* Tue Jun 21 2022 Wolfgang Rosenauer - Firefox 102.0 (build1)- requires NSPR >= 4.34 NSS >= 3.79 rust = 1.60 * Fri Jun 10 2022 Andreas Stieger - Mozilla Firefox 101.0.1: * Fixed context menus not appearing when right-clicking Picture-in-Picture windows on some Linux systems (bmo#1771914) * Various stability fixes * Sun May 29 2022 Wolfgang Rosenauer - Mozilla Firefox 101.0 * Reading is now easier with the prefers-contrast media query, which allows sites to detect if the user has requested that web content is presented with a higher (or lower) contrast * All non-configured MIME types can now be assigned a custom action upon download completion * allows users to use as many microphones as you want, at the same time, during video conferencing. The most exciting benefit is that you can easily switch your microphones at any time (if your conferencing service provider enables this flexibility) MFSA 2022-20 (bsc#1200027) * CVE-2022-31736 (bmo#1735923) Cross-Origin resource\'s length leaked * CVE-2022-31737 (bmo#1743767) Heap buffer overflow in WebGL * CVE-2022-31738 (bmo#1756388) Browser window spoof using fullscreen mode * CVE-2022-31739 (bmo#1765049) Attacker-influenced path traversal when saving downloaded files * CVE-2022-31740 (bmo#1766806) Register allocation problem in WASM on arm64 * CVE-2022-31741 (bmo#1767590) Uninitialized variable leads to invalid memory read * CVE-2022-31742 (bmo#1730434) Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information * CVE-2022-31743 (bmo#1747388) HTML Parsing incorrectly ended HTML comments prematurely * CVE-2022-31744 (bmo#1757604) CSP bypass enabling stylesheet injection * CVE-2022-31745 (bmo#1760944) Incorrect Assertion caused by unoptimized array shift operations * CVE-2022-1919 (bmo#1761275) Memory Corruption when manipulating webp images * CVE-2022-31747 (bmo#1760765, bmo#1765610, bmo#1766283, bmo#1767365, bmo#1768559, bmo#1768734) Memory safety bugs fixed in Firefox 101 and Firefox ESR 91.10 * CVE-2022-31748 (bmo#1713773, bmo#1762201, bmo#1762469, bmo#1762770, bmo#1764878, bmo#1765226, bmo#1765782, bmo#1765973, bmo#1767177, bmo#1767181, bmo#1768232, bmo#1768251, bmo#1769869) Memory safety bugs fixed in Firefox 101- requires * NSS 3.78.1 * rust-cbindgen 0.23.0 * rust 1.59 * Fri May 20 2022 Wolfgang Rosenauer - Mozilla Firefox 100.0.2 MFSA 2022-19 (bsc#1199768) * CVE-2022-1802 (bmo#1770137) Prototype pollution in Top-Level Await implementation * CVE-2022-1529 (bmo#1770048) Untrusted input used in JavaScript object indexing, leading to prototype pollution * Wed May 18 2022 Andreas Stieger - Mozilla Firefox 100.0.1: * Fixed: Fixed an issue with subtitles in Picture-in-Picture mode while using Netflix (bmo#1768818) * Fixed: Fixed an issue where some commands were unavailable in the Picture-in-Picture window (bmo#1768201) * Sun May 01 2022 Wolfgang Rosenauer - Mozilla Firefox 100.0 * subtitle support in PiP * spell checking supports multiple languages in parallel * more details here https://www.mozilla.org/en-US/firefox/100.0/releasenotes MFSA 2022-16 (boo#1198970) * CVE-2022-29914 (bmo#1746448) Fullscreen notification bypass using popups * CVE-2022-29909 (bmo#1755081) Bypassing permission prompt in nested browsing contexts * CVE-2022-29916 (bmo#1760674) Leaking browser history with CSS variables * CVE-2022-29911 (bmo#1761981) iframe Sandbox bypass * CVE-2022-29912 (bmo#1692655) Reader mode bypassed SameSite cookies * CVE-2022-29910 (bmo#1757138) Firefox for Android forgot HTTP Strict Transport Security settings * CVE-2022-29915 (bmo#1751678) Leaking cross-origin redirect through the Performance API * CVE-2022-29917 (bmo#1684739, bmo#1706441, bmo#1753298, bmo#1762614, bmo#1762620, bmo#1764778) Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9 * CVE-2022-29918 (bmo#1744043, bmo#1747178, bmo#1753535, bmo#1754017, bmo#1755847, bmo#1756172, bmo#1757477, bmo#1758223, bmo#1760160, bmo#1761481, bmo#1761771) Memory safety bugs fixed in Firefox 100- requires NSS 3.77 * Tue Apr 12 2022 Andreas Stieger - Mozilla Firefox 99.0.1 * Fixed an issue with text rendering in Bengali (bmo#1763368) * Fixed a selection issue in the Download panel with drag and drop (bmo#1762723) * Fixed: Fixed an issue preventing Zoom gallery mode for users who go to zoom.us URLs instead of subdomain.zoom.us URLs (bmo#1763801) * Mon Apr 04 2022 Wolfgang Rosenauer - Mozilla Firefox 99.0 * You can now toggle Narrate in ReaderMode with the keyboard shortcut \"n.\" * You can find added support for search—with or without diacritics—in the PDF viewer. * The Linux sandbox has been strengthened: processes exposed to web content no longer have access to the X Window system (X11). * Firefox now supports credit card autofill and capture in Germany and France. MFSA 2022-13 (bsc#1197903) * CVE-2022-1097 (bmo#1745667) Use-after-free in NSSToken objects * CVE-2022-28281 (bmo#1755621) Out of bounds write due to unexpected WebAuthN Extensions * CVE-2022-28282 (bmo#1751609) Use-after-free in DocumentL10n::TranslateDocument * CVE-2022-28283 (bmo#1754066) Missing security checks for fetching sourceMapURL * CVE-2022-28284 (bmo#1754522) Script could be executed via svg\'s use element * CVE-2022-28285 (bmo#1756957) Incorrect AliasSet used in JIT Codegen * CVE-2022-28286 (bmo#1735265) iframe contents could be rendered outside the border * CVE-2022-28287 (bmo#1741515) Text Selection could crash Firefox * CVE-2022-24713 (bmo#1758509) Denial of Service via complex regular expressions * CVE-2022-28289 (bmo#1663508, bmo#1744525, bmo#1753508, bmo#1757476, bmo#1757805, bmo#1758549, bmo#1758776) Memory safety bugs fixed in Firefox 99 and Firefox ESR 91.8 * CVE-2022-28288 (bmo#1746415, bmo#1746495, bmo#1746500, bmo#1747282, bmo#1748759, bmo#1749056, bmo#1749786, bmo#1751679, bmo#1752120, bmo#1756010, bmo#1756017, bmo#1757213, bmo#1757258, bmo#1757427) Memory safety bugs fixed in Firefox 99- requires NSS >= 3.76.1- remove obsolete patch * mozilla-bmo1756347.patch * mozilla-bmo1757571.patch- update create-tar.sh * Thu Mar 24 2022 Andreas Stieger - MozillaFirefox 98.0.2: * Fixed: Fixed an issue preventing users from typing in Address Bar after opening new tab and pressing cmd + enter (bmo#1757376) * Fixed: Fixed an issue causing some users to crash in out-of- memory conditions (bmo#1757618) * Fixed: Fixed an issue in session history which caused some sites to fail to load (bmo#1758664) * Fixed: Fixed an add-on specific compatibility issue (bmo#1759162) * Wed Mar 23 2022 Simon Vogl - Change mozilla-kde.patch to follow the GNOME registry behavior for new MIME types to avoid opening downloaded files without any inquiries (bsc#1197319) * Tue Mar 22 2022 Guillaume GARDET - Add patch to fix start-up on aarch64: * mozilla-bmo1757571.patch * Thu Mar 17 2022 Dirk Müller - exclude slow cpus for building * Thu Mar 17 2022 Martin Sirringhaus - Add cpu-flag `asimdrdm` to aarch64 constraints, to select newer, faster buildhosts, as the others struggle to build FF. * Mon Mar 14 2022 Wolfgang Rosenauer - Mozilla Firefox 98.0.1: * Yandex and Mail.ru have been removed as optional search providers in the drop-down search menu in Firefox * Tue Mar 08 2022 Wolfgang Rosenauer - Mozilla Firefox 98.0 * Firefox has a new optimized download flow * other changes as documented here https://www.mozilla.org/en-US/firefox/98.0/releasenotes MFSA 2022-10 (bsc#1196900) * CVE-2022-26383 (bmo#1742421) Browser window spoof using fullscreen mode * CVE-2022-26384 (bmo#1744352) iframe allow-scripts sandbox bypass * CVE-2022-26387 (bmo#1752979) Time-of-check time-of-use bug when verifying add-on signatures * CVE-2022-26381 (bmo#1736243) Use-after-free in text reflows * CVE-2022-26382 (bmo#1741888) Autofill Text could be exfiltrated via side-channel attacks * CVE-2022-26385 (bmo#1747526) Use-after-free in thread shutdown * CVE-2022-0843 (bmo#1746523, bmo#1749062, bmo#1749164, bmo#1749214, bmo#1749610, bmo#1750032, bmo#1752100, bmo#1752405, bmo#1753612, bmo#1754508) Memory safety bugs fixed in Firefox 98- requires NSS 3.75- add mozilla-bmo1756347.patch to fix i586 build * Fri Feb 18 2022 Andreas Stieger - Mozilla Firefox 97.0.1 * Fixed: Fixed an issue where TikTok videos would fail to load when selected from a user\'s profile page (bmo#1750973) * Fixed: Fixed an issue which led to Picture-in-Picture mode being unable to be toggled on Hulu (bmo#1753401) * Fixed: Works around problems with WebRoot SecureAnywhere antivirus rendering Firefox unusable in some situations (bmo#1752466) * Fixed: Fixed an issue causing users to see the Restore Session screen unexpectedly when starting Firefox (bmo#1749996) * Mon Feb 14 2022 Luciano Santos - Remove bashisms (\"source\" and \"function\" keywords) from mozilla.sh.in to ally with the #!/bin/sh shebang. If the end user has either dash-sh package or busybox-sh to handle Bourn Shell scripts rather than having bash-sh package, the script would fail. Using \".\" instead of \"source\" and \"create_langpack_link()\" function definition is enough to keep both sides sane, behavior-wise. * Tue Feb 08 2022 Wolfgang Rosenauer - Mozilla Firefox 97.0 MFSA 2022-04 (bsc#1195682) * CVE-2022-22753 (bmo#1732435) Privilege Escalation to SYSTEM on Windows via Maintenance Service * CVE-2022-22754 (bmo#1750565) Extensions could have bypassed permission confirmation during update * CVE-2022-22755 (bmo#1309630) XSL could have allowed JavaScript execution after a tab was closed * CVE-2022-22756 (bmo#1317873) Drag and dropping an image could have resulted in the dropped object being an executable * CVE-2022-22757 (bmo#1720098) Remote Agent did not prevent local websites from connecting * CVE-2022-22758 (bmo#1728742) tel: links could have sent USSD codes to the dialer on Firefox for Android * CVE-2022-22759 (bmo#1739957) Sandboxed iframes could have executed script if the parent appended elements * CVE-2022-22760 (bmo#1740985, bmo#1748503) Cross-Origin responses could be distinguished between script and non-script content-types * CVE-2022-22761 (bmo#1745566) frame-ancestors Content Security Policy directive was not enforced for framed extension pages * CVE-2022-22762 (bmo#1743931) JavaScript Dialogs could have been displayed over other domains on Firefox for Android * CVE-2022-22764 (bmo#1742682, bmo#1744165, bmo#1746545, bmo#1748210, bmo#1748279) Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6 * CVE-2022-0511 (bmo#1713579, bmo#1735448, bmo#1743821, bmo#1746313, bmo#1746314, bmo#1746316, bmo#1746321, bmo#1746322, bmo#1746323, bmo#1746412, bmo#1746430, bmo#1746451, bmo#1746488, bmo#1746875, bmo#1746898, bmo#1746905, bmo#1746907, bmo#1746917, bmo#1747128, bmo#1747137, bmo#1747331, bmo#1747346, bmo#1747439, bmo#1747457, bmo#1747870, bmo#1749051, bmo#1749274, bmo#1749831) Memory safety bugs fixed in Firefox 97- requires NSS 3.74- requires rust 1.57 * Mon Feb 07 2022 Dirk Müller - remove memoryperjob and use %limit instead. this allows to adapt to more worker types, and lowers the time the package is stuck in \"scheduling\". raising memory above 8 to lower risk for LTO jobs to run OOM- add hack to disable -Wl,--gc-section which avoids a binutils segfault on x86- change mozilla-reduce-rust-debuginfo.patch: use -g1 everywhere * Sun Jan 30 2022 Dirk Müller - disable ccache, this adds about 1 minute of build time and over 2 GB of disk space usage without benefit on OBS builds- build with rust-simd like upstream does- use -g1 for debuginfo generation as this is what upstream does as well and it saves ~ 2GB of writes- use %limit on x86_64 to scale down to less capable workers- disable install stripping so that debuginfo is useful- use autopatch- cleanup constraints to specify only jobs, physicalmemory and memoryperjob to be more flexible on which host to build on * Fri Jan 28 2022 Wolfgang Rosenauer - Mozilla Firefox 96.0.3 (bsc#1195230) * Fixed an issue that allowed unexpected data to be submitted in some of our search telemetry (bmo#1752317) * Mon Jan 24 2022 Martin Liška - Enable -fimplicit-constexpr for GCC 12+. * Thu Jan 20 2022 Andreas Stieger - Mozilla Firefox 96.0.2 * Fix an issue that caused tab height to display inconsistently on Linux when audio was played (bmo#1714276) * Fix an issue that caused Lastpass dropdowns to appear blank in Private Browsing mode (bmo#1748158) * Fix a crash encountered when resizing a Facebook app (bmo#1746084) * Fri Jan 14 2022 Andreas Stieger - Mozilla Firefox 96.0.1 * Fixed: Improvements to make the parsing of content-length headers more robust (bmo#1749957, boo#1194677) * Sat Jan 08 2022 Wolfgang Rosenauer - Mozilla Firefox 96.0 * https://www.mozilla.org/en-US/firefox/96.0/releasenotes MFSA 2022-01 (bsc#1194547) * CVE-2022-22746 (bmo#1735071) Calling into reportValidity could have lead to fullscreen window spoof * CVE-2022-22743 (bmo#1739220) Browser window spoof using fullscreen mode * CVE-2022-22742 (bmo#1739923) Out-of-bounds memory access when inserting text in edit mode * CVE-2022-22741 (bmo#1740389) Browser window spoof using fullscreen mode * CVE-2022-22740 (bmo#1742334) Use-after-free of ChannelEventQueue::mOwner * CVE-2022-22738 (bmo#1742382) Heap-buffer-overflow in blendGaussianBlur * CVE-2022-22737 (bmo#1745874) Race condition when playing audio files * CVE-2021-4140 (bmo#1746720) Iframe sandbox bypass with XSLT * CVE-2022-22750 (bmo#1566608) IPC passing of resource handles could have lead to sandbox bypass * CVE-2022-22749 (bmo#1705094) Lack of URL restrictions when scanning QR codes * CVE-2022-22748 (bmo#1705211) Spoofed origin on external protocol launch dialog * CVE-2022-22745 (bmo#1735856) Leaking cross-origin URLs through securitypolicyviolation event * CVE-2022-22744 (bmo#1737252) The \'Copy as curl\' feature in DevTools did not fully escape website-controlled data, potentially leading to command injection * CVE-2022-22747 (bmo#1735028) Crash when handling empty pkcs7 sequence * CVE-2022-22736 (bmo#1742692) Potential local privilege escalation when loading modules from the install directory. * CVE-2022-22739 (bmo#1744158) Missing throttling on external protocol launch dialog * CVE-2022-22751 (bmo#1664149, bmo#1737816, bmo#1739366, bmo#1740274, bmo#1740797, bmo#1741201, bmo#1741869, bmo#1743221, bmo#1743515, bmo#1745373, bmo#1746011) Memory safety bugs fixed in Firefox 96 and Firefox ESR 91.5 * CVE-2022-22752 (bmo#1740534, bmo#1741210, bmo#1742770) Memory safety bugs fixed in Firefox 96- removed obsolete patches * mozilla-bmo1745560.patch * mozilla-bmo1744896.patch * mozilla-sandbox-fips.patch- requires NSPR >= 4.33 NSS >= 3.73.1 * Tue Dec 28 2021 Bjørn Lie - Add upstream patches: * mozilla-bmo1745560.patch: Fix build against wayland 1.20. * mozilla-bmo1744896.patch: Create WaylandVsyncSource on window creation * Mon Dec 20 2021 Wolfgang Rosenauer - Mozilla Firefox 95.0.2 * Addresses frequent crashes experienced by users with C/E/Z-Series \"Bobcat\" CPUs running on Windows 7, 8, and 8.1.- updated constraints for ppc and x86-64 * Fri Dec 17 2021 Wolfgang Rosenauer - Mozilla Firefox 95.0.1 (bsc#1193845) * Fixed frequent MOZILLA_PKIX_ERROR_OCSP_RESPONSE_FOR_CERT_MISSING error messages when trying to connect to various microsoft.com domains (bmo#1745600) * Fix for a WebRender crash on some Linux/X11 systems (bmo#1741956) * Fix for a frequent Windows shutdown crash (bmo#1738984) * Fix websites contrast issues for some Linux users with Dark mode set at OS level (bmo#1740518) * Sat Dec 04 2021 Wolfgang Rosenauer - Mozilla Firefox 95.0 * You can now move the Picture-in-Picture toggle button to the opposite side of the video. Simply look for the new context menu option Move Picture-in-Picture Toggle to Left (Right) Side. * To better protect Firefox users against side-channel attacks such as Spectre, Site Isolation is now enabled for all Firefox 95 users. * https://www.mozilla.org/en-US/firefox/95.0/releasenotes MFSA 2021-52 (bsc#1193485) * CVE-2021-43536 (bmo#1730120) URL leakage when navigating while executing asynchronous function * CVE-2021-43537 (bmo#1738237) Heap buffer overflow when using structured clone * CVE-2021-43538 (bmo#1739091) Missing fullscreen and pointer lock notification when requesting both * CVE-2021-43539 (bmo#1739683) GC rooting failure when calling wasm instance methods * MOZ-2021-0010 (bmo#1735852) Use-after-free in fullscreen objects on MacOS * CVE-2021-43540 (bmo#1636629) WebExtensions could have installed persistent ServiceWorkers * CVE-2021-43541 (bmo#1696685) External protocol handler parameters were unescaped * CVE-2021-43542 (bmo#1723281) XMLHttpRequest error codes could have leaked the existence of an external protocol handler * CVE-2021-43543 (bmo#1738418) Bypass of CSP sandbox directive when embedding * CVE-2021-43544 (bmo#1739934) Receiving a malicious URL as text through a SEND intent could have led to XSS * CVE-2021-43545 (bmo#1720926) Denial of Service when using the Location API in a loop * CVE-2021-43546 (bmo#1737751) Cursor spoofing could overlay user interface when native cursor is zoomed * MOZ-2021-0009 (bmo#1393362, bmo#1736046, bmo#1736751, bmo#1737009, bmo#1739372, bmo#1739421) Memory safety bugs fixed in Firefox 95 and Firefox ESR 91.4- requires NSS >= 3.72 * Thu Dec 02 2021 Andreas Stieger - remove x-scheme-handler/ftp from firefox.desktop boo#1193321 * Thu Nov 25 2021 Bjørn Lie - Drop unused libidl-devel BuildRequires. * Tue Nov 23 2021 Andreas Stieger - Mozilla Firefox 94.0.2: * Update preference design for Firefox Suggest for improved clarity * Resolved general instability/crashes on Linux caused by a file descriptor leak when backgrounding tabs using WebGL (bmo#1741997) * Fri Nov 05 2021 Andreas Stieger - Mozilla Firefox 94.0.1: * fixes for other platforms * Sat Oct 30 2021 Wolfgang Rosenauer - Mozilla Firefox 94.0 * https://www.mozilla.org/en-US/firefox/94.0/releasenotes MFSA 2021-48 (bsc#1192250) * CVE-2021-38503 (bmo#1729517) iframe sandbox rules did not apply to XSLT stylesheets * CVE-2021-38504 (bmo#1730156) Use-after-free in file picker dialog * CVE-2021-38505 (bmo#1730194) Windows 10 Cloud Clipboard may have recorded sensitive user data * CVE-2021-38506 (bmo#1730750) Firefox could be coaxed into going into fullscreen mode without notification or warning * CVE-2021-38507 (bmo#1730935) Opportunistic Encryption in HTTP2 could be used to bypass the Same-Origin-Policy on services hosted on other ports * MOZ-2021-0003 (bmo#1736886) Universal XSS in Firefox for Android via QR Code URLs * CVE-2021-38508 (bmo#1366818) Permission Prompt could be overlaid, resulting in user confusion and potential spoofing * MOZ-2021-0004 (bmo#1659155) Web Extensions could access pre-redirect URL when their context menu was triggered by a user * CVE-2021-38509 (bmo#1718571) Javascript alert box could have been spoofed onto an arbitrary domain * CVE-2021-38510 (bmo#1731779) Download Protections were bypassed by .inetloc files on Mac OS * MOZ-2021-0005 (bmo#1719203) \'Copy Image Link\' context menu action could have been abused to see authentication tokens * MOZ-2021-0006 (bmo#1724233) URL Parsing may incorrectly parse internationalized domains * MOZ-2021-0007 (bmo#1606864, bmo#1712671, bmo#1730048, bmo#1735152) Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3- removed obsolete patches * mozilla-bmo1602730.patch * mozilla-bmo1725828.patch * mozilla-bmo1729124.patch- requires NSS >= 3.71 rust >= 1.53- fix Plasma detection (boo#1191825)- fix Link error \"undefined hidden symbol:\" https://github.com/openSUSE/firefox-maintenance/issues/37 * Tue Oct 26 2021 Wolfgang Rosenauer - Drop unused pkgconfig(gdk-x11-2.0) BuildRequires- (re-)enable LTO on Tumbleweed * Wed Oct 20 2021 Martin Sirringhaus - Rebase mozilla-sandbox-fips.patch to punch another hole in the sandbox containment, to be able to open /proc/sys/crypto/fips_enabled from within the newly introduced socket process sandbox. This fixes bsc#1191815 and bsc#1190141 * Mon Oct 18 2021 Guillaume GARDET - Add patch to fix build on aarch64 (bmo#1729124) * mozilla-bmo1729124.patch * Fri Oct 01 2021 Wolfgang Rosenauer - Mozilla Firefox 93.0 * supports the new AVIF image format * PDF viewer now supports filling more forms (XFA-based forms) * now blocks downloads that rely on insecure connections, protecting against potentially malicious or unsafe downloads * Improved web compatibility for privacy protections with SmartBlock 3.0 * Introducing a new referrer tracking protection in Strict Tracking Protection and Private Browsing * TLS ciphersuites that use 3DES have been disabled. Such ciphersuites can only be enabled when deprecated versions of TLS are also enabled * The download panel now follows the Firefox visual styles MFSA 2021-43 (bsc#1191332) * CVE-2021-38496 (bmo#1725335) Use-after-free in MessageTask * CVE-2021-38497 (bmo#1726621) Validation message could have been overlaid on another origin * CVE-2021-38498 (bmo#1729642) Use-after-free of nsLanguageAtomService object * CVE-2021-32810 (bmo#1729813) https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-pqqp-xmhj-wgcw) Data race in crossbeam-deque * CVE-2021-38500 (bmo#1725854, bmo#1728321) Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2 * CVE-2021-38501 (bmo#1685354, bmo#1715755, bmo#1723176) Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2 * CVE-2021-38499 (bmo#1667102, bmo#1723170, bmo#1725356, bmo#1727364) Memory safety bugs fixed in Firefox 93- removed obsolete mozilla-bmo1708709.patch- require NSS >= 3.70- allow to override wayland detection by defining MOZ_ENABLE_WAYLAND explicitely as 0 or 1- fix aarch64 build by updating constraints- add mozilla-bmo1725828.patch to fix widevine (bsc#1190842)- add mozilla-bmo531915.patch to fix build for i586 * Sat Sep 25 2021 Andreas Stieger - Mozilla Firefox 92.0.1 * Fixed: Fixes an issue where audio playback was not working on some Linux systems (bmo#1730499) * Fixed: Fixes issues with the findbar close button on different operating systems (bmo#1728368) * Mon Sep 06 2021 Wolfgang Rosenauer - Mozilla Firefox 92.0 * More secure connections: Firefox can now automatically upgrade to HTTPS using HTTPS RR as Alt-Svc headers * Full-range color levels are now supported for video playback on many systems MFSA 2021-38 (bsc#1190269) * CVE-2021-29993 (bmo#1708544, bmo#1708767, bmo#1712240, bmo#1712242, bmo#1729259) Handling custom intents could lead to crashes and UI spoofs * CVE-2021-38491 (bmo#1551886) Mixed-Content-Blocking was unable to check opaque origins * CVE-2021-38492 (bmo#1721107) Navigating to `mk:` URL scheme could load Internet Explorer * CVE-2021-38493 (bmo#1723391, bmo#1724101, bmo#1724107) Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 * CVE-2021-38494 (bmo#1723920, bmo#1725638) Memory safety bugs fixed in Firefox 92- updated appdata- remove mozilla-disable-wasm-emulate-arm-unaligned-fp-access.patch (does not apply anymore; unclear if obsolete)- bring back mozilla-silence-no-return-type.patch and run post-build-checks everywhere again- requires NSS 3.69.1 * Tue Aug 31 2021 Atri Bhattacharya - Add mozilla-bmo1708709.patch: On [wayland] popup can be wrongly repositioned due to rounding errors when font scaling != 1 (bmo#1708709); patch taken from upstream bug report and rebased to apply cleanly against current version. * Sun Aug 29 2021 Martin Liška - Bump using with GCC (tested locally). * Fri Aug 27 2021 Andreas Stieger - Mozilla Firefox 91.0.2: * Fixed: Firefox no longer clears authentication data when purging trackers, to avoid repeatedly prompting for a password (bmo#1721084) * Wed Aug 18 2021 Wolfgang Rosenauer - Mozilla Firefox 91.0.1 * Fixed an issue causing buttons on the tab bar to be resized when loading certain websites (bmo#1704404) * Fixed an issue which caused tabs from private windows to be visible in non-private windows when viewing switch-to-tab results in the address bar panel (bmo#1720369) * Various stability fixes MFSA 2021-37 (bsc#1189547) * CVE-2021-29991 (bmo#1724896) Header Splitting possible with HTTP/3 Responses * Mon Aug 09 2021 Wolfgang Rosenauer - Mozilla Firefox 91.0 MFSA 2021-33 (bsc#1188891) * CVE-2021-29986 (bmo#1696138) Race condition when resolving DNS names could have led to memory corruption * CVE-2021-29981 (bmo#1707774) Live range splitting could have led to conflicting assignments in the JIT * CVE-2021-29988 (bmo#1717922) Memory corruption as a result of incorrect style treatment * CVE-2021-29983 (bmo#1719088) Firefox for Android could get stuck in fullscreen mode * CVE-2021-29984 (bmo#1720031) Incorrect instruction reordering during JIT optimization * CVE-2021-29980 (bmo#1722204) Uninitialized memory in a canvas object could have led to memory corruption * CVE-2021-29987 (bmo#1716129) Users could have been tricked into accepting unwanted permissions on Linux * CVE-2021-29985 (bmo#1722083) Use-after-free media channels * CVE-2021-29982 (bmo#1715318) Single bit data leak due to incorrect JIT optimization and type confusion * CVE-2021-29989 (bmo#1662676, bmo#1666184, bmo#1719178, bmo#1719998, bmo#1720568) Memory safety bugs fixed in Firefox 91 and Firefox ESR 78.13 * CVE-2021-29990 (bmo#1544190, bmo#1716481, bmo#1717778, bmo#1719319, bmo#1722073) Memory safety bugs fixed in Firefox 91- requires * rustc/cargo >= 1.51 * NSPR >= 4.32 * NSS >= 3.68- force-disable webrender on BE platforms * Sat Jul 24 2021 Andreas Stieger - Mozilla Firefox 90.0.2: * Changed: Updates to support DoH Canada rollout (bmo#1713036) * Fixed: Fixed truncated output when printing (bmo#1720621) * Fixed: Fixed menu styling on some Gtk themes (bmo#1720441, bmo#1720874) * Mon Jul 19 2021 Andreas Stieger - Mozilla Firefox 90.0.1 (boo#1188480): * Fixed: Fixed busy looping processing some HTTP3 responses (bmo#1720079) * Fixed: Fixed transient errors authenticating with some smart cards (bmo#1715325) * Fixed: Fixed a rare crash on shutdown (bmo#1707057) * Fixed: Fixed a race on startup that caused about:support to end up empty after upgrade (bmo#1717894, boo#1188330) * Sun Jul 11 2021 Wolfgang Rosenauer - Mozilla Firefox 90.0 MFSA 2021-28 (bsc#1188275) * CVE-2021-29970 (bmo#1709976) Use-after-free in accessibility features of a document * CVE-2021-29971 (bmo#1713638) Granted permissions only compared host; omitting scheme and port on Android * CVE-2021-30547 (bmo#1715766) Out of bounds write in ANGLE * CVE-2021-29972 (bmo#1696816) Use of out-of-date library included use-after-free vulnerability * CVE-2021-29973 (bmo#1701932) Password autofill on HTTP websites was enabled without user interaction on Android * CVE-2021-29974 (bmo#1704843) HSTS errors could be overridden when network partitioning was enabled * CVE-2021-29975 (bmo#1713259) Text message could be overlaid on top of another website * CVE-2021-29976 (bmo#1700895, bmo#1703334, bmo#1706910, bmo#1711576, bmo#1714391) Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 * CVE-2021-29977 (bmo#1665836, bmo#1686138, bmo#1704316, bmo#1706314, bmo#1709931, bmo#1712084, bmo#1712357, bmo#1714066) Memory safety bugs fixed in Firefox 90- requires NSPR 4.31 NSS 3.66- Gtk2 support removed (was only for Flash plugin before) * Wed Jun 23 2021 Andreas Stieger - Mozilla Firefox 89.0.2 (boo#1187648): * Fix occasional hangs with Software WebRender on Linux (bmo#1708224) * Sat Jun 19 2021 Andreas Stieger - Mozilla Firefox 89.0.1 (boo#1187475): * Updated translations, including full Spanish (Mexico) localization and other improvements (bmo#1714946) * Fix various font related regressions (bmo#1694174) * Linux: Fix performance and stability regressions with WebRender (bmo#1715895, bmo#1715902) * Enterprise: Fix for the `DisableDeveloperTools` policy not having effect anymore (bmo#1715777) * Linux: Fix broken scrollbars on some GTK themes (bmo#1714103) * Various stability fixes * Sat May 29 2021 Wolfgang Rosenauer - Mozilla Firefox 89.0 * UI redesign * The Event Timing API is now supported * The CSS forced-colors media query is now supported MFSA 2021-23 (bsc#1186696) * CVE-2021-29965 (bmo#1709257) Password Manager on Firefox for Android susceptible to domain spoofing * CVE-2021-29960 (bmo#1675965) Filenames printed from private browsing mode incorrectly retained in preferences * CVE-2021-29961 (bmo#1700235) Firefox UI spoof using `