1 ------------------------------------------------------------------- |
1 ------------------------------------------------------------------- |
2 Thu Oct 4 04:51:23 UTC 2012 - wr@rosenauer.org |
2 Mon Oct 15 14:15:53 UTC 2012 - wr@rosenauer.org |
3 |
3 |
4 - update to Aurora 17 (20121003) |
4 - update to Aurora 18 (20121015) |
|
5 |
|
6 ------------------------------------------------------------------- |
|
7 Mon Oct 15 14:07:12 UTC 2012 - wr@rosenauer.org |
|
8 |
|
9 - update to Firefox 17.0b1 |
5 - use internal NSPR for now (bmo#776877) |
10 - use internal NSPR for now (bmo#776877) |
6 |
11 |
7 ------------------------------------------------------------------- |
12 ------------------------------------------------------------------- |
8 Thu Sep 27 18:20:18 UTC 2012 - wr@rosenauer.org |
13 Thu Oct 11 01:51:16 UTC 2012 - wr@rosenauer.org |
9 |
14 |
10 - update to Firefox 16.0b5 |
15 - update to Firefox 16.0.1 (bnc#783533) |
|
16 * MFSA 2012-88/CVE-2012-4191 (bmo#798045) |
|
17 Miscellaneous memory safety hazards |
|
18 * MFSA 2012-89/CVE-2012-4192/CVE-2012-4193 (bmo#799952, bmo#720619) |
|
19 defaultValue security checks not applied |
|
20 |
|
21 ------------------------------------------------------------------- |
|
22 Sun Oct 7 21:40:14 UTC 2012 - wr@rosenauer.org |
|
23 |
|
24 - update to Firefox 16.0 (bnc#783533) |
|
25 * MFSA 2012-74/CVE-2012-3982/CVE-2012-3983 |
|
26 Miscellaneous memory safety hazards |
|
27 * MFSA 2012-75/CVE-2012-3984 (bmo#575294) |
|
28 select element persistance allows for attacks |
|
29 * MFSA 2012-76/CVE-2012-3985 (bmo#655649) |
|
30 Continued access to initial origin after setting document.domain |
|
31 * MFSA 2012-77/CVE-2012-3986 (bmo#775868) |
|
32 Some DOMWindowUtils methods bypass security checks |
|
33 * MFSA 2012-79/CVE-2012-3988 (bmo#725770) |
|
34 DOS and crash with full screen and history navigation |
|
35 * MFSA 2012-80/CVE-2012-3989 (bmo#783867) |
|
36 Crash with invalid cast when using instanceof operator |
|
37 * MFSA 2012-81/CVE-2012-3991 (bmo#783260) |
|
38 GetProperty function can bypass security checks |
|
39 * MFSA 2012-82/CVE-2012-3994 (bmo#765527) |
|
40 top object and location property accessible by plugins |
|
41 * MFSA 2012-83/CVE-2012-3993/CVE-2012-4184 (bmo#768101, bmo#780370) |
|
42 Chrome Object Wrapper (COW) does not disallow acces to privileged |
|
43 functions or properties |
|
44 * MFSA 2012-84/CVE-2012-3992 (bmo#775009) |
|
45 Spoofing and script injection through location.hash |
|
46 * MFSA 2012-85/CVE-2012-3995/CVE-2012-4179/CVE-2012-4180/ |
|
47 CVE-2012-4181/CVE-2012-4182/CVE-2012-4183 |
|
48 Use-after-free, buffer overflow, and out of bounds read issues |
|
49 found using Address Sanitizer |
|
50 * MFSA 2012-86/CVE-2012-4185/CVE-2012-4186/CVE-2012-4187/ |
|
51 CVE-2012-4188 |
|
52 Heap memory corruption issues found using Address Sanitizer |
|
53 * MFSA 2012-87/CVE-2012-3990 (bmo#787704) |
|
54 Use-after-free in the IME State Manager |
11 - requires NSPR 4.9.2 |
55 - requires NSPR 4.9.2 |
12 - improve GStreamer integration (bmo#760140) |
56 - improve GStreamer integration (bmo#760140) |
13 - removed upstreamed mozilla-crashreporter-restart-args.patch |
57 - removed upstreamed mozilla-crashreporter-restart-args.patch |
14 - webapprt now included |
58 - webapprt now included |
15 - use kmozillahelper's new REVEAL command (bnc#777415) |
59 - use kmozillahelper's new REVEAL command (bnc#777415) |
16 (requires mozilla-kde4-integration >= 0.6.4) |
60 (requires mozilla-kde4-integration >= 0.6.4) |
|
61 - updated translations-other with new languages |
17 |
62 |
18 ------------------------------------------------------------------- |
63 ------------------------------------------------------------------- |
19 Mon Sep 10 19:37:56 UTC 2012 - wr@rosenauer.org |
64 Mon Sep 10 19:37:56 UTC 2012 - wr@rosenauer.org |
20 |
65 |
21 - update to Firefox 15.0.1 (bnc#779936) |
66 - update to Firefox 15.0.1 (bnc#779936) |