MozillaFirefox/MozillaFirefox.changes
changeset 712 427ae22e730e
parent 711 012a5adf5c74
child 714 b686e856c800
equal deleted inserted replaced
711:012a5adf5c74 712:427ae22e730e
     1 -------------------------------------------------------------------
     1 -------------------------------------------------------------------
     2 Sun Mar 16 13:39:15 UTC 2014 - wr@rosenauer.org
     2 Sun Mar 16 13:39:15 UTC 2014 - wr@rosenauer.org
     3 
     3 
     4 - update to Firefox 28.0 (bnc#)
     4 - update to Firefox 28.0 (bnc#868603)
       
     5   * MFSA 2014-15/CVE-2014-1493/CVE-2014-1494
       
     6     Miscellaneous memory safety hazards
       
     7   * MFSA 2014-17/CVE-2014-1497 (bmo#966311)
       
     8     Out of bounds read during WAV file decoding
       
     9   * MFSA 2014-18/CVE-2014-1498 (bmo#935618)
       
    10     crypto.generateCRMFRequest does not validate type of key
       
    11   * MFSA 2014-19/CVE-2014-1499 (bmo#961512)
       
    12     Spoofing attack on WebRTC permission prompt
       
    13   * MFSA 2014-20/CVE-2014-1500 (bmo#956524)
       
    14     onbeforeunload and Javascript navigation DOS
       
    15   * MFSA 2014-22/CVE-2014-1502 (bmo#972622)
       
    16     WebGL content injection from one domain to rendering in another
       
    17   * MFSA 2014-23/CVE-2014-1504 (bmo#911547)
       
    18     Content Security Policy for data: documents not preserved by
       
    19     session restore
       
    20   * MFSA 2014-26/CVE-2014-1508 (bmo#963198)
       
    21     Information disclosure through polygon rendering in MathML
       
    22   * MFSA 2014-27/CVE-2014-1509 (bmo#966021)
       
    23     Memory corruption in Cairo during PDF font rendering
       
    24   * MFSA 2014-28/CVE-2014-1505 (bmo#941887)
       
    25     SVG filters information disclosure through feDisplacementMap
       
    26   * MFSA 2014-29/CVE-2014-1510/CVE-2014-1511 (bmo#982906, bmo#982909)
       
    27     Privilege escalation using WebIDL-implemented APIs
       
    28   * MFSA 2014-30/CVE-2014-1512 (bmo#982957)
       
    29     Use-after-free in TypeObject
       
    30   * MFSA 2014-31/CVE-2014-1513 (bmo#982974)
       
    31     Out-of-bounds read/write through neutering ArrayBuffer objects
       
    32   * MFSA 2014-32/CVE-2014-1514 (bmo#983344)
       
    33     Out-of-bounds write through TypedArrayObject after neutering
     5 - requires NSPR 4.10.3 and NSS 3.15.5
    34 - requires NSPR 4.10.3 and NSS 3.15.5
     6 - new build dependency:
    35 - new build dependency (and recommends):
     7   * libpulse
    36   * libpulse
     8 - update of PowerPC 64 patches (bmo#976648) (pcerny@suse.com)
    37 - update of PowerPC 64 patches (bmo#976648) (pcerny@suse.com)
     9 - rebased patches
    38 - rebased patches
    10 
    39 
    11 -------------------------------------------------------------------
    40 -------------------------------------------------------------------