MozillaFirefox/MozillaFirefox.changes
author Wolfgang Rosenauer <wr@rosenauer.org>
Tue, 12 Apr 2016 21:14:38 +0200
branchfirefox45
changeset 907 3ccb278a9ceb
parent 906 7e9a2b678bba
child 908 b29b47737173
permissions -rw-r--r--
prepare gtk3
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
893
86f72f1e98a4 prepare Gtk3 based builds on a feature branch
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 892
diff changeset
     1
-------------------------------------------------------------------
907
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     2
Tue Apr 12 19:11:30 UTC 2016 - badshah400@gmail.com
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     3
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     4
- Compile against gtk3 depending on whether the macro
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     5
  %firefox_use_gtk3 is defined or not (e.g., at the prjconf
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     6
  level); macro is undefined by default and so gtk2 is used as the
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     7
  default toolkit.
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     8
- Add BuildRequires for additional packages needed when building
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
     9
  against gtk3: pkgconfig(glib-2.0), pkgconfig(gobject-2.0),
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
    10
  pkgconfig(gtk+-3.0) >= 3.4.0, pkgconfig(gtk+-unix-print-3.0).
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
    11
- Add firefox-gtk3_20.patch to fix appearance with gtk3 >= 3.20;
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
    12
  patch taken from Fedora (bmo#1230955).
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
    13
3ccb278a9ceb prepare gtk3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 906
diff changeset
    14
-------------------------------------------------------------------
906
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    15
Mon Apr 11 22:49:24 UTC 2016 - astieger@suse.com
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    16
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    17
- Mozilla Firefox 45.0.2:
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    18
  * Fix an issue impacting the cookie header when third-party
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    19
    cookies are blocked (bmo#1257861)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    20
  * Fix a web compatibility regression impacting the srcset
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    21
    attribute of the image tag (bmo#1259482)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    22
  * Fix a crash impacting the video playback with Media Source
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    23
    Extension (bmo#1258562)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    24
  * Fix a regression impacting some specific uploads (bmo#1255735)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    25
  * Fix a regression with the copy and paste with some old versions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    26
    of some Gecko applications like Thunderbird (bmo#1254980)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    27
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    28
-------------------------------------------------------------------
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    29
Fri Mar 18 08:52:58 UTC 2016 - astieger@suse.com
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    30
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    31
- Mozilla Firefox 45.0.1:
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    32
  * Fix a regression causing search engine settings to be lost in
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    33
    some context (bmo#1254694)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    34
  * Bring back non-standard jar: URIs to fix a regression in IBM
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    35
    iNotes (bmo#1255139)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    36
  * XSLTProcessor.importStylesheet was failing when <import> was
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    37
    used (bmo#1249572)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    38
  * Fix an issue which could cause the list of search provider to
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    39
    be empty (bmo#1255605)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    40
  * Fix a regression when using the location bar (bmo#1254503)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    41
  * Fix some loading issues when Accept third-party cookies: was
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    42
    set to Never (bmo#1254856)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    43
  * Disabled Graphite font shaping library
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    44
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    45
-------------------------------------------------------------------
904
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    46
Sun Mar  6 19:52:13 UTC 2016 - wr@rosenauer.org
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    47
906
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    48
- update to Firefox 45.0 (boo#969894)
904
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    49
  * requires NSPR 4.12 / NSS 3.21.1
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    50
  * Instant browser tab sharing through Hello
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    51
  * Synced Tabs button in button bar
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    52
  * Tabs synced via Firefox Accounts from other devices are now shown
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    53
    in dropdown area of Awesome Bar when searching
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    54
  * Introduce a new preference (network.dns.blockDotOnion) to allow
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    55
    blocking .onion at the DNS level
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
    56
  * Tab Groups (Panorama) feature removed
906
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    57
  * MFSA 2016-16/CVE-2016-1952/CVE-2016-1953
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    58
    Miscellaneous memory safety hazards
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    59
  * MFSA 2016-17/CVE-2016-1954 (bmo#1243178)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    60
    Local file overwriting and potential privilege escalation through
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    61
    CSP reports
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    62
  * MFSA 2016-18/CVE-2016-1955 (bmo#1208946)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    63
    CSP reports fail to strip location information for embedded iframe pages
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    64
  * MFSA 2016-19/CVE-2016-1956 (bmo#1199923)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    65
    Linux video memory DOS with Intel drivers
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    66
  * MFSA 2016-20/CVE-2016-1957 (bmo#1227052)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    67
    Memory leak in libstagefright when deleting an array during MP4
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    68
    processing
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    69
  * MFSA 2016-21/CVE-2016-1958 (bmo#1228754)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    70
    Displayed page address can be overridden
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    71
  * MFSA 2016-22/CVE-2016-1959 (bmo#1234949)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    72
    Service Worker Manager out-of-bounds read in Service Worker Manager
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    73
  * MFSA 2016-23/CVE-2016-1960/ZDI-CAN-3545 (bmo#1246014)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    74
    Use-after-free in HTML5 string parser
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    75
  * MFSA 2016-24/CVE-2016-1961/ZDI-CAN-3574 (bmo#1249377)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    76
    Use-after-free in SetBody
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    77
  * MFSA 2016-25/CVE-2016-1962 (bmo#1240760)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    78
    Use-after-free when using multiple WebRTC data channels
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    79
  * MFSA 2016-26/CVE-2016-1963 (bmo#1238440)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    80
    Memory corruption when modifying a file being read by FileReader
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    81
  * MFSA 2016-27/CVE-2016-1964 (bmo#1243335)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    82
    Use-after-free during XML transformations
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    83
  * MFSA 2016-28/CVE-2016-1965 (bmo#1245264)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    84
    Addressbar spoofing though history navigation and Location protocol
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    85
    property
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    86
  * MFSA 2016-29/CVE-2016-1967 (bmo#1246956)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    87
    Same-origin policy violation using perfomance.getEntries and
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    88
    history navigation with session restore
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    89
  * MFSA 2016-30/CVE-2016-1968 (bmo#1246742)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    90
    Buffer overflow in Brotli decompression
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    91
  * MFSA 2016-31/CVE-2016-1966 (bmo#1246054)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    92
    Memory corruption with malicious NPAPI plugin
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    93
  * MFSA 2016-32/CVE-2016-1970/CVE-2016-1971/CVE-2016-1975/
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    94
    CVE-2016-1976/CVE-2016-1972
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    95
    WebRTC and LibVPX vulnerabilities found through code inspection
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    96
  * MFSA 2016-33/CVE-2016-1973 (bmo#1219339)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    97
    Use-after-free in GetStaticInstance in WebRTC
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    98
  * MFSA 2016-34/CVE-2016-1974 (bmo#1228103)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
    99
    Out-of-bounds read in HTML parser following a failed allocation
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   100
  * MFSA 2016-35/CVE-2016-1950 (bmo#1245528)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   101
    Buffer overflow during ASN.1 decoding in NSS
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   102
    (fixed by requiring 3.21.1)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   103
  * MFSA 2016-36/CVE-2016-1979 (bmo#1185033)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   104
    Use-after-free during processing of DER encoded keys in NSS
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   105
    (fixed by requiring 3.21.1)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   106
  * MFSA 2016-37/CVE-2016-1977/CVE-2016-2790/CVE-2016-2791/
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   107
    CVE-2016-2792/CVE-2016-2793/CVE-2016-2794/CVE-2016-2795/
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   108
    CVE-2016-2796/CVE-2016-2797/CVE-2016-2798/CVE-2016-2799/
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   109
    CVE-2016-2800/CVE-2016-2801/CVE-2016-2802
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 904
diff changeset
   110
    Font vulnerabilities in the Graphite 2 library
904
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
   111
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
   112
-------------------------------------------------------------------
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
   113
Sat Mar  5 15:27:00 UTC 2016 - olaf@aepfle.de
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
   114
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
   115
- Remove B_CNT from symbols.zip filename to reduce build-compare noise
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
   116
6a889427cd4f 45.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 903
diff changeset
   117
-------------------------------------------------------------------
903
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   118
Fri Feb 26 16:22:52 UTC 2016 - astieger@suse.com
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   119
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   120
- fix build problems on i586, caused by too large unified compile
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   121
  units - adding mozilla-reduce-files-per-UnifiedBindings.patch
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   122
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   123
-------------------------------------------------------------------
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   124
Thu Feb 11 07:51:34 UTC 2016 - wr@rosenauer.org
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   125
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   126
- update to Firefox 44.0.2
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   127
  * MFSA 2016-13/CVE-2016-1949 (bmo#1245724, boo#966438)
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   128
    Same-origin-policy violation using Service Workers with plugins
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   129
  * Fix issue which could lead to the removal of stored passwords
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   130
    under certain circumstances (bmo#1242176)
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   131
  * Allows spaces in cookie names (bmo#1244505)
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   132
  * Disable opus/vorbis audio with H.264 (bmo#1245696)
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   133
  * Fix for graphics startup crash (GNU/Linux) (bmo#1222171)
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   134
  * Fix a crash in cache networking (bmo#1244076)
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   135
  * Fix using WebSockets in service worker controlled pages (bmo#1243942)
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   136
83801946c93f 44.0.2 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 902
diff changeset
   137
-------------------------------------------------------------------
900
91466ca5c8d9 latest merge from firefox43
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 899 897
diff changeset
   138
Sun Jan 24 09:33:15 UTC 2016 - wr@rosenauer.org
91466ca5c8d9 latest merge from firefox43
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 899 897
diff changeset
   139
902
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   140
- update to Firefox 44.0
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   141
  * MFSA 2016-01/CVE-2016-1930/CVE-2016-1931 boo#963633
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   142
    Miscellaneous memory safety hazards
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   143
  * MFSA 2016-02/CVE-2016-1933 (bmo#1231761) boo#963634
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   144
    Out of Memory crash when parsing GIF format images
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   145
  * MFSA 2016-03/CVE-2016-1935 (bmo#1220450) boo#963635
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   146
    Buffer overflow in WebGL after out of memory allocation
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   147
  * MFSA 2016-04/CVE-2015-7208/CVE-2016-1939 (bmo#1191423, bmo#1233784) boo#963637
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   148
    Firefox allows for control characters to be set in cookie names
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   149
  * MFSA 2016-06/CVE-2016-1937 (bmo#724353) boo#963641
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   150
    Missing delay following user click events in protocol handler dialog
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   151
  * MFSA 2016-07/CVE-2016-1938 (bmo#1190248) boo#963731
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   152
    Errors in mp_div and mp_exptmod cryptographic functions in NSS
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   153
    (fixed by requiring NSS 3.21)
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   154
  * MFSA 2016-09/CVE-2016-1942/CVE-2016-1943 (bmo#1189082, bmo#1228590)
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   155
    Addressbar spoofing attacks boo#963643
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   156
  * MFSA 2016-10/CVE-2016-1944/CVE-2016-1945/CVE-2016-1946
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   157
    (bmo#1186621, bmo#1214782, bmo#1232096) boo#963644
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   158
    Unsafe memory manipulation found through code inspection
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   159
  * MFSA 2016-11/CVE-2016-1947 (bmo#1237103) boo#963645
11475705ab0f 44.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 900
diff changeset
   160
    Application Reputation service disabled in Firefox 43
899
44a28160de40 prepare 44.0b9
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   161
  * requires NSPR 4.11
44a28160de40 prepare 44.0b9
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   162
  * requires NSS 3.21
896
2b664b26b6b2 change was after submission
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 895
diff changeset
   163
- prepare mozilla-kde.patch for Gtk3 builds
899
44a28160de40 prepare 44.0b9
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   164
- rebased patches
896
2b664b26b6b2 change was after submission
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 895
diff changeset
   165
2b664b26b6b2 change was after submission
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 895
diff changeset
   166
-------------------------------------------------------------------
897
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   167
Mon Jan 11 08:04:24 UTC 2016 - astieger@suse.com
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   168
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   169
- Mozilla Firefox 43.0.4:
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   170
  * Re-enable SHA-1 certificates to prevent outdated
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   171
    man-in-the-middle security devices from interfering with
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   172
    properly secured SSL/TLS connections (bmo#1236975)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   173
  * Fix for startup crash for users of a third party antivirus tool
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   174
    (bmo#1235537)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   175
- The following change was previously in the package as a patch:
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   176
  * Multi-user GNU/Linux download folders can be created
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   177
   (bmo#1233434), removed mozilla-bmo1233434.patch
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   178
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 896
diff changeset
   179
-------------------------------------------------------------------
895
b0e57b478b1b merge change from mozilla:Factory (libXcomposite-devel requirement)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 894
diff changeset
   180
Tue Dec 29 20:29:35 UTC 2015 - wr@rosenauer.org
892
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   181
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   182
- update to Firefox 43.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   183
  * requires NSS 3.20.2 to fix
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   184
    MFSA 2015-150/CVE-2015-7575 (bmo#1158489)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   185
    MD5 signatures accepted within TLS 1.2 ServerKeyExchange in
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   186
    server signature
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   187
  * various changes to support Windows update (SHA-1 vs. SHA-2)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   188
  * workaround Youtube user agent detection issue (bmo#1233970)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   189
- fix file download regression for multi user systems
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   190
  (bmo#1233434) (mozilla-bmo1233434.patch)
895
b0e57b478b1b merge change from mozilla:Factory (libXcomposite-devel requirement)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 894
diff changeset
   191
- explicitely requires libXcomposite-devel
892
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   192
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 890
diff changeset
   193
-------------------------------------------------------------------
890
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   194
Sun Dec 13 23:07:56 UTC 2015 - wr@rosenauer.org
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   195
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   196
- update to Firefox 43.0 (bnc#959277)
889
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   197
  * Improved API support for m4v video playback
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   198
  * Users can opt-in to receive search suggestions from the Awesome Bar
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   199
  * WebRTC streaming on multiple monitors
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   200
  * User selectable second block list for Private Browsing's Tracking
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   201
    Protection
890
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   202
  security fixes:
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   203
  * MFSA 2015-134/CVE-2015-7201/CVE-2015-7202
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   204
    Miscellaneous memory safety hazards
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   205
  * MFSA 2015-135/CVE-2015-7204 (bmo#1216130)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   206
    Crash with JavaScript variable assignment with unboxed objects
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   207
  * MFSA 2015-136/CVE-2015-7207 (bmo#1185256)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   208
    Same-origin policy violation using perfomance.getEntries and
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   209
    history navigation
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   210
  * MFSA 2015-137/CVE-2015-7208 (bmo#1191423)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   211
    Firefox allows for control characters to be set in cookies
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   212
  * MFSA 2015-138/CVE-2015-7210 (bmo#1218326)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   213
    Use-after-free in WebRTC when datachannel is used after being
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   214
    destroyed
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   215
  * MFSA 2015-139/CVE-2015-7212 (bmo#1222809)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   216
    Integer overflow allocating extremely large textures
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   217
  * MFSA 2015-140/CVE-2015-7215 (bmo#1160890)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   218
    Cross-origin information leak through web workers error events
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   219
  * MFSA 2015-141/CVE-2015-7211 (bmo#1221444)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   220
    Hash in data URI is incorrectly parsed
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   221
  * MFSA 2015-142/CVE-2015-7218/CVE-2015-7219 (bmo#1194818, bmo#1194820)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   222
    DOS due to malformed frames in HTTP/2
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   223
  * MFSA 2015-143/CVE-2015-7216/CVE-2015-7217 (bmo#1197059, bmo#1203078)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   224
    Linux file chooser crashes on malformed images due to flaws in
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   225
    Jasper library
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   226
  * MFSA 2015-144/CVE-2015-7203/CVE-2015-7220/CVE-2015-7221
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   227
    (bmo#1201183, bmo#1178033, bmo#1199400)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   228
    Buffer overflows found through code inspection
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   229
  * MFSA 2015-145/CVE-2015-7205 (bmo#1220493)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   230
    Underflow through code inspection
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   231
  * MFSA 2015-146/CVE-2015-7213 (bmo#1206211)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   232
    Integer overflow in MP4 playback in 64-bit versions
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   233
  * MFSA 2015-147/CVE-2015-7222 (bmo#1216748)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   234
    Integer underflow and buffer overflow processing MP4 metadata in
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   235
    libstagefright
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   236
  * MFSA 2015-148/CVE-2015-7223 (bmo#1226423)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   237
    Privilege escalation vulnerabilities in WebExtension APIs
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   238
  * MFSA 2015-149/CVE-2015-7214 (bmo#1228950)
4ba0eb6a14ca 43.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 889
diff changeset
   239
    Cross-site reading attack through data and view-source URIs
889
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   240
- rebased patches
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   241
de3a92aed259 43.0b9 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 886
diff changeset
   242
-------------------------------------------------------------------
886
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   243
Sun Nov 15 19:52:20 UTC 2015 - wr@rosenauer.org
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   244
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   245
- Add desktop menu action for private browsing window to desktop
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   246
  file (boo#954747)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   247
- remove obsolete patch mozilla-bmo1005535.patch completely from
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   248
  source package to avoid automatic check failures
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   249
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   250
-------------------------------------------------------------------
885
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   251
Sat Oct 31 19:50:03 UTC 2015 - wr@rosenauer.org
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   252
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   253
- update to Firefox 42.0 (bnc#952810)
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   254
  * Private Browsing with Tracking Protection blocks certain Web
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   255
    elements that could be used to record your behavior across sites
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   256
  * Control Center that contains site security and privacy controls
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   257
  * Login Manager improvements
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   258
  * WebRTC improvements
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   259
  * Indicator added to tabs that play audio with one-click muting
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   260
  * Media Source Extension for HTML5 video available for all sites
886
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   261
  security fixes:
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   262
  * MFSA 2015-116/CVE-2015-4513/CVE-2015-4514
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   263
    Miscellaneous memory safety hazards
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   264
  * MFSA 2015-117/CVE-2015-4515 (bmo#1046421)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   265
    Information disclosure through NTLM authentication
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   266
  * MFSA 2015-118/CVE-2015-4518 (bmo#1182778, bmo#1136692)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   267
    CSP bypass due to permissive Reader mode whitelist
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   268
  * MFSA 2015-119/CVE-2015-7185 (bmo#1149000) (Android only)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   269
    Firefox for Android addressbar can be removed after fullscreen mode
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   270
  * MFSA 2015-120/CVE-2015-7186 (bmo#1193027) (Android only)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   271
    Reading sensitive profile files through local HTML file on Android
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   272
  * MFSA 2015-121/CVE-2015-7187 (bmo#1195735)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   273
    disabling scripts in Add-on SDK panels has no effect
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   274
  * MFSA 2015-122/CVE-2015-7188 (bmo#1199430)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   275
    Trailing whitespace in IP address hostnames can bypass same-origin policy
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   276
  * MFSA 2015-123/CVE-2015-7189 (bmo#1205900)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   277
    Buffer overflow during image interactions in canvas
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   278
  * MFSA 2015-124/CVE-2015-7190 (bmo#1208520) (Android only)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   279
    Android intents can be used on Firefox for Android to open privileged files
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   280
  * MFSA 2015-125/CVE-2015-7191 (bmo#1208956) (Android only)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   281
    XSS attack through intents on Firefox for Android
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   282
  * MFSA 2015-126/CVE-2015-7192 (bmo#1210023) (OS X only)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   283
    Crash when accessing HTML tables with accessibility tools on OS X
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   284
  * MFSA 2015-127/CVE-2015-7193 (bmo#1210302)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   285
    CORS preflight is bypassed when non-standard Content-Type headers
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   286
    are received
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   287
  * MFSA 2015-128/CVE-2015-7194 (bmo#1211262)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   288
    Memory corruption in libjar through zip files
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   289
  * MFSA 2015-129/CVE-2015-7195 (bmo#1211871)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   290
    Certain escaped characters in host of Location-header are being
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   291
    treated as non-escaped
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   292
  * MFSA 2015-130/CVE-2015-7196 (bmo#1140616)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   293
    JavaScript garbage collection crash with Java applet
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   294
  * MFSA 2015-131/CVE-2015-7198/CVE-2015-7199/CVE-2015-7200
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   295
    (bmo#1188010, bmo#1204061, bmo#1204155)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   296
    Vulnerabilities found through code inspection
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   297
  * MFSA 2015-132/CVE-2015-7197 (bmo#1204269)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   298
    Mixed content WebSocket policy bypass through workers
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   299
  * MFSA 2015-133/CVE-2015-7181/CVE-2015-7182/CVE-2015-7183
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   300
    (bmo#1202868, bmo#1205157)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   301
    NSS and NSPR memory corruption issues
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   302
    (fixed in mozilla-nspr and mozilla-nss packages)
2e9f984bca7f changelogs and desktop file changes
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 885
diff changeset
   303
- requires NSPR >= 4.10.10 and NSS >= 3.19.4
885
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   304
- removed obsolete patches
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   305
  * mozilla-arm-disable-edsp.patch
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   306
  * mozilla-icu-strncat.patch
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   307
  * mozilla-skia-be-le.patch
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   308
  * toolkit-download-folder.patch
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   309
- fixed build with enable-libproxy (bmo#1220399)
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   310
  * mozilla-libproxy.patch
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   311
ee3c462047d5 42 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 884
diff changeset
   312
-------------------------------------------------------------------
884
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   313
Thu Oct 15 08:25:54 UTC 2015 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   314
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   315
- update to Firefox 41.0.2 (bnc#950686)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   316
  * MFSA 2015-115/CVE-2015-7184 (bmo#1208339, bmo#1212669)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   317
    Cross-origin restriction bypass using Fetch
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   318
- added explicit appdata provides (bnc#949983)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   319
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   320
-------------------------------------------------------------------
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   321
Sun Oct  4 09:20:56 UTC 2015 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   322
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   323
- do not build with --enable-stdcxx-compat
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   324
  (this starts to fail build on various toolchain combinations
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   325
  and is not required for openSUSE builds in general
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   326
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   327
-------------------------------------------------------------------
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   328
Thu Oct  1 09:49:57 UTC 2015 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   329
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   330
- update to Firefox 41.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   331
  * Fix a startup crash related to Yandex toolbar and Adblock Plus
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   332
    (bmo#1209124)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   333
  * Fix potential hangs with Flash plugins (bmo#1185639)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   334
  * Fix a regression in the bookmark creation (bmo#1206376)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   335
  * Fix a startup crash with some Intel Media Accelerator 3150
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   336
    graphic cards (bmo#1207665)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   337
  * Fix a graphic crash, occurring occasionally on Facebook (bmo#1178601)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   338
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 883
diff changeset
   339
-------------------------------------------------------------------
883
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   340
Sat Sep 19 20:23:29 UTC 2015 - wr@rosenauer.org
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   341
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   342
- update to Firefox 41.0 (bnc#947003)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   343
  * MFSA 2015-96/CVE-2015-4500/CVE-2015-4501
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   344
    Miscellaneous memory safety hazards
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   345
  * MFSA 2015-97/CVE-2015-4503 (bmo#994337)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   346
    Memory leak in mozTCPSocket to servers
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   347
  * MFSA 2015-98/CVE-2015-4504 (bmo#1132467)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   348
    Out of bounds read in QCMS library with ICC V4 profile attributes
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   349
  * MFSA 2015-99/CVE-2015-4476 (bmo#1162372) (Android only)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   350
    Site attribute spoofing on Android by pasting URL with unknown scheme
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   351
  * MFSA 2015-100/CVE-2015-4505 (bmo#1177861) (Windows only)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   352
    Arbitrary file manipulation by local user through Mozilla updater
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   353
  * MFSA 2015-101/CVE-2015-4506 (bmo#1192226)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   354
    Buffer overflow in libvpx while parsing vp9 format video
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   355
  * MFSA 2015-102/CVE-2015-4507 (bmo#1192401)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   356
    Crash when using debugger with SavedStacks in JavaScript
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   357
  * MFSA 2015-103/CVE-2015-4508 (bmo#1195976)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   358
    URL spoofing in reader mode
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   359
  * MFSA 2015-104/CVE-2015-4510 (bmo#1200004)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   360
    Use-after-free with shared workers and IndexedDB
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   361
  * MFSA 2015-105/CVE-2015-4511 (bmo#1200148)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   362
    Buffer overflow while decoding WebM video
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   363
  * MFSA 2015-106/CVE-2015-4509 (bmo#1198435)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   364
    Use-after-free while manipulating HTML media content
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   365
  * MFSA 2015-107/CVE-2015-4512 (bmo#1170390)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   366
    Out-of-bounds read during 2D canvas display on Linux 16-bit
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   367
    color depth systems
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   368
  * MFSA 2015-108/CVE-2015-4502 (bmo#1105045)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   369
    Scripted proxies can access inner window
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   370
  * MFSA 2015-109/CVE-2015-4516 (bmo#904886)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   371
    JavaScript immutable property enforcement can be bypassed
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   372
  * MFSA 2015-110/CVE-2015-4519 (bmo#1189814)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   373
    Dragging and dropping images exposes final URL after redirects
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   374
  * MFSA 2015-111/CVE-2015-4520 (bmo#1200856, bmo#1200869)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   375
    Errors in the handling of CORS preflight request headers
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   376
  * MFSA 2015-112/CVE-2015-4517/CVE-2015-4521/CVE-2015-4522/
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   377
    CVE-2015-7174/CVE-2015-7175/CVE-2015-7176/CVE-2015-7177/
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   378
    CVE-2015-7180
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   379
    Vulnerabilities found through code inspection
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   380
  * MFSA 2015-113/CVE-2015-7178/CVE-2015-7179 (bmo#1189860,
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   381
    bmo#1190526) (Windows only)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   382
    Memory safety errors in libGLES in the ANGLE graphics library
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   383
  * MFSA 2015-114 (bmo#1167498, bmo#1153672) (Windows only)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   384
    Information disclosure via the High Resolution Time API
882
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 875
diff changeset
   385
- rebased patches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 875
diff changeset
   386
- removed obsolete patches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 875
diff changeset
   387
  * mozilla-arm64-libjpeg-turbo.patch
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 875
diff changeset
   388
883
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   389
------------------------------------------------------------------
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   390
Thu Aug 27 06:03:51 UTC 2015 - wr@rosenauer.org
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   391
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   392
- update to Firefox 40.0.3 (bnc#943550)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   393
  * Disable the asynchronous plugin initialization (bmo#1198590)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   394
  * Fix a segmentation fault in the GStreamer support (bmo#1145230)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   395
  * Fix a regression with some Japanese fonts used in the <input>
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   396
    field (bmo#1194055)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   397
  * On some sites, the selection in a select combox box using the
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   398
    mouse could be broken (bmo#1194733)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   399
  security fixes
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   400
  * MFSA 2015-94/CVE-2015-4497 (bmo#1164766, bmo#1175278)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   401
    Use-after-free when resizing canvas element during restyling
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   402
  * MFSA 2015-95/CVE-2015-4498 (bmo#1042699)
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   403
    Add-on notification bypass through data URLs
7aa7715fdc8f 41.0 release and changelogs
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 882
diff changeset
   404
882
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 875
diff changeset
   405
-------------------------------------------------------------------
875
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   406
Fri Aug  7 07:49:49 UTC 2015 - wr@rosenauer.org
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   407
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   408
- update to Firefox 40.0 (bnc#940806)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   409
  * Added protection against unwanted software downloads
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   410
  * Suggested Tiles show sites of interest, based on categories
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   411
    from your recent browsing history
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   412
  * Hello allows adding a link to conversations to provide context
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   413
    on what the conversation will be about
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   414
  * New style for add-on manager based on the in-content
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   415
    preferences style
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   416
  * Improved scrolling, graphics, and video playback performance
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   417
    with off main thread compositing (GNU/Linux only)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   418
  * Graphic blocklist mechanism improved: Firefox version ranges
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   419
    can be specified, limiting the number of devices blocked
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   420
  security fixes:
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   421
  * MFSA 2015-79/CVE-2015-4473/CVE-2015-4474
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   422
    Miscellaneous memory safety hazards
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   423
  * MFSA 2015-80/CVE-2015-4475 (bmo#1175396)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   424
    Out-of-bounds read with malformed MP3 file
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   425
  * MFSA 2015-81/CVE-2015-4477 (bmo#1179484)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   426
    Use-after-free in MediaStream playback
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   427
  * MFSA 2015-82/CVE-2015-4478 (bmo#1105914)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   428
    Redefinition of non-configurable JavaScript object properties
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   429
  * MFSA 2015-83/CVE-2015-4479/CVE-2015-4480/CVE-2015-4493
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   430
    Overflow issues in libstagefright
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   431
  * MFSA 2015-84/CVE-2015-4481 (bmo1171518)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   432
    Arbitrary file overwriting through Mozilla Maintenance Service
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   433
    with hard links (only affected Windows)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   434
  * MFSA 2015-85/CVE-2015-4482 (bmo#1184500)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   435
    Out-of-bounds write with Updater and malicious MAR file
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   436
    (does not affect openSUSE RPM packages which do not ship the
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   437
     updater)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   438
  * MFSA 2015-86/CVE-2015-4483 (bmo#1148732)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   439
    Feed protocol with POST bypasses mixed content protections
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   440
  * MFSA 2015-87/CVE-2015-4484 (bmo#1171540)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   441
    Crash when using shared memory in JavaScript
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   442
  * MFSA 2015-88/CVE-2015-4491 (bmo#1184009)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   443
    Heap overflow in gdk-pixbuf when scaling bitmap images
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   444
  * MFSA 2015-89/CVE-2015-4485/CVE-2015-4486 (bmo#1177948, bmo#1178148)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   445
    Buffer overflows on Libvpx when decoding WebM video
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   446
  * MFSA 2015-90/CVE-2015-4487/CVE-2015-4488/CVE-2015-4489
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   447
    Vulnerabilities found through code inspection
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   448
  * MFSA 2015-91/CVE-2015-4490 (bmo#1086999)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   449
    Mozilla Content Security Policy allows for asterisk wildcards
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   450
    in violation of CSP specification
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   451
  * MFSA 2015-92/CVE-2015-4492 (bmo#1185820)
2d6ccc01ea9e 40.0 final
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 872
diff changeset
   452
    Use-after-free in XMLHttpRequest with shared workers
869
0dd25a92df97 working FF 40 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 868
diff changeset
   453
- added mozilla-no-stdcxx-check.patch
0dd25a92df97 working FF 40 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 868
diff changeset
   454
- removed obsolete patches
868
284da266ec46 40beta rebase
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 867
diff changeset
   455
  * mozilla-add-glibcxx_use_cxx11_abi.patch
869
0dd25a92df97 working FF 40 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 868
diff changeset
   456
  * firefox-multilocale-chrome.patch
868
284da266ec46 40beta rebase
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 867
diff changeset
   457
- rebased patches
869
0dd25a92df97 working FF 40 build
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 868
diff changeset
   458
- requires version 40 of the branding package
871
4c6e8495720b beta update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 869
diff changeset
   459
- removed browser/searchplugins/ location as it's not valid anymore
867
3af93b7e5e3d merge from firefox39 and switch to 40beta branch
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   460
3af93b7e5e3d merge from firefox39 and switch to 40beta branch
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   461
-------------------------------------------------------------------
870
09ffe9247f8a FF 39.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   462
Fri Aug  7 07:09:39 UTC 2015 - wr@rosenauer.org
09ffe9247f8a FF 39.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   463
09ffe9247f8a FF 39.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   464
- security update to Firefox 39.0.3 (bnc#940918)
09ffe9247f8a FF 39.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   465
  * MFSA 2015-78/CVE-2015-4495 (bmo#1179262, bmo#1178058)
09ffe9247f8a FF 39.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   466
    Same origin violation and local file stealing via PDF reader
09ffe9247f8a FF 39.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   467
09ffe9247f8a FF 39.0.3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 866
diff changeset
   468
-------------------------------------------------------------------
866
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   469
Wed Jul  1 06:43:02 UTC 2015 - wr@rosenauer.org
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   470
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   471
- update to Firefox 39.0 (bnc#935979)
863
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   472
  * Share Hello URLs with social networks
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   473
  * Support for 'switch' role in ARIA 1.1 (web accessibility)
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   474
  * SafeBrowsing malware detection lookups enabled for downloads
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   475
    (Mac OS X and Linux)
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   476
  * Support for new Unicode 8.0 skin tone emoji
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   477
  * Removed support for insecure SSLv3 for network communications
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   478
  * Disable use of RC4 except for temporarily whitelisted hosts
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   479
  * NPAPI Plug-in performance improved via asynchronous initialization
866
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   480
  security fixes:
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   481
  * MFSA 2015-59/CVE-2015-2724/CVE-2015-2725/CVE-2015-2726
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   482
    Miscellaneous memory safety hazards
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   483
  * MFSA 2015-60/CVE-2015-2727 (bmo#1163422)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   484
    Local files or privileged URLs in pages can be opened into new tabs
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   485
  * MFSA 2015-61/CVE-2015-2728 (bmo#1142210)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   486
    Type confusion in Indexed Database Manager
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   487
  * MFSA 2015-62/CVE-2015-2729 (bmo#1122218)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   488
    Out-of-bound read while computing an oscillator rendering range in Web Audio
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   489
  * MFSA 2015-63/CVE-2015-2731 (bmo#1149891)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   490
    Use-after-free in Content Policy due to microtask execution error
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   491
  * MFSA 2015-64/CVE-2015-2730 (bmo#1125025)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   492
    ECDSA signature validation fails to handle some signatures correctly
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   493
    (this fix is shipped by NSS 3.19.1 externally)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   494
  * MFSA 2015-65/CVE-2015-2722/CVE-2015-2733 (bmo#1166924, bmo#1169867)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   495
    Use-after-free in workers while using XMLHttpRequest
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   496
  * MFSA 2015-66/CVE-2015-2734/CVE-2015-2735/CVE-2015-2736/CVE-2015-2737
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   497
    CVE-2015-2738/CVE-2015-2739/CVE-2015-2740
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   498
    Vulnerabilities found through code inspection
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   499
  * MFSA 2015-67/CVE-2015-2741 (bmo#1147497)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   500
    Key pinning is ignored when overridable errors are encountered
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   501
  * MFSA 2015-68/CVE-2015-2742 (bmo#1138669)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   502
    OS X crash reports may contain entered key press information
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   503
    (not relevant under Linux)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   504
  * MFSA 2015-69/CVE-2015-2743 (bmo#1163109)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   505
    Privilege escalation in PDF.js
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   506
  * MFSA 2015-70/CVE-2015-4000 (bmo#1138554)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   507
    NSS accepts export-length DHE keys with regular DHE cipher suites
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   508
    (this fix is shipped by NSS 3.19.1 externally)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   509
  * MFSA 2015-71/CVE-2015-2721 (bmo#1086145)
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   510
    NSS incorrectly permits skipping of ServerKeyExchange
28eb9d3ab7e8 39.0 final with changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 863
diff changeset
   511
    (this fix is shipped by NSS 3.19.1 externally)
857
ab297940ae8a rebased to 39.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 855
diff changeset
   512
- dropped mozilla-prefer_plugin_pref.patch as this feature is
ab297940ae8a rebased to 39.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 855
diff changeset
   513
  likely not worth maintaining further
ab297940ae8a rebased to 39.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 855
diff changeset
   514
- rebased patches
863
d5a1c8dec7ed Firefox 39.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 862
diff changeset
   515
- require NSS 3.19.2
857
ab297940ae8a rebased to 39.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 855
diff changeset
   516
ab297940ae8a rebased to 39.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 855
diff changeset
   517
-------------------------------------------------------------------
862
390088186660 mozilla-arm64-libjpeg-turbo.patch: fix libjpeg-turbo configuration
Andreas Schwab <schwab@suse.de>
parents: 861
diff changeset
   518
Thu Jun 18 10:30:18 UTC 2015 - schwab@suse.de
390088186660 mozilla-arm64-libjpeg-turbo.patch: fix libjpeg-turbo configuration
Andreas Schwab <schwab@suse.de>
parents: 861
diff changeset
   519
390088186660 mozilla-arm64-libjpeg-turbo.patch: fix libjpeg-turbo configuration
Andreas Schwab <schwab@suse.de>
parents: 861
diff changeset
   520
- mozilla-arm64-libjpeg-turbo.patch: fix libjpeg-turbo configuration
390088186660 mozilla-arm64-libjpeg-turbo.patch: fix libjpeg-turbo configuration
Andreas Schwab <schwab@suse.de>
parents: 861
diff changeset
   521
390088186660 mozilla-arm64-libjpeg-turbo.patch: fix libjpeg-turbo configuration
Andreas Schwab <schwab@suse.de>
parents: 861
diff changeset
   522
-------------------------------------------------------------------
854
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 853
diff changeset
   523
Sun Jun  7 07:09:12 UTC 2015 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 853
diff changeset
   524
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 853
diff changeset
   525
- update to Firefox 38.0.6
855
1f860c829900 correct changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 854
diff changeset
   526
  * fixes bmo#1171730 which is not really relevant to oS builds
1f860c829900 correct changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 854
diff changeset
   527
- fix KDE regression from 38.0.5 builds (bsc#933439)
854
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 853
diff changeset
   528
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 853
diff changeset
   529
-------------------------------------------------------------------
853
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   530
Sat May 23 21:13:49 UTC 2015 - wr@rosenauer.org
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   531
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   532
- update to Firefox 38.0.5
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   533
  * Keep track of articles and videos with Pocket
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   534
  * Clean formatting for articles and blog posts with Reader View
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   535
  * Share the active tab or window in a Hello conversation
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   536
- add changes file as source for SRPM (bsc#932142)
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   537
cf7e96afbe3a Firefox 38.0.5
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 852
diff changeset
   538
-------------------------------------------------------------------
852
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   539
Fri May 15 10:40:19 UTC 2015 - normand@linux.vnet.ibm.com
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   540
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   541
- add mozilla-add-glibcxx_use_cxx11_abi.patch grabbed from
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   542
  https://bugzilla.mozilla.org/show_bug.cgi?id=1153109
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   543
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   544
-------------------------------------------------------------------
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   545
Fri May 15 07:37:46 UTC 2015 - wr@rosenauer.org
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   546
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   547
- update to Firefox 38.0.1
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   548
  stability and regression fixes
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   549
  * Systems with first generation NVidia Optimus graphics cards
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   550
    may crash on start-up
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   551
  * Users who import cookies from Google Chrome can end up with
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   552
    broken websites
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   553
  * Large animated images may fail to play and may stop other
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   554
    images from loading
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   555
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   556
-------------------------------------------------------------------
851
0855c4ac4793 Firefox 38.0
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 850
diff changeset
   557
Sun May 10 07:07:49 UTC 2015 - wr@rosenauer.org
0855c4ac4793 Firefox 38.0
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 850
diff changeset
   558
852
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   559
- update to Firefox 38.0 (bnc#930622)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   560
  * New tab-based preferences
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   561
  * Ruby annotation support
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   562
  * more info: https://www.mozilla.org/en-US/firefox/38.0/releasenotes/
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   563
  security fixes:
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   564
  * MFSA 2015-46/CVE-2015-2708/CVE-2015-2709
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   565
    Miscellaneous memory safety hazards
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   566
  * MFSA 2015-47/VE-2015-0797 (bmo#1080995)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   567
    Buffer overflow parsing H.264 video with Linux Gstreamer
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   568
  * MFSA 2015-48/CVE-2015-2710 (bmo#1149542)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   569
    Buffer overflow with SVG content and CSS
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   570
  * MFSA 2015-49/CVE-2015-2711 (bmo#1113431)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   571
    Referrer policy ignored when links opened by middle-click and
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   572
    context menu
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   573
  * MFSA 2015-50/CVE-2015-2712 (bmo#1152280)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   574
    Out-of-bounds read and write in asm.js validation
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   575
  * MFSA 2015-51/CVE-2015-2713 (bmo#1153478)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   576
    Use-after-free during text processing with vertical text enabled
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   577
  * MFSA 2015-53/CVE-2015-2715 (bmo#988698)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   578
    Use-after-free due to Media Decoder Thread creation during shutdown
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   579
  * MFSA 2015-54/CVE-2015-2716 (bmo#1140537)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   580
    Buffer overflow when parsing compressed XML
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   581
  * MFSA 2015-55/CVE-2015-2717 (bmo#1154683)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   582
    Buffer overflow and out-of-bounds read while parsing MP4 video
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   583
    metadata
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   584
  * MFSA 2015-56/CVE-2015-2718 (bmo#1146724)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   585
    Untrusted site hosting trusted page can intercept webchannel
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   586
    responses
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   587
  * MFSA 2015-57/CVE-2011-3079 (bmo#1087565)
e11af0d6cb48 38.0.1 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 851
diff changeset
   588
    Privilege escalation through IPC channel messages
850
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   589
- requires NSS 3.18.1
851
0855c4ac4793 Firefox 38.0
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 850
diff changeset
   590
- removed obsolete patches:
0855c4ac4793 Firefox 38.0
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 850
diff changeset
   591
  * mozilla-skia-bmo1136958.patch
0855c4ac4793 Firefox 38.0
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 850
diff changeset
   592
- remove gnomevfs build options as it is removed from sources
0855c4ac4793 Firefox 38.0
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 850
diff changeset
   593
- rebased patches
850
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   594
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   595
-------------------------------------------------------------------
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   596
Fri Apr 17 16:39:20 UTC 2015 - wr@rosenauer.org
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   597
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   598
- update to Firefox 37.0.2 (bnc#928116)
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   599
  * MFSA 2015-45/CVE-2015-2706 (bmo#1141081)
a2bdff616a0e prepare 38beta
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 845
diff changeset
   600
    Memory corruption during failed plugin initialization
845
a704b2a17e39 38.0 beta series
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 844
diff changeset
   601
a704b2a17e39 38.0 beta series
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 844
diff changeset
   602
-------------------------------------------------------------------
844
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   603
Fri Apr  3 08:27:24 UTC 2015 - wr@rosenauer.org
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   604
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   605
- update to Firefox 37.0.1 (bnc#926166)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   606
  * MFSA 2015-43/CVE-2015-0798 (bmo#1147597) (Android only)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   607
    Loading privileged content through Reader mode
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   608
  * MFSA 2015-44/CVE-2015-0799 (bmo#1148328)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   609
    Certificate verification bypass through the HTTP/2 Alt-Svc header
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   610
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   611
-------------------------------------------------------------------
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   612
Sat Mar 28 09:46:48 UTC 2015 - wr@rosenauer.org
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   613
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   614
- update to Firefox 37.0 (bnc#925368)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   615
  * Heartbeat user rating system
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   616
  * Yandex set as default search provider for the Turkish locale
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   617
  * Bing search now uses HTTPS for secure searching
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   618
  * Improved protection against site impersonation via OneCRL
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   619
    centralized certificate revocation
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   620
  * Opportunistically encrypt HTTP traffic where the server supports
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   621
    HTTP/2 AltSvc
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   622
  * some more behaviour changes for TLS
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   623
  security fixes:
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   624
  * MFSA 2015-30/CVE-2015-0814/CVE-2015-0815
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   625
    Miscellaneous memory safety hazards
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   626
  * MFSA 2015-31/CVE-2015-0813 (bmo#1106596))
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   627
    Use-after-free when using the Fluendo MP3 GStreamer plugin
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   628
  * MFSA 2015-32/CVE-2015-0812 (bmo#1128126)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   629
    Add-on lightweight theme installation approval bypassed through
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   630
    MITM attack
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   631
  * MFSA 2015-33/CVE-2015-0816 (bmo#1144991)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   632
    resource:// documents can load privileged pages
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   633
  * MFSA-2015-34/CVE-2015-0811 (bmo#1132468)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   634
    Out of bounds read in QCMS library
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   635
  * MFSA-2015-35/CVE-2015-0810 (bmo#1125013)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   636
    Cursor clickjacking with flash and images (OS X only)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   637
  * MFSA-2015-36/CVE-2015-0808 (bmo#1109552)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   638
    Incorrect memory management for simple-type arrays in WebRTC
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   639
  * MFSA-2015-37/CVE-2015-0807 (bmo#1111834)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   640
    CORS requests should not follow 30x redirections after preflight
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   641
  * MFSA-2015-38/CVE-2015-0805/CVE-2015-0806 (bmo#1135511, bmo#1099437)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   642
    Memory corruption crashes in Off Main Thread Compositing
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   643
  * MFSA-2015-39/CVE-2015-0803/CVE-2015-0804 (bmo#1134560)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   644
    Use-after-free due to type confusion flaws
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   645
  * MFSA-2015-40/CVE-2015-0801 (bmo#1146339)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   646
    Same-origin bypass through anchor navigation
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   647
  * MFSA-2015-41/CVE-2015-0800/CVE-2012-2808
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   648
    PRNG weakness allows for DNS poisoning on Android (only)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   649
  * MFSA-2015-42/CVE-2015-0802 (bmo#1124898)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   650
    Windows can retain access to privileged content on navigation
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   651
    to unprivileged pages
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   652
- removed obsolete patches
837
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 836
diff changeset
   653
  * mozilla-bmo1088588.patch
844
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   654
  * mozilla-bmo1108834.patch
836
12530a091878 prepare 37 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   655
- requires NSPR 4.10.8
12530a091878 prepare 37 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   656
12530a091878 prepare 37 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   657
-------------------------------------------------------------------
844
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   658
Tue Mar 24 15:35:24 UTC 2015 - dvaleev@suse.com
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   659
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   660
- Fix builds with skia on Power
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   661
  mozilla-skia-be-le.patch (patch from #bmo1136958)
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   662
  mozilla-bmo1108834.patch
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   663
  mozilla-bmo1005535.patch
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   664
86fa73db98e5 Firefox 37.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 843
diff changeset
   665
-------------------------------------------------------------------
839
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   666
Sat Mar 21 09:03:12 UTC 2015 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   667
840
e160750ffe91 new bug id
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 839
diff changeset
   668
- update to Firefox 36.0.4 (bnc#923534)
839
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   669
  * MFSA 2015-28/CVE-2015-0818 (bmo#1144988)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   670
    Privilege escalation through SVG navigation
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   671
  * MFSA 2015-29/CVE-2015-0817 (bmo#1145255)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   672
    Code execution through incorrect JavaScript bounds checking
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   673
    elimination
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   674
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   675
-------------------------------------------------------------------
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   676
Fri Mar 20 15:02:33 UTC 2015 - dimstar@opensuse.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   677
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   678
- Copy the icons to /usr/share/icons instead of symlinking them:
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   679
  in preparation for containerized apps (e.g. xdg-app) as well as
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   680
  AppStream metadata extraction, there are a couple locations that
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   681
  need to be real files for system integration (.desktop files,
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   682
  icons, mime-type info).
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   683
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 838
diff changeset
   684
-------------------------------------------------------------------
838
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   685
Sat Mar  7 07:40:56 UTC 2015 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   686
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   687
- update to Firefox 36.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   688
  Bugfixes:
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   689
  * Disable the usage of the ANY DNS query type (bmo#1093983)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   690
  * Hello may become inactive until restart (bmo#1137469)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   691
  * Print preferences may not be preserved (bmo#1136855)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   692
  * Hello contact tabs may not be visible (bmo#1137141)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   693
  * Accept hostnames that include an underscore character ("_")
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   694
    (bmo#1136616)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   695
  * WebGL may use significant memory with Canvas2d (bmo#1137251)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   696
  * Option -remote has been restored (bmo#1080319)
840
e160750ffe91 new bug id
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 839
diff changeset
   697
- added mozilla-skia-bmo1136958.patch to fix build issues for
e160750ffe91 new bug id
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 839
diff changeset
   698
  ARM and PPC
838
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   699
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 835
diff changeset
   700
-------------------------------------------------------------------
832
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   701
Fri Feb 20 22:53:39 UTC 2015 - wr@rosenauer.org
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   702
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   703
- update to Firefox 36.0 (bnc#917597)
828
59013b3a51f5 update to 36.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 827
diff changeset
   704
  * mozilla-xremote-client was removed
59013b3a51f5 update to 36.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 827
diff changeset
   705
  * added libclearkey.so media plugin
832
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   706
  * Pinned tiles on the new tab page can be synced
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   707
  * Support for the full HTTP/2 protocol. HTTP/2 enables a faster,
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   708
    more scalable, and more responsive web.
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   709
  * Locale added: Uzbek (uz)
835
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   710
  security fixes:
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   711
  * MFSA 2015-11/CVE-2015-0835/CVE-2015-0836
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   712
    Miscellaneous memory safety hazards
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   713
  * MFSA 2015-12/CVE-2015-0833 (bmo#945192)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   714
    Invoking Mozilla updater will load locally stored DLL files
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   715
    (Windows only)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   716
  * MFSA 2015-13/CVE-2015-0832 (bmo#1065909)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   717
    Appended period to hostnames can bypass HPKP and HSTS protections
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   718
  * MFSA 2015-14/CVE-2015-0830 (bmo#1110488)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   719
    Malicious WebGL content crash when writing strings
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   720
  * MFSA 2015-15/CVE-2015-0834 (bmo#1098314)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   721
    TLS TURN and STUN connections silently fail to simple TCP connections
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   722
  * MFSA 2015-16/CVE-2015-0831 (bmo#1130514)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   723
    Use-after-free in IndexedDB
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   724
  * MFSA 2015-17/CVE-2015-0829 (bmo#1128939)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   725
    Buffer overflow in libstagefright during MP4 video playback
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   726
  * MFSA 2015-18/CVE-2015-0828 (bmo#1030667, bmo#988675)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   727
    Double-free when using non-default memory allocators with a
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   728
    zero-length XHR
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   729
  * MFSA 2015-19/CVE-2015-0827 (bmo#1117304)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   730
    Out-of-bounds read and write while rendering SVG content
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   731
  * MFSA 2015-20/CVE-2015-0826 (bmo#1092363)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   732
    Buffer overflow during CSS restyling
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   733
  * MFSA 2015-21/CVE-2015-0825 (bmo#1092370)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   734
    Buffer underflow during MP3 playback
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   735
  * MFSA 2015-22/CVE-2015-0824 (bmo#1095925)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   736
    Crash using DrawTarget in Cairo graphics library
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   737
  * MFSA 2015-23/CVE-2015-0823 (bmo#1098497)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   738
    Use-after-free in Developer Console date with OpenType Sanitiser
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   739
  * MFSA 2015-24/CVE-2015-0822 (bmo#1110557)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   740
    Reading of local files through manipulation of form autocomplete
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   741
  * MFSA 2015-25/CVE-2015-0821 (bmo#1111960)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   742
    Local files or privileged URLs in pages can be opened into new tabs
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   743
  * MFSA 2015-26/CVE-2015-0819 (bmo#1079554)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   744
    UI Tour whitelisted sites in background tab can spoof foreground
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   745
    tabs
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   746
  * MFSA 2015-27CVE-2015-0820 (bmo#1125398)
e7e5b3d0f1b3 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 832
diff changeset
   747
    Caja Compiler JavaScript sandbox bypass
832
4d52d2b45cf0 prepare 36.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 831
diff changeset
   748
- rebased patches
830
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   749
- requires NSS 3.17.4
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   750
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   751
-------------------------------------------------------------------
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   752
Sat Jan 31 18:37:38 UTC 2015 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   753
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   754
- update to Firefox 35.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   755
  * With the Enhanced Steam extension, Firefox could crash (bmo#1123732)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   756
  * Kerberos authentication did not work with alias (bmo#1108971)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   757
  * SVG / CSS animation had a regression causing rendering issues on
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   758
    websites like openstreemap.org (bmo#1083079)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   759
  * On Godaddy webmail, Firefox could crash (bmo#1113121)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   760
  * document.baseURI did not get updated to document.location after
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   761
    base tag was removed from DOM for site with a CSP (bmo#1121857)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   762
  * With a Right-to-left (RTL) version of Firefox, the text selection
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   763
    could be broken (bmo#1104036)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   764
  * CSP had a change in behavior with regard to case sensitivity
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 828
diff changeset
   765
    resources loading (bmo#1122445)
828
59013b3a51f5 update to 36.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 827
diff changeset
   766
59013b3a51f5 update to 36.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 827
diff changeset
   767
-------------------------------------------------------------------
826
677ef48cf29b Firefox 35.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 824
diff changeset
   768
Sat Jan 10 18:36:37 UTC 2015 - wr@rosenauer.org
677ef48cf29b Firefox 35.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 824
diff changeset
   769
677ef48cf29b Firefox 35.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 824
diff changeset
   770
- update to Firefox 35.0 (bnc#910669)
827
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   771
  notable features:
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   772
  * Firefox Hello with new rooms-based conversations model
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   773
  * Implemented HTTP Public Key Pinning Extension (for enhanced
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   774
    authentication of encrypted connections)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   775
  security fixes:
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   776
  * MFSA 2015-01/CVE-2014-8634/CVE-2014-8635
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   777
    Miscellaneous memory safety hazards
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   778
  * MFSA 2015-02/CVE-2014-8637 (bmo#1094536)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   779
    Uninitialized memory use during bitmap rendering
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   780
  * MFSA 2015-03/CVE-2014-8638 (bmo#1080987)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   781
    sendBeacon requests lack an Origin header
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   782
  * MFSA 2015-04/CVE-2014-8639 (bmo#1095859)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   783
    Cookie injection through Proxy Authenticate responses
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   784
  * MFSA 2015-05/CVE-2014-8640 (bmo#1100409)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   785
    Read of uninitialized memory in Web Audio
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   786
  * MFSA 2015-06/CVE-2014-8641 (bmo#1108455)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   787
    Read-after-free in WebRTC
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   788
  * MFSA 2015-07/CVE-2014-8643 (bmo#1114170) (Windows-only)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   789
    Gecko Media Plugin sandbox escape
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   790
  * MFSA 2015-08/CVE-2014-8642 (bmo#1079658)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   791
    Delegated OCSP responder certificates failure with
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   792
    id-pkix-ocsp-nocheck extension
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   793
  * MFSA 2015-09/CVE-2014-8636 (bmo#987794)
3caf8b25f146 merge from ff35
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 826
diff changeset
   794
    XrayWrapper bypass through DOM objects
807
f54c68340963 Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 806
diff changeset
   795
- rebased patches
809
af47260a332c morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 807
diff changeset
   796
- dropped explicit support for everything older than 12.3
af47260a332c morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 807
diff changeset
   797
  (including SLES11)
af47260a332c morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 807
diff changeset
   798
  * merge firefox-kde.patch and firefox-kde-114.patch
af47260a332c morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 807
diff changeset
   799
  * dropped mozilla-sle11.patch
af47260a332c morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 807
diff changeset
   800
- reworked specfile to build conditionally based on release channel
af47260a332c morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 807
diff changeset
   801
  either Firefox or Firefox Developer Edition
af47260a332c morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 807
diff changeset
   802
- added mozilla-openaes-decl.patch to fix implicit declarations
819
5a18bd66e46c [Bug 908892] Updated Firefox (33.0-1.90.1 -> 34.0.5-1.94.3) crashes in tracker-miner-firefox
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 818
diff changeset
   803
- obsolete tracker-miner-firefox < 0.15 because it leads to startup
5a18bd66e46c [Bug 908892] Updated Firefox (33.0-1.90.1 -> 34.0.5-1.94.3) crashes in tracker-miner-firefox
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 818
diff changeset
   804
  crashes (bnc#908892)
807
f54c68340963 Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 806
diff changeset
   805
f54c68340963 Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 806
diff changeset
   806
-------------------------------------------------------------------
820
419e95018725 fix bashism in mozilla.sh script
Led <ledest@gmail.com>
parents: 813
diff changeset
   807
Sat Dec 13 22:13:00 UTC 2014 - Led <ledest@gmail.com>
419e95018725 fix bashism in mozilla.sh script
Led <ledest@gmail.com>
parents: 813
diff changeset
   808
419e95018725 fix bashism in mozilla.sh script
Led <ledest@gmail.com>
parents: 813
diff changeset
   809
- fix bashism in mozilla.sh script
419e95018725 fix bashism in mozilla.sh script
Led <ledest@gmail.com>
parents: 813
diff changeset
   810
419e95018725 fix bashism in mozilla.sh script
Led <ledest@gmail.com>
parents: 813
diff changeset
   811
-------------------------------------------------------------------
813
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   812
Sat Nov 29 21:23:03 UTC 2014 - wr@rosenauer.org
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   813
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   814
- update to Firefox 34.0.5 (bnc#908009)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   815
  * Default search engine changed to Yahoo! for North America
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   816
  * Default search engine changed to Yandex for Belarusian, Kazakh,
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   817
    and Russian locales
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   818
  * Improved search bar (en-US only)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   819
  * Firefox Hello real-time communication client
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   820
  * Easily switch themes/personas directly in the Customizing mode
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   821
  * Implementation of HTTP/2 (draft14) and ALPN
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   822
  * Disabled SSLv3
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   823
  * MFSA 2014-83/CVE-2014-1587/CVE-2014-1588
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   824
    Miscellaneous memory safety hazards
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   825
  * MFSA 2014-84/CVE-2014-1589 (bmo#1043787)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   826
    XBL bindings accessible via improper CSS declarations
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   827
  * MFSA 2014-85/CVE-2014-1590 (bmo#1087633)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   828
    XMLHttpRequest crashes with some input streams
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   829
  * MFSA 2014-86/CVE-2014-1591 (bmo#1069762)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   830
    CSP leaks redirect data via violation reports
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   831
  * MFSA 2014-87/CVE-2014-1592 (bmo#1088635)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   832
    Use-after-free during HTML5 parsing
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   833
  * MFSA 2014-88/CVE-2014-1593 (bmo#1085175)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   834
    Buffer overflow while parsing media content
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   835
  * MFSA 2014-89/CVE-2014-1594 (bmo#1074280)
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   836
    Bad casting from the BasicThebesLayer to BasicContainerLayer
9e3063dcc69e Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 811
diff changeset
   837
- rebased patches
806
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 805
diff changeset
   838
- limit linker memory usage for %ix86
807
f54c68340963 Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 806
diff changeset
   839
- rebased patches
805
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 802
diff changeset
   840
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 802
diff changeset
   841
-------------------------------------------------------------------
801
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   842
Fri Nov  7 20:14:32 UTC 2014 - wr@rosenauer.org
787
f4578fb6fcc3 33.1 preparation
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   843
f4578fb6fcc3 33.1 preparation
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   844
- update to Firefox 33.1
802
6c8dd9468bcc 33.1 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 801
diff changeset
   845
  * Adding DuckDuckGo as a search option (upstream)
6c8dd9468bcc 33.1 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 801
diff changeset
   846
  * Forget Button added
6c8dd9468bcc 33.1 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 801
diff changeset
   847
  * Enhanced Tiles
6c8dd9468bcc 33.1 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 801
diff changeset
   848
  * Privacy tour introduced
797
3b2d52457c91 fix typo on Recommends
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 789
diff changeset
   849
- fix typo in GStreamer Recommends
787
f4578fb6fcc3 33.1 preparation
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   850
f4578fb6fcc3 33.1 preparation
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   851
-------------------------------------------------------------------
801
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   852
Tue Nov  4 18:00:35 UTC 2014 - guillaume@opensuse.org
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   853
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   854
- Disable elf-hack for aarch64
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   855
- Enable EGL for aarch64
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   856
- Limit RAM usage during link for %arm
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   857
- Fix _constraints for ARM
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   858
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   859
-------------------------------------------------------------------
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   860
Mon Nov  3 11:36:04 UTC 2014 - dmueller@suse.com
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   861
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   862
- use proper macros for ARM
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   863
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   864
-------------------------------------------------------------------
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   865
Mon Nov  3 11:26:23 UTC 2014 - josua.mayer97@gmail.com
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   866
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   867
- use '--disable-optimize' not only on 32-bit x86, but on 32-bit arm too
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   868
  to fix compiling.
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   869
- pass '-Wl,--no-keep-memory' to linker to reduce required memory during
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   870
  linking on arm.
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   871
f5f6f5547c2b merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 797
diff changeset
   872
-------------------------------------------------------------------
788
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   873
Thu Oct 30 11:31:05 UTC 2014 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   874
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   875
- update to Firefox 33.0.2
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   876
  * Fix a startup crash with some combination of hardware and drivers
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   877
  33.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   878
  * Firefox displays a black screen at start-up with certain
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   879
    graphics drivers
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   880
- adjusted _constraints for ARM
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   881
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 786
diff changeset
   882
-------------------------------------------------------------------
786
f721a3dea219 added fix for bmo1088588
<josua.mayer97@gmail.com>
parents: 785
diff changeset
   883
Tue Oct 28 15:23:09 UTC 2014 - josua.mayer97@gmail.com
f721a3dea219 added fix for bmo1088588
<josua.mayer97@gmail.com>
parents: 785
diff changeset
   884
f721a3dea219 added fix for bmo1088588
<josua.mayer97@gmail.com>
parents: 785
diff changeset
   885
- added mozilla-bmo1088588.patch to fix build with EGL (bmo#1088588)
785
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 781
diff changeset
   886
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 781
diff changeset
   887
-------------------------------------------------------------------
781
4ee017942f28 use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 780
diff changeset
   888
Sat Oct 25 08:45:43 UTC 2014 - wr@rosenauer.org
4ee017942f28 use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 780
diff changeset
   889
4ee017942f28 use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 780
diff changeset
   890
- define /usr/share/myspell as additional dictionary location
4ee017942f28 use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 780
diff changeset
   891
  and remove add-plugins.sh finally (bnc#900639)
4ee017942f28 use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 780
diff changeset
   892
4ee017942f28 use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 780
diff changeset
   893
-------------------------------------------------------------------
780
c20a07035a80 use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 777
diff changeset
   894
Sun Oct 19 12:59:28 UTC 2014 - vindex17@outlook.it
c20a07035a80 use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 777
diff changeset
   895
c20a07035a80 use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 777
diff changeset
   896
- use Firefox default optimization flags instead of -Os
c20a07035a80 use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 777
diff changeset
   897
- specfile cleanup
c20a07035a80 use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 777
diff changeset
   898
c20a07035a80 use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 777
diff changeset
   899
-------------------------------------------------------------------
777
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   900
Wed Oct 15 08:05:33 UTC 2014 - wr@rosenauer.org
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   901
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   902
- fix build for all ppc by not enabling elf-hack
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   903
  (bnc#901213)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   904
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   905
-------------------------------------------------------------------
776
fd46c2b70724 prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 774
diff changeset
   906
Sat Oct 11 08:48:24 UTC 2014 - wr@rosenauer.org
fd46c2b70724 prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 774
diff changeset
   907
777
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   908
- update to Firefox 33.0 (bnc#900941)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   909
  New features:
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   910
  * OpenH264 support (sandboxed)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   911
  * Enhanced Tiles
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   912
  * Improved search experience through the location bar
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   913
  * Slimmer and faster JavaScript strings
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   914
  * New CSP (Content Security Policy) backend
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   915
  * Support for connecting to HTTP proxy over HTTPS
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   916
  * Improved reliability of the session restoration
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   917
  * Proprietary window.crypto properties/functions removed
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   918
  Security:
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   919
  * MFSA 2014-74/CVE-2014-1574/CVE-2014-1575
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   920
    Miscellaneous memory safety hazards
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   921
  * MFSA 2014-75/CVE-2014-1576 (bmo#1041512)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   922
    Buffer overflow during CSS manipulation
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   923
  * MFSA 2014-76/CVE-2014-1577 (bmo#1012609)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   924
    Web Audio memory corruption issues with custom waveforms
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   925
  * MFSA 2014-77/CVE-2014-1578 (bmo#1063327)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   926
    Out-of-bounds write with WebM video
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   927
  * MFSA 2014-78/CVE-2014-1580 (bmo#1063733)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   928
    Further uninitialized memory use during GIF rendering
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   929
  * MFSA 2014-79/CVE-2014-1581 (bmo#1068218)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   930
    Use-after-free interacting with text directionality
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   931
  * MFSA 2014-80/CVE-2014-1582/CVE-2014-1584 (bmo#1049095, bmo#1066190)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   932
    Key pinning bypasses
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   933
  * MFSA 2014-81/CVE-2014-1585/CVE-2014-1586 (bmo#1062876, bmo#1062981)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   934
    Inconsistent video sharing within iframe
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   935
  * MFSA 2014-82/CVE-2014-1583 (bmo#1015540)
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   936
    Accessing cross-origin objects via the Alarms API
f1c5ccf4d1a7 changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 776
diff changeset
   937
    (only relevant for installed web apps)
765
0955f22b3f4f changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 761
diff changeset
   938
- requires NSPR 4.10.7
773
22545f50497c update to 33.0b9
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 769
diff changeset
   939
- requires NSS 3.17.1
776
fd46c2b70724 prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 774
diff changeset
   940
- removed obsolete patches:
773
22545f50497c update to 33.0b9
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 769
diff changeset
   941
  * mozilla-ppc.patch
776
fd46c2b70724 prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 774
diff changeset
   942
  * mozilla-libproxy-compat.patch
774
f61bd1cd52c2 added basic appstream appdata information
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 773
diff changeset
   943
- added basic appdata information
769
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   944
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   945
-------------------------------------------------------------------
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   946
Sat Sep 20 13:33:51 UTC 2014 - wr@rosenauer.org
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   947
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   948
- update to Firefox 32.0.2
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   949
  * just a version bump for our builds
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   950
  * fixed the in application update process for certain environments
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   951
    (in application update is not enabled in openSUSE and Linux
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   952
    is unaffected in any case)
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   953
- build with --disable-optimize for 13.1 and above for i586 to
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 767
diff changeset
   954
  workaround miscompilations (bnc#896624)
767
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 765
diff changeset
   955
- use some more build flags to align with upstream
765
0955f22b3f4f changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 761
diff changeset
   956
0955f22b3f4f changelog
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 761
diff changeset
   957
-------------------------------------------------------------------
761
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   958
Sat Sep 13 16:58:16 UTC 2014 - wr@rosenauer.org
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   959
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   960
- update to Firefox 32.0.1
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   961
  * fixed stability issues for computers with multiple graphics cards
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   962
  * mixed content icon may be incorrectly displayed instead of lock
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   963
    icon for SSL sites in 32.0 (
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   964
  * WebRTC: setRemoteDescription() silently fails if no success
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   965
    callback is specified (bmo#1063971)
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   966
c748af0c7534 update to 32.0.1
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 759
diff changeset
   967
-------------------------------------------------------------------
759
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   968
Sun Aug 31 07:44:54 UTC 2014 - wr@rosenauer.org
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   969
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   970
- update to Firefox 32.0 (bnc#894370)
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   971
  * MFSA 2014-67/CVE-2014-1553/CVE-2014-1554/CVE-2014-1562
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   972
    Miscellaneous memory safety hazards
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   973
  * MFSA 2014-68/CVE-2014-1563 (bmo#1018524)
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   974
    Use-after-free during DOM interactions with SVG
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   975
  * MFSA 2014-69/CVE-2014-1564 (bmo#1045977)
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   976
    Uninitialized memory use during GIF rendering
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   977
  * MFSA 2014-70/CVE-2014-1565 (bmo#1047831)
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   978
    Out-of-bounds read in Web Audio audio timeline
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   979
  * MFSA 2014-72/CVE-2014-1567 (bmo#1037641)
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   980
    Use-after-free setting text directionality
748
72ba5129e5fd full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 746
diff changeset
   981
- rebased patches
756
e4fa9844604e update to beta8
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 753
diff changeset
   982
- requires NSS 3.16.4
748
72ba5129e5fd full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 746
diff changeset
   983
- removed upstreamed patch
72ba5129e5fd full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 746
diff changeset
   984
  * mozilla-aarch64-bmo-810631.patch
72ba5129e5fd full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 746
diff changeset
   985
72ba5129e5fd full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 746
diff changeset
   986
-------------------------------------------------------------------
759
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   987
Wed Aug 20 13:50:58 CEST 2014 - behlert@suse.de
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   988
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   989
- adapted _constraints, used more than 3900MB on s390x during
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   990
  last build
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   991
b2ae89c6dea9 Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 756
diff changeset
   992
-------------------------------------------------------------------
753
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
   993
Sun Jul 20 18:11:44 UTC 2014 - wr@rosenauer.org
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
   994
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
   995
- update to Firefox 31.0 (bnc#887746)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
   996
  * MFSA 2014-56/CVE-2014-1547/CVE-2014-1548
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
   997
    Miscellaneous memory safety hazards
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
   998
  * MFSA 2014-57/CVE-2014-1549 (bmo#1020205)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
   999
    Buffer overflow during Web Audio buffering for playback
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1000
  * MFSA 2014-58/CVE-2014-1550 (bmo#1020411)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1001
    Use-after-free in Web Audio due to incorrect control message ordering
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1002
  * MFSA 2014-60/CVE-2014-1561 (bmo#1000514, bmo#910375)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1003
    Toolbar dialog customization event spoofing
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1004
  * MFSA 2014-61/CVE-2014-1555 (bmo#1023121)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1005
    Use-after-free with FireOnStateChange event
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1006
  * MFSA 2014-62/CVE-2014-1556 (bmo#1028891)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1007
    Exploitable WebGL crash with Cesium JavaScript library
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1008
  * MFSA 2014-63/CVE-2014-1544 (bmo#963150)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1009
    Use-after-free while when manipulating certificates in the trusted cache
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1010
    (solved with NSS 3.16.2 requirement)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1011
  * MFSA 2014-64/CVE-2014-1557 (bmo#913805)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1012
    Crash in Skia library when scaling high quality images
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1013
  * MFSA 2014-65/CVE-2014-1558/CVE-2014-1559/CVE-2014-1560
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1014
    (bmo#1015973, bmo#1026022, bmo#997795)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1015
    Certificate parsing broken by non-standard character encoding
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1016
  * MFSA 2014-66/CVE-2014-1552 (bmo#985135)
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1017
    IFRAME sandbox same-origin access through redirect
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1018
- use EGL on ARM
746
b441942b2a3f update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 744
diff changeset
  1019
- rebased patches
b441942b2a3f update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 744
diff changeset
  1020
- requires NSS 3.16.2
753
f3bf114c6639 Firefox 32.0b3
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 748
diff changeset
  1021
- requires python-devel (not only python)
746
b441942b2a3f update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 744
diff changeset
  1022
b441942b2a3f update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 744
diff changeset
  1023
-------------------------------------------------------------------
744
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1024
Mon Jun  9 08:28:17 UTC 2014 - wr@rosenauer.org
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1025
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1026
- update to Firefox 30.0 (bnc#881874)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1027
  * MFSA 2014-48/CVE-2014-1533/CVE-2014-1534
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1028
    (bmo#921622, bmo#967354, bmo#969517, bmo#969549, bmo#973874,
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1029
     bmo#978652, bmo#978811, bmo#988719, bmo#990868, bmo#991981,
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1030
     bmo#992274, bmo#994907, bmo#995679, bmo#995816, bmo#995817,
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1031
     bmo#996536, bmo#996715, bmo#999651, bmo#1000598,
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1032
     bmo#1000960, bmo#1002340, bmo#1005578, bmo#1007223,
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1033
     bmo#1009952, bmo#1011007)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1034
    Miscellaneous memory safety hazards (rv:30.0)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1035
  * MFSA 2014-49/CVE-2014-1536/CVE-2014-1537/CVE-2014-1538
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1036
    (bmo#989994, bmo#999274, bmo#1005584)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1037
    Use-after-free and out of bounds issues found using Address
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1038
    Sanitizer
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1039
  * MFSA 2014-50/CVE-2014-1539 (bmo#995603)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1040
    Clickjacking through cursor invisability after Flash interaction
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1041
  * MFSA 2014-51/CVE-2014-1540 (bmo#978862)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1042
    Use-after-free in Event Listener Manager
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1043
  * MFSA 2014-52/CVE-2014-1541 (bmo#1000185)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1044
    Use-after-free with SMIL Animation Controller
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1045
  * MFSA 2014-53/CVE-2014-1542 (bmo#991533)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1046
    Buffer overflow in Web Audio Speex resampler
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1047
  * MFSA 2014-54/CVE-2014-1543 (bmo#1011859)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1048
    Buffer overflow in Gamepad API
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1049
  * MFSA 2014-55/CVE-2014-1545 (bmo#1018783)
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1050
    Out of bounds write in NSPR
733
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1051
- rebased patches
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1052
- removed obsolete patches
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1053
  * firefox-browser-css.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1054
  * mozilla-aarch64-bmo-962488.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1055
  * mozilla-aarch64-bmo-963023.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1056
  * mozilla-aarch64-bmo-963024.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1057
  * mozilla-aarch64-bmo-963027.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1058
  * mozilla-ppc64-xpcom.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1059
  * mozilla-ppc64le-javascript.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1060
  * mozilla-ppc64le-libffi.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1061
  * mozilla-ppc64le-mfbt.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1062
  * mozilla-ppc64le-webrtc.patch
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1063
  * mozilla-ppc64le-xpcom.patch
744
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1064
  * mozilla-ppc64le-build.patch
e2d94ddb82f0 manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 738
diff changeset
  1065
- requires NSPR 4.10.6
725
b688c34894ee minor updates
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 718
diff changeset
  1066
- enabled GStreamer 1.0 usage for 13.2 and above
b688c34894ee minor updates
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 718
diff changeset
  1067
b688c34894ee minor updates
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 718
diff changeset
  1068
-------------------------------------------------------------------
738
f118b88b7d7f Aurora 31 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 733
diff changeset
  1069
Sat May 10 06:09:37 UTC 2014 - wr@rosenauer.org
f118b88b7d7f Aurora 31 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 733
diff changeset
  1070
f118b88b7d7f Aurora 31 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 733
diff changeset
  1071
- update to Firefox 29.0.1
f118b88b7d7f Aurora 31 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 733
diff changeset
  1072
  * Seer disabled by default (bmo#1005958)
f118b88b7d7f Aurora 31 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 733
diff changeset
  1073
  * Session Restore failed with a corrupted sessionstore.js file
f118b88b7d7f Aurora 31 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 733
diff changeset
  1074
    (bmo#1001167)
f118b88b7d7f Aurora 31 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 733
diff changeset
  1075
  * pdf.js printing white page (bmo#1003707, bnc#876833)
733
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1076
- general.useragent.locale gets overwritten with en-US while it
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1077
  should be using the active langpack's setting
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1078
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1079
-------------------------------------------------------------------
727
727fef76f8d7 manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 725
diff changeset
  1080
Sat Apr 26 12:18:07 UTC 2014 - wr@rosenauer.org
727fef76f8d7 manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 725
diff changeset
  1081
727fef76f8d7 manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 725
diff changeset
  1082
- update to Firefox 29.0 (bnc#875378)
733
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1083
  * MFSA 2014-34/CVE-2014-1518/CVE-2014-1519
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1084
    Miscellaneous memory safety hazards
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1085
  * MFSA 2014-36/CVE-2014-1522 (bmo#995289)
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1086
    Web Audio memory corruption issues
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1087
  * MFSA 2014-37/CVE-2014-1523 (bmo#969226)
b2202fea7983 manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents: 727
diff changeset
  1088
    Out of bounds read while decoding JPG images