(bmo#1088635)
Use-after-free during HTML5 parsing

* MFSA 2014-88/CVE-2014-1593
(bmo#1085175)
Buffer overflow while parsing media content

* MFSA 2014-89/CVE-2014-1594
(bmo#1074280)
Bad casting from the BasicThebesLayer to BasicContainerLayer
- removing merged patch disabling SSLv3 by default

Wed Oct 15 14:00:00 2014 pcernyAATTsuse.com
- update to Firefox 31.2.0 ESR (bnc#900941)

* MFSA 2014-74/CVE-2014-1574/CVE-2014-1575
(bmo#1001994, bmo#1011354, bmo#1018916, bmo#1020034,
bmo#1023035, bmo#1032208, bmo#1033020, bmo#1034230,
bmo#1061214, bmo#1061600, bmo#1064346, bmo#1072044,
bmo#1072174)
Miscellaneous memory safety hazards (rv:33.0/rv:31.2)

* MFSA 2014-75/CVE-2014-1576
(bmo#1041512)
Buffer overflow during CSS manipulation

* MFSA 2014-76/CVE-2014-1577
(bmo#1012609)
Web Audio memory corruption issues with custom waveforms

* MFSA 2014-77/CVE-2014-1578
(bmo#1063327)
Out-of-bounds write with WebM video

* MFSA 2014-79/CVE-2014-1581
(bmo#1068218)
Use-after-free interacting with text directionality

* MFSA 2014-81/CVE-2014-1585/CVE-2014-1586
(bmo#1062876, bmo#1062981)
Inconsistent video sharing within iframe

* MFSA 2014-82/CVE-2014-1583
(bmo#1015540)
Accessing cross-origin objects via the Alarms API
- SSLv3 is disabled by default. See README.POODLE for more
detailed information.

Fri Sep 5 14:00:00 2014 pcernyAATTsuse.com
- update to Firefox 31.1.0 (bnc#894370)

* MFSA 2014-67/CVE-2014-1553/CVE-2014-1554/CVE-2014-1562
(bmo#990247,bmo#995075,bmo#995704,bmo#1004480,bmo#1016519,
bmo#1022945,bmo#1027359,bmo#1033121,bmo#1035007,bmo#1037666,
bmo#1041148,bmo#1054359)
Miscellaneous memory safety hazards

* MFSA 2014-68/CVE-2014-1563 (bmo#1018524)
Use-after-free during DOM interactions with SVG

* MFSA 2014-69/CVE-2014-1564 (bmo#1045977)
Uninitialized memory use during GIF rendering

* MFSA 2014-70/CVE-2014-1565 (bmo#1047831)
Out-of-bounds read in Web Audio audio timeline

* MFSA 2014-72/CVE-2014-1567 (bmo#1037641)
Use-after-free setting text directionality
- require NSPR 4.10.7/NSS 3.16.4

Wed Aug 20 14:00:00 2014 behlertAATTsuse.de
- adapted _constraints, used more than 3900MB on s390x during
last build

Thu Jul 17 14:00:00 2014 pcernyAATTsuse.com
- update to Firefox 31.0.0 ESR (bnc#887746)

* MFSA 2014-56/CVE-2014-1547/CVE-2014-1548
Miscellaneous memory safety hazards

* MFSA 2014-61/CVE-2014-1555 (bmo#1023121)
Use-after-free with FireOnStateChange event

* MFSA 2014-62/CVE-2014-1556 (bmo#1028891)
Exploitable WebGL crash with Cesium JavaScript library

* MFSA 2014-63/CVE-2014-1544 (bmo#963150)
Use-after-free while when manipulating certificates in the
trusted cache
(solved with NSS 3.16.3 requirement)

* MFSA 2014-64/CVE-2014-1557 (bmo#913805)
Crash in Skia library when scaling high quality images
- require NSS 3.16.3

Fri Jun 13 14:00:00 2014 pcernyAATTsuse.com
- update to Firefox 31 beta 6
- require NSS 3.16.1

Mon Apr 28 14:00:00 2014 pcernyAATTsuse.com
- update to Firefox 30 beta 8
- requires NSS 3.16
- removed obsolete patches

* firefox-browser-css.patch

* mozilla-aarch64-599882cfb998.diff

* mozilla-aarch64-bmo-963028.patch

* mozilla-aarch64-bmo-963029.patch

* mozilla-aarch64-bmo-963030.patch

* mozilla-aarch64-bmo-963031.patch
- added mozilla-icu-strncat.patch to fix post build checks

Mon Apr 7 14:00:00 2014 dmuellerAATTsuse.com
- add mozilla-aarch64-599882cfb998.patch,
mozilla-aarch64-bmo-810631.patch,
mozilla-aarch64-bmo-962488.patch,
mozilla-aarch64-bmo-963030.patch,
mozilla-aarch64-bmo-963027.patch,
mozilla-aarch64-bmo-963028.patch,
mozilla-aarch64-bmo-963029.patch,
mozilla-aarch64-bmo-963023.patch,
mozilla-aarch64-bmo-963024.patch,
mozilla-aarch64-bmo-963031.patch: AArch64 porting

Mon Mar 31 14:00:00 2014 dvaleevAATTsuse.com
- Fix MozillaFirefox builds for ppc64 and ppc64le
- added patches:

* mozilla-ppc64-xpcom.patch
- modified patches:

* mozilla-ppc64le-xpcom.patch

Sun Mar 16 13:00:00 2014 pcernyAATTsuse.com
- update to Firefox 28.0 (bnc#868603)
- requires NSPR 4.10.4 and NSS 3.15.5
- new build dependency:

* libpulse
- update of PowerPC 64 patches (bmo#976648)
- rebased patches

Tue Mar 4 13:00:00 2014 dvaleevAATTsuse.com
- Refresh patch to fit Firefox27 build system
- modified patches:

* mozilla-ppc64le-xpcom.patch

Fri Feb 28 13:00:00 2014 pcernyAATTsuse.com
- update to Firefox 27.0.1

* Fixed stability issues with Greasemonkey and other JS that used
ClearTimeoutOrInterval

* JS math correctness issue (bnc#941381)
- incorporate Google API key for geolocation (bnc#864170)
- updated list of \"other\" locales in RPM requirements
- update of PowerPC 64 patches (bmo#976648)

Tue Jan 28 13:00:00 2014 wrAATTrosenauer.org
- update to Firefox 27.0 (bnc#861847)

* MFSA 2014-01/CVE-2014-1477/CVE-2014-1478
Miscellaneous memory safety hazards (rv:27.0 / rv:24.3)

* MFSA 2014-02/CVE-2014-1479 (bmo#911864)
Clone protected content with XBL scopes

* MFSA 2014-03/CVE-2014-1480 (bmo#916726)
UI selection timeout missing on download prompts

* MFSA 2014-04/CVE-2014-1482 (bmo#943803)
Incorrect use of discarded images by RasterImage

* MFSA 2014-05/CVE-2014-1483 (bmo#950427)
Information disclosure with
*FromPoint on iframes

* MFSA 2014-06/CVE-2014-1484 (bmo#953993)
Profile path leaks to Android system log

* MFSA 2014-07/CVE-2014-1485 (bmo#910139)
XSLT stylesheets treated as styles in Content Security Policy

* MFSA 2014-08/CVE-2014-1486 (bmo#942164)
Use-after-free with imgRequestProxy and image proccessing

* MFSA 2014-09/CVE-2014-1487 (bmo#947592)
Cross-origin information leak through web workers

* MFSA 2014-10/CVE-2014-1489 (bmo#959531)
Firefox default start page UI content invokable by script

* MFSA 2014-11/CVE-2014-1488 (bmo#950604)
Crash when using web workers with asm.js

* MFSA 2014-12/CVE-2014-1490/CVE-2014-1491
(bmo#934545, bmo#930874, bmo#930857)
NSS ticket handling issues

* MFSA 2014-13/CVE-2014-1481(bmo#936056)
Inconsistent JavaScript handling of access to Window objects
- requires NSS 3.15.4 or higher
- rebased/reworked patches
- removed obsolete mozilla-bug929439.patch

Thu Dec 12 13:00:00 2013 uweigandAATTde.ibm.com
- Add support for powerpc64le-linux.

* mozilla-ppc64le.patch: general support

* mozilla-libffi-ppc64le.patch: libffi backport

* mozilla-xpcom-ppc64le.patch: port xpcom
- Add build fix from mainline.

* mozilla-bug929439.patch

Sun Dec 8 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 26.0 (bnc#854367, bnc#854370)

* rebased patches

* requires NSPR 4.10.2 and NSS 3.15.3.1

* MFSA 2013-104/CVE-2013-5609/CVE-2013-5610
Miscellaneous memory safety hazards

* MFSA 2013-105/CVE-2013-5611 (bmo#771294)
Application Installation doorhanger persists on navigation

* MFSA 2013-106/CVE-2013-5612 (bmo#871161)
Character encoding cross-origin XSS attack

* MFSA 2013-107/CVE-2013-5614 (bmo#886262)
Sandbox restrictions not applied to nested object elements

* MFSA 2013-108/CVE-2013-5616 (bmo#938341)
Use-after-free in event listeners

* MFSA 2013-109/CVE-2013-5618 (bmo#926361)
Use-after-free during Table Editing

* MFSA 2013-110/CVE-2013-5619 (bmo#917841)
Potential overflow in JavaScript binary search algorithms

* MFSA 2013-111/CVE-2013-6671 (bmo#930281)
Segmentation violation when replacing ordered list elements

* MFSA 2013-112/CVE-2013-6672 (bmo#894736)
Linux clipboard information disclosure though selection paste

* MFSA 2013-113/CVE-2013-6673 (bmo#970380)
Trust settings for built-in roots ignored during EV certificate
validation

* MFSA 2013-114/CVE-2013-5613 (bmo#930381, bmo#932449)
Use-after-free in synthetic mouse movement

* MFSA 2013-115/CVE-2013-5615 (bmo#929261)
GetElementIC typed array stubs can be generated outside observed
typesets

* MFSA 2013-116/CVE-2013-6629/CVE-2013-6630 (bmo#891693)
JPEG information leak

* MFSA 2013-117 (bmo#946351)
Mis-issued ANSSI/DCSSI certificate
(fixed via NSS 3.15.3.1)
- removed gecko.js preference file as GStreamer is enabled by
default now

Thu Oct 24 14:00:00 2013 wrAATTrosenauer.org
- update to Firefox 25.0 (bnc#847708)

* rebased patches

* requires NSS 3.15.2 or above

* MFSA 2013-93/CVE-2013-5590/CVE-2013-5591/CVE-2013-5592
Miscellaneous memory safety hazards

* MFSA 2013-94/CVE-2013-5593 (bmo#868327)
Spoofing addressbar through SELECT element

* MFSA 2013-95/CVE-2013-5604 (bmo#914017)
Access violation with XSLT and uninitialized data

* MFSA 2013-96/CVE-2013-5595 (bmo#916580)
Improperly initialized memory and overflows in some JavaScript
functions

* MFSA 2013-97/CVE-2013-5596 (bmo#910881)
Writing to cycle collected object during image decoding

* MFSA 2013-98/CVE-2013-5597 (bmo#918864)
Use-after-free when updating offline cache

* MFSA 2013-99/CVE-2013-5598 (bmo#920515)
Security bypass of PDF.js checks using iframes

* MFSA 2013-100/CVE-2013-5599/CVE-2013-5600/CVE-2013-5601
(bmo#915210, bmo#915576, bmo#916685)
Miscellaneous use-after-free issues found through ASAN fuzzing

* MFSA 2013-101/CVE-2013-5602 (bmo#897678)
Memory corruption in workers

* MFSA 2013-102/CVE-2013-5603 (bmo#916404)
Use-after-free in HTML document templates

Tue Sep 24 14:00:00 2013 wrAATTrosenauer.org
- as GStreamer is not automatically required anymore but loaded
dynamically if available, require it explicitely
- recommend optional GStreamer plugins for comprehensive media
support

Mon Sep 16 14:00:00 2013 lnusselAATTsuse.de
- move greek to the translations-common package (bnc#840551)

Sat Sep 14 14:00:00 2013 wrAATTrosenauer.org
- update to Firefox 24.0 (bnc#840485)

* MFSA 2013-76/CVE-2013-1718/CVE-2013-1719
Miscellaneous memory safety hazards

* MFSA 2013-77/CVE-2013-1720 (bmo#888820)
Improper state in HTML5 Tree Builder with templates

* MFSA 2013-78/CVE-2013-1721 (bmo#890277)
Integer overflow in ANGLE library

* MFSA 2013-79/CVE-2013-1722 (bmo#893308)
Use-after-free in Animation Manager during stylesheet cloning

* MFSA 2013-80/CVE-2013-1723 (bmo#891292)
NativeKey continues handling key messages after widget is destroyed

* MFSA 2013-81/CVE-2013-1724 (bmo#894137)
Use-after-free with select element

* MFSA 2013-82/CVE-2013-1725 (bmo#876762)
Calling scope for new Javascript objects can lead to memory corruption

* MFSA 2013-85/CVE-2013-1728 (bmo#883686)
Uninitialized data in IonMonkey

* MFSA 2013-88/CVE-2013-1730 (bmo#851353)
Compartment mismatch re-attaching XBL-backed nodes

* MFSA 2013-89/CVE-2013-1732 (bmo#883514)
Buffer overflow with multi-column, lists, and floats

* MFSA 2013-90/CVE-2013-1735/CVE-2013-1736 (bmo#898871, bmo#906301)
Memory corruption involving scrolling

* MFSA 2013-91/CVE-2013-1737 (bmo#907727)
User-defined properties on DOM proxies get the wrong \"this\" object

* MFSA 2013-92/CVE-2013-1738 (bmo#887334, bmo#882897)
GC hazard with default compartments and frame chain restoration
- enable gstreamer explicitely via pref (gecko.js)
- require NSS 3.15.1

Mon Aug 26 14:00:00 2013 wrAATTrosenauer.org
- update to Firefox 23.0.1

* Audio static/\"burble\"/breakup in Firefox to Firefox WebRTC calls
(bmo#901527)

Sun Aug 4 14:00:00 2013 wrAATTrosenauer.org
- update to Firefox 23.0 (bnc#833389)

* MFSA 2013-63/CVE-2013-1701/CVE-2013-1702
Miscellaneous memory safety hazards

* MFSA 2013-64/CVE-2013-1704 (bmo#883313)
Use after free mutating DOM during SetBody

* MFSA 2013-65/CVE-2013-1705 (bmo#882865)
Buffer underflow when generating CRMF requests

* MFSA 2013-67/CVE-2013-1708 (bmo#879924)
Crash during WAV audio file decoding

* MFSA 2013-68/CVE-2013-1709 (bmo#838253)
Document URI misrepresentation and masquerading

* MFSA 2013-69/CVE-2013-1710 (bmo#871368)
CRMF requests allow for code execution and XSS attacks

* MFSA 2013-70/CVE-2013-1711 (bmo#843829)
Bypass of XrayWrappers using XBL Scopes

* MFSA 2013-72/CVE-2013-1713 (bmo#887098)
Wrong principal used for validating URI for some Javascript
components

* MFSA 2013-73/CVE-2013-1714 (bmo#879787)
Same-origin bypass with web workers and XMLHttpRequest

* MFSA 2013-75/CVE-2013-1717 (bmo#406541, bmo#738397)
Local Java applets may read contents of local file system
- requires NSPR 4.10 and NSS 3.15

Wed Jul 3 14:00:00 2013 dmuellerAATTsuse.com
- fix build on ARM (/-g/ matches /-grecord-switches/)

Sat Jun 22 14:00:00 2013 wrAATTrosenauer.org
- update to Firefox 22.0 (bnc#825935)

* removed obsolete patches
+ mozilla-qcms-ppc.patch
+ mozilla-gstreamer-760140.patch

* GStreamer support does not build on 12.1 anymore (build only
on 12.2 and later)

* MFSA 2013-49/CVE-2013-1682/CVE-2013-1683
Miscellaneous memory safety hazards

* MFSA 2013-50/CVE-2013-1684/CVE-2013-1685/CVE-2013-1686
Memory corruption found using Address Sanitizer

* MFSA 2013-51/CVE-2013-1687 (bmo#863933, bmo#866823)
Privileged content access and execution via XBL

* MFSA 2013-52/CVE-2013-1688 (bmo#873966)
Arbitrary code execution within Profiler

* MFSA 2013-53/CVE-2013-1690 (bmo#857883)
Execution of unmapped memory through onreadystatechange event

* MFSA 2013-54/CVE-2013-1692 (bmo#866915)
Data in the body of XHR HEAD requests leads to CSRF attacks

* MFSA 2013-55/CVE-2013-1693 (bmo#711043)
SVG filters can lead to information disclosure

* MFSA 2013-56/CVE-2013-1694 (bmo#848535)
PreserveWrapper has inconsistent behavior

* MFSA 2013-57/CVE-2013-1695 (bmo#849791)
Sandbox restrictions not applied to nested frame elements

* MFSA 2013-58/CVE-2013-1696 (bmo#761667)
X-Frame-Options ignored when using server push with multi-part
responses

* MFSA 2013-59/CVE-2013-1697 (bmo#858101)
XrayWrappers can be bypassed to run user defined methods in a
privileged context

* MFSA 2013-60/CVE-2013-1698 (bmo#876044)
getUserMedia permission dialog incorrectly displays location

* MFSA 2013-61/CVE-2013-1699 (bmo#840882)
Homograph domain spoofing in .com, .net and .name

Tue Jun 11 14:00:00 2013 dvaleevAATTsuse.com
- Fix qcms altivec include (mozilla-qcms-ppc.patch)

Fri May 10 14:00:00 2013 wrAATTrosenauer.org
- update to Firefox 21.0 (bnc#819204)

* removed upstreamed patch firefox-712763.patch

* removed disabled mozilla-disable-neon-option.patch

* MFSA 2013-41/CVE-2013-0801/CVE-2013-1669
Miscellaneous memory safety hazards

* MFSA 2013-42/CVE-2013-1670 (bmo#853709)
Privileged access for content level constructor

* MFSA 2013-43/CVE-2013-1671 (bmo#842255)
File input control has access to full path

* MFSA 2013-46/CVE-2013-1674 (bmo#860971)
Use-after-free with video and onresize event

* MFSA 2013-47/CVE-2013-1675 (bmo#866825)
Uninitialized functions in DOMSVGZoomEvent

* MFSA 2013-48/CVE-2013-1676/CVE-2013-1677/CVE-2013-1678/
CVE-2013-1679/CVE-2013-1680/CVE-2013-1681
Memory corruption found using Address Sanitizer

Tue Apr 9 14:00:00 2013 wrAATTrosenauer.org
- revert to use GStreamer 0.10 on 12.3 (bnc#814101)
(remove mozilla-gstreamer-1.patch)

Fri Apr 5 14:00:00 2013 schwabAATTlinux-m68k.org
- Explicitly disable WebRTC support on non-x86, the configure script
disables it only half-heartedly

Fri Mar 29 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 20.0 (bnc#813026)

* requires NSPR 4.9.5 and NSS 3.14.3

* mozilla-webrtc-ppc.patch included upstream

* MFSA 2013-30/CVE-2013-0788/CVE-2013-0789
Miscellaneous memory safety hazards

* MFSA 2013-31/CVE-2013-0800 (bmo#825721)
Out-of-bounds write in Cairo library

* MFSA 2013-35/CVE-2013-0796 (bmo#827106)
WebGL crash with Mesa graphics driver on Linux

* MFSA 2013-36/CVE-2013-0795 (bmo#825697)
Bypass of SOW protections allows cloning of protected nodes

* MFSA 2013-37/CVE-2013-0794 (bmo#626775)
Bypass of tab-modal dialog origin disclosure

* MFSA 2013-38/CVE-2013-0793 (bmo#803870)
Cross-site scripting (XSS) using timed history navigations

* MFSA 2013-39/CVE-2013-0792 (bmo#722831)
Memory corruption while rendering grayscale PNG images
- use GStreamer 1.0 starting with 12.3 (mozilla-gstreamer-1.patch)

Tue Mar 12 13:00:00 2013 dmuellerAATTsuse.com
- build fixes for armv7hl:

* disable debug build as armv7hl does not have enough memory

* disable webrtc on armv7hl as it is non-compiling

Thu Mar 7 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 19.0.2 (bnc#808243)

* MFSA 2013-29/CVE-2013-0787 (bmo#848644)
Use-after-free in HTML Editor

Thu Feb 28 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 19.0.1

* blocklist updates

Sat Feb 16 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 19.0 (bnc#804248)

* MFSA 2013-21/CVE-2013-0783/2013-0784
Miscellaneous memory safety hazards

* MFSA 2013-22/CVE-2013-0772 (bmo#801366)
Out-of-bounds read in image rendering

* MFSA 2013-23/CVE-2013-0765 (bmo#830614)
Wrapped WebIDL objects can be wrapped again

* MFSA 2013-24/CVE-2013-0773 (bmo#809652)
Web content bypass of COW and SOW security wrappers

* MFSA 2013-25/CVE-2013-0774 (bmo#827193)
Privacy leak in JavaScript Workers

* MFSA 2013-26/CVE-2013-0775 (bmo#831095)
Use-after-free in nsImageLoadingContent

* MFSA 2013-27/CVE-2013-0776 (bmo#796475)
Phishing on HTTPS connection through malicious proxy

* MFSA 2013-28/CVE-2013-0780/CVE-2013-0782/CVE-2013-0777/
CVE-2013-0778/CVE-2013-0779/CVE-2013-0781
Use-after-free, out of bounds read, and buffer overflow issues
found using Address Sanitizer
- removed obsolete patches

* mozilla-webrtc.patch

* mozilla-gstreamer-803287.patch
- added patch to fix session restore window order (bmo#712763)

Sat Feb 2 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 18.0.2

* blocklist and CTP updates

* fixes in JS engine

Wed Jan 16 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 18.0.1

* blocklist updates

* backed out bmo#677092 (removed patch)

* fixed problems involving HTTP proxy transactions

Sat Jan 12 13:00:00 2013 schwabAATTlinux-m68k.org
- Fix WebRTC to build on powerpc

Sun Jan 6 13:00:00 2013 wrAATTrosenauer.org
- update to Firefox 18.0 (bnc#796895)

* MFSA 2013-01/CVE-2013-0749/CVE-2013-0769/CVE-2013-0770
Miscellaneous memory safety hazards

* MFSA 2013-02/CVE-2013-0760/CVE-2013-0762/CVE-2013-0766/CVE-2013-0767
CVE-2013-0761/CVE-2013-0763/CVE-2013-0771/CVE-2012-5829
Use-after-free and buffer overflow issues found using Address Sanitizer

* MFSA 2013-03/CVE-2013-0768 (bmo#815795)
Buffer Overflow in Canvas

* MFSA 2013-04/CVE-2012-0759 (bmo#802026)
URL spoofing in addressbar during page loads

* MFSA 2013-05/CVE-2013-0744 (bmo#814713)
Use-after-free when displaying table with many columns and column groups

* MFSA 2013-06/CVE-2013-0751 (bmo#790454)
Touch events are shared across iframes

* MFSA 2013-07/CVE-2013-0764 (bmo#804237)
Crash due to handling of SSL on threads

* MFSA 2013-08/CVE-2013-0745 (bmo#794158)
AutoWrapperChanger fails to keep objects alive during garbage collection

* MFSA 2013-09/CVE-2013-0746 (bmo#816842)
Compartment mismatch with quickstubs returned values

* MFSA 2013-10/CVE-2013-0747 (bmo#733305)
Event manipulation in plugin handler to bypass same-origin policy

* MFSA 2013-11/CVE-2013-0748 (bmo#806031)
Address space layout leaked in XBL objects

* MFSA 2013-12/CVE-2013-0750 (bmo#805121)
Buffer overflow in Javascript string concatenation

* MFSA 2013-13/CVE-2013-0752 (bmo#805024)
Memory corruption in XBL with XML bindings containing SVG

* MFSA 2013-14/CVE-2013-0757 (bmo#813901)
Chrome Object Wrapper (COW) bypass through changing prototype

* MFSA 2013-15/CVE-2013-0758 (bmo#813906)
Privilege escalation through plugin objects

* MFSA 2013-16/CVE-2013-0753 (bmo#814001)
Use-after-free in serializeToStream

* MFSA 2013-17/CVE-2013-0754 (bmo#814026)
Use-after-free in ListenerManager

* MFSA 2013-18/CVE-2013-0755 (bmo#814027)
Use-after-free in Vibrate

* MFSA 2013-19/CVE-2013-0756 (bmo#814029)
Use-after-free in Javascript Proxy objects
- requires NSS 3.14.1 (MFSA 2013-20, CVE-2013-0743)
- removed obsolete SLE11 patches (mozilla-gcc43
*)
- reenable WebRTC
- added mozilla-libproxy-compat.patch for libproxy API compat
on openSUSE 11.2 and earlier
- backed out restartless language packs as it broke multi-locale
setup (bmo#677092, bmo#818468)

Thu Nov 29 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 17.0.1

* revert some useragent changes introduced in 17.0

* leaving private browsing with social enabled doesn\'t reset all
social components (bmo#815042)
- fix KDE integration for file dialogs

Tue Nov 20 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 17.0 (bnc#790140)

* MFSA 2012-91/CVE-2012-5842/CVE-2012-5843
Miscellaneous memory safety hazards

* MFSA 2012-92/CVE-2012-4202 (bmo#758200)
Buffer overflow while rendering GIF images

* MFSA 2012-93/CVE-2012-4201 (bmo#747607)
evalInSanbox location context incorrectly applied

* MFSA 2012-94/CVE-2012-5836 (bmo#792857)
Crash when combining SVG text on path with CSS

* MFSA 2012-95/CVE-2012-4203 (bmo#765628)
Javascript: URLs run in privileged context on New Tab page

* MFSA 2012-96/CVE-2012-4204 (bmo#778603)
Memory corruption in str_unescape

* MFSA 2012-97/CVE-2012-4205 (bmo#779821)
XMLHttpRequest inherits incorrect principal within sandbox

* MFSA 2012-99/CVE-2012-4208 (bmo#798264)
XrayWrappers exposes chrome-only properties when not in chrome
compartment

* MFSA 2012-100/CVE-2012-5841 (bmo#805807)
Improper security filtering for cross-origin wrappers

* MFSA 2012-101/CVE-2012-4207 (bmo#801681)
Improper character decoding in HZ-GB-2312 charset

* MFSA 2012-102/CVE-2012-5837 (bmo#800363)
Script entered into Developer Toolbar runs with chrome privileges

* MFSA 2012-103/CVE-2012-4209 (bmo#792405)
Frames can shadow top.location

* MFSA 2012-104/CVE-2012-4210 (bmo#796866)
CSS and HTML injection through Style Inspector

* MFSA 2012-105/CVE-2012-4214/CVE-2012-4215/CVE-2012-4216/
CVE-2012-5829/CVE-2012-5839/CVE-2012-5840/CVE-2012-4212/
CVE-2012-4213/CVE-2012-4217/CVE-2012-4218
Use-after-free and buffer overflow issues found using Address
Sanitizer

* MFSA 2012-106/CVE-2012-5830/CVE-2012-5833/CVE-2012-5835/CVE-2012-5838
Use-after-free, buffer overflow, and memory corruption issues
found using Address Sanitizer
- rebased patches
- disabled WebRTC since build is broken (bmo#776877)

Tue Nov 20 13:00:00 2012 pcernyAATTsuse.com
- build on SLE11

* mozilla-gcc43-enums.patch

* mozilla-gcc43-template_hacks.patch

* mozilla-gcc43-templates_instantiation.patch

Wed Oct 24 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 16.0.2 (bnc#786522)

* MFSA 2012-90/CVE-2012-4194/CVE-2012-4195/CVE-2012-4196
(bmo#800666, bmo#793121, bmo#802557)
Fixes for Location object issues
- bring back Obsoletes for libproxy\'s mozjs plugin for distributions
before 12.2 to avoid crashes

Thu Oct 11 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 16.0.1 (bnc#783533)

* MFSA 2012-88/CVE-2012-4191 (bmo#798045)
Miscellaneous memory safety hazards

* MFSA 2012-89/CVE-2012-4192/CVE-2012-4193 (bmo#799952, bmo#720619)
defaultValue security checks not applied

Sun Oct 7 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 16.0 (bnc#783533)

* MFSA 2012-74/CVE-2012-3982/CVE-2012-3983
Miscellaneous memory safety hazards

* MFSA 2012-75/CVE-2012-3984 (bmo#575294)
select element persistance allows for attacks

* MFSA 2012-76/CVE-2012-3985 (bmo#655649)
Continued access to initial origin after setting document.domain

* MFSA 2012-77/CVE-2012-3986 (bmo#775868)
Some DOMWindowUtils methods bypass security checks

* MFSA 2012-79/CVE-2012-3988 (bmo#725770)
DOS and crash with full screen and history navigation

* MFSA 2012-80/CVE-2012-3989 (bmo#783867)
Crash with invalid cast when using instanceof operator

* MFSA 2012-81/CVE-2012-3991 (bmo#783260)
GetProperty function can bypass security checks

* MFSA 2012-82/CVE-2012-3994 (bmo#765527)
top object and location property accessible by plugins

* MFSA 2012-83/CVE-2012-3993/CVE-2012-4184 (bmo#768101, bmo#780370)
Chrome Object Wrapper (COW) does not disallow acces to privileged
functions or properties

* MFSA 2012-84/CVE-2012-3992 (bmo#775009)
Spoofing and script injection through location.hash

* MFSA 2012-85/CVE-2012-3995/CVE-2012-4179/CVE-2012-4180/
CVE-2012-4181/CVE-2012-4182/CVE-2012-4183
Use-after-free, buffer overflow, and out of bounds read issues
found using Address Sanitizer

* MFSA 2012-86/CVE-2012-4185/CVE-2012-4186/CVE-2012-4187/
CVE-2012-4188
Heap memory corruption issues found using Address Sanitizer

* MFSA 2012-87/CVE-2012-3990 (bmo#787704)
Use-after-free in the IME State Manager
- requires NSPR 4.9.2
- improve GStreamer integration (bmo#760140)
- removed upstreamed mozilla-crashreporter-restart-args.patch
- webapprt now included
- use kmozillahelper\'s new REVEAL command (bnc#777415)
(requires mozilla-kde4-integration >= 0.6.4)
- updated translations-other with new languages

Mon Sep 10 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 15.0.1 (bnc#779936)

* Sites visited while in Private Browsing mode could be found
through manual browser cache inspection (bmo#787743)

Sun Aug 26 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 15.0 (bnc#777588)

* MFSA 2012-57/CVE-2012-1970
Miscellaneous memory safety hazards

* MFSA 2012-58/CVE-2012-1972/CVE-2012-1973/CVE-2012-1974/CVE-2012-1975
CVE-2012-1976/CVE-2012-3956/CVE-2012-3957/CVE-2012-3958/CVE-2012-3959
CVE-2012-3960/CVE-2012-3961/CVE-2012-3962/CVE-2012-3963/CVE-2012-3964
Use-after-free issues found using Address Sanitizer

* MFSA 2012-59/CVE-2012-1956 (bmo#756719)
Location object can be shadowed using Object.defineProperty

* MFSA 2012-60/CVE-2012-3965 (bmo#769108)
Escalation of privilege through about:newtab

* MFSA 2012-61/CVE-2012-3966 (bmo#775794, bmo#775793)
Memory corruption with bitmap format images with negative height

* MFSA 2012-62/CVE-2012-3967/CVE-2012-3968
WebGL use-after-free and memory corruption

* MFSA 2012-63/CVE-2012-3969/CVE-2012-3970
SVG buffer overflow and use-after-free issues

* MFSA 2012-64/CVE-2012-3971
Graphite 2 memory corruption

* MFSA 2012-65/CVE-2012-3972 (bmo#746855)
Out-of-bounds read in format-number in XSLT

* MFSA 2012-66/CVE-2012-3973 (bmo#757128)
HTTPMonitor extension allows for remote debugging without explicit
activation

* MFSA 2012-68/CVE-2012-3975 (bmo#770684)
DOMParser loads linked resources in extensions when parsing
text/html

* MFSA 2012-69/CVE-2012-3976 (bmo#768568)
Incorrect site SSL certificate data display

* MFSA 2012-70/CVE-2012-3978 (bmo#770429)
Location object security checks bypassed by chrome code

* MFSA 2012-72/CVE-2012-3980 (bmo#771859)
Web console eval capable of executing chrome-privileged code
- fix HTML5 video crash with GStreamer enabled (bmo#761030)
- GStreamer is only used for MP4 (no WebM, OGG)
- updated filelist
- moved browser specific preferences to correct location

Sun Jul 29 14:00:00 2012 ajAATTsuse.de
- Fix mozilla-kde.patch to include sys/resource.h for getrlimit etc (glibc 2.16)

Sat Jul 14 14:00:00 2012 wrAATTrosenauer.org
- update to 14.0.1 (bnc#771583)

* MFSA 2012-42/CVE-2012-1949/CVE-2012-1948
Miscellaneous memory safety hazards

* MFSA 2012-43/CVE-2012-1950
Incorrect URL displayed in addressbar through drag and drop

* MFSA 2012-44/CVE-2012-1951/CVE-2012-1954/CVE-2012-1953/CVE-2012-1952
Gecko memory corruption

* MFSA 2012-45/CVE-2012-1955 (bmo#757376)
Spoofing issue with location

* MFSA 2012-46/CVE-2012-1966 (bmo#734076)
XSS through data: URLs

* MFSA 2012-47/CVE-2012-1957 (bmo#750096)
Improper filtering of javascript in HTML feed-view

* MFSA 2012-48/CVE-2012-1958 (bmo#750820)
use-after-free in nsGlobalWindow::PageHidden

* MFSA 2012-49/CVE-2012-1959 (bmo#754044, bmo#737559)
Same-compartment Security Wrappers can be bypassed

* MFSA 2012-50/CVE-2012-1960 (bmo#761014)
Out of bounds read in QCMS

* MFSA 2012-51/CVE-2012-1961 (bmo#761655)
X-Frame-Options header ignored when duplicated

* MFSA 2012-52/CVE-2012-1962 (bmo#764296)
JSDependentString::undepend string conversion results in memory
corruption

* MFSA 2012-53/CVE-2012-1963 (bmo#767778)
Content Security Policy 1.0 implementation errors cause data
leakage

* MFSA 2012-55/CVE-2012-1965 (bmo#758990)
feed: URLs with an innerURI inherit security context of page

* MFSA 2012-56/CVE-2012-1967 (bmo#758344)
Code execution through javascript: URLs
- license change from tri license to MPL-2.0
- fix crashreporter restart option (bmo#762780)
- require NSS 3.13.5
- remove mozjs pacrunner obsoletes again for now
- adopted mozilla-prefer_plugin_pref.patch
- PPC fixes:

* reenabled mozilla-yarr-pcre.patch to fix build for PPC

* add patches for bmo#750620 and bmo#746112

* fix xpcshell segfault on ppc

Fri Jun 15 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 13.0.1

* bugfix release
- obsolete libproxy\'s mozjs pacrunner (bnc#759123)

Sat Jun 2 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 13.0 (bnc#765204)

* MFSA 2012-34/CVE-2012-1938/CVE-2012-1937/CVE-2011-3101
Miscellaneous memory safety hazards

* MFSA 2012-36/CVE-2012-1944 (bmo#751422)
Content Security Policy inline-script bypass

* MFSA 2012-37/CVE-2012-1945 (bmo#670514)
Information disclosure though Windows file shares and shortcut
files

* MFSA 2012-38/CVE-2012-1946 (bmo#750109)
Use-after-free while replacing/inserting a node in a document

* MFSA 2012-40/CVE-2012-1947/CVE-2012-1940/CVE-2012-1941
Buffer overflow and use-after-free issues found using Address
Sanitizer
- require NSS 3.13.4

* MFSA 2012-39/CVE-2012-0441 (bmo#715073)
- fix sound notifications when filename/path contains a whitespace
(bmo#749739)

Wed May 23 14:00:00 2012 adrianAATTsuse.de
- fix build on arm

Wed May 16 14:00:00 2012 wrAATTrosenauer.org
- reenabled crashreporter for Factory/12.2
(fix in mozilla-gcc47.patch)

Sat Apr 21 14:00:00 2012 wrAATTrosenauer.org
- update to Firefox 12.0 (bnc#758408)

* rebased patches

* MFSA 2012-20/CVE-2012-0467/CVE-2012-0468
Miscellaneous memory safety hazards

* MFSA 2012-22/CVE-2012-0469 (bmo#738985)
use-after-free in IDBKeyRange

* MFSA 2012-23/CVE-2012-0470 (bmo#734288)
Invalid frees causes heap corruption in gfxImageSurface

* MFSA 2012-24/CVE-2012-0471 (bmo#715319)
Potential XSS via multibyte content processing errors

* MFSA 2012-25/CVE-2012-0472 (bmo#744480)
Potential memory corruption during font rendering using cairo-dwrite

* MFSA 2012-26/CVE-2012-0473 (bmo#743475)
WebGL.drawElements may read illegal video memory due to
FindMaxUshortElement error

* MFSA 2012-27/CVE-2012-0474 (bmo#687745, bmo#737307)
Page load short-circuit can lead to XSS

* MFSA 2012-28/CVE-2012-0475 (bmo#694576)
Ambiguous IPv6 in Origin headers may bypass webserver access
restrictions

* MFSA 2012-29/CVE-2012-0477 (bmo#718573)
Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues

* MFSA 2012-30/CVE-2012-0478 (bmo#727547)
Crash with WebGL content using textImage2D

* MFSA 2012-31/CVE-2011-3062 (bmo#739925)
Off-by-one error in OpenType Sanitizer

* MFSA 2012-32/CVE-2011-1187 (bmo#624621)
HTTP Redirections and remote content can be read by javascript errors

* MFSA 2012-33/CVE-2012-0479 (bmo#714631)
Potential site identity spoofing when loading RSS and Atom feeds
- added mozilla-libnotify.patch to allow fallback from libnotify
to xul based events if no notification-daemon is running
- gcc 4.7 fixes

* mozilla-gcc47.patch

* disabled crashreporter temporarily for Factory
- recommend libcanberra0 for proper sound notifications

Fri Mar 9 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 11.0 (bnc#750044)

* MFSA 2012-13/CVE-2012-0455 (bmo#704354)
XSS with Drag and Drop and Javascript: URL

* MFSA 2012-14/CVE-2012-0456/CVE-2012-0457 (bmo#711653, #720103)
SVG issues found with Address Sanitizer

* MFSA 2012-15/CVE-2012-0451 (bmo#717511)
XSS with multiple Content Security Policy headers

* MFSA 2012-16/CVE-2012-0458
Escalation of privilege with Javascript: URL as home page

* MFSA 2012-17/CVE-2012-0459 (bmo#723446)
Crash when accessing keyframe cssText after dynamic modification

* MFSA 2012-18/CVE-2012-0460 (bmo#727303)
window.fullScreen writeable by untrusted content

* MFSA 2012-19/CVE-2012-0461/CVE-2012-0462/CVE-2012-0464/
CVE-2012-0463
Miscellaneous memory safety hazards
- ported and reenabled KDE integration (bnc#746591)
- explicitely build-require X libs

Mon Mar 5 13:00:00 2012 vdziewieckiAATTsuse.com
- add Provides: browser(npapi) FATE#313084

Fri Feb 17 13:00:00 2012 pcernyAATTsuse.com
- better plugin directory resolution (bnc#747320)

Thu Feb 16 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.2 (bnc#747328)

* CVE-2011-3026 (bmo#727401)
libpng: integer overflow leading to heap-buffer overflow

Thu Feb 9 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0.1 (bnc#746616)

* MFSA 2012-10/CVE-2012-0452 (bmo#724284)
use after free in nsXBLDocumentInfo::ReadPrototypeBindings

Tue Feb 7 13:00:00 2012 dvaleevAATTsuse.com
- Use YARR interpreter instead of PCRE on platforms where YARR JIT
is not supported, since PCRE doesnt build (bmo#691898)
- fix ppc64 build (bmo#703534)

Mon Jan 30 13:00:00 2012 wrAATTrosenauer.org
- update to Firefox 10.0 (bnc#744275)

* MFSA 2012-01/CVE-2012-0442/CVE-2012-0443
Miscellaneous memory safety hazards

* MFSA 2012-03/CVE-2012-0445 (bmo#701071)