1 ------------------------------------------------------------------- |
1 ------------------------------------------------------------------- |
2 Sun Sep 17 08:07:43 UTC 2017 - wr@rosenauer.org |
2 Sat Sep 30 20:10:50 UTC 2017 - zaitor@opensuse.org |
3 |
3 |
4 - update to Firefox 56.0b12 |
4 - Drop libgnomeui-devel, and replace it with pkgconfig(gconf-2.0), |
|
5 pkgconfig(gtk+-2.0), pkgconfig(gtk+-unix-print-2.0), |
|
6 pkgconfig(glib-2.0), pkgconfig(gobject-2.0) and |
|
7 pkgconfig(gdk-x11-2.0) BuildRequires, align with what configure |
|
8 looks for. |
|
9 |
|
10 ------------------------------------------------------------------- |
|
11 Thu Sep 28 08:28:29 UTC 2017 - wr@rosenauer.org |
|
12 |
|
13 - update to Firefox 56.0 (boo#1060445) |
|
14 * Firefox Screenshots |
5 * Find Options/Preferences more quickly with new search function |
15 * Find Options/Preferences more quickly with new search function |
6 * Media is no longer auto-played when opened in a background tab |
16 * Media is no longer auto-played when opened in a background tab |
7 * Enable CSS Grid Layout View |
17 * Enable CSS Grid Layout View |
|
18 MFSA 2017-21 |
|
19 * CVE-2017-7793 (bmo#1371889) |
|
20 Use-after-free with Fetch API |
|
21 * CVE-2017-7817 (bmo#1356596) (Android-only) |
|
22 Firefox for Android address bar spoofing through fullscreen mode |
|
23 * CVE-2017-7818 (bmo#1363723) |
|
24 Use-after-free during ARIA array manipulation |
|
25 * CVE-2017-7819 (bmo#1380292) |
|
26 Use-after-free while resizing images in design mode |
|
27 * CVE-2017-7824 (bmo#1398381) |
|
28 Buffer overflow when drawing and validating elements with ANGLE |
|
29 * CVE-2017-7805 (bmo#1377618) (fixed via NSS requirement) |
|
30 Use-after-free in TLS 1.2 generating handshake hashes |
|
31 * CVE-2017-7812 (bmo#1379842) |
|
32 Drag and drop of malicious page content to the tab bar can open locally stored files |
|
33 * CVE-2017-7814 (bmo#1376036) |
|
34 Blob and data URLs bypass phishing and malware protection warnings |
|
35 * CVE-2017-7813 (bmo#1383951) |
|
36 Integer truncation in the JavaScript parser |
|
37 * CVE-2017-7825 (bmo#1393624, bmo#1390980) (OSX-only) |
|
38 OS X fonts render some Tibetan and Arabic unicode characters as spaces |
|
39 * CVE-2017-7815 (bmo#1368981) |
|
40 Spoofing attack with modal dialogs on non-e10s installations |
|
41 * CVE-2017-7816 (bmo#1380597) |
|
42 WebExtensions can load about: URLs in extension UI |
|
43 * CVE-2017-7821 (bmo#1346515) |
|
44 WebExtensions can download and open non-executable files without user interaction |
|
45 * CVE-2017-7823 (bmo#1396320) |
|
46 CSP sandbox directive did not create a unique origin |
|
47 * CVE-2017-7822 (bmo#1368859) |
|
48 WebCrypto allows AES-GCM with 0-length IV |
|
49 * CVE-2017-7820 (bmo#1378207) |
|
50 Xray wrapper bypass with new tab and web console |
|
51 * CVE-2017-7811 |
|
52 Memory safety bugs fixed in Firefox 56 |
|
53 * CVE-2017-7810 |
|
54 Memory safety bugs fixed in Firefox 56 and Firefox ESR 52.4 |
8 - requires NSPR 4.16 and NSS 3.32.1 |
55 - requires NSPR 4.16 and NSS 3.32.1 |
|
56 - rebased patches |
|
57 |
|
58 ------------------------------------------------------------------- |
|
59 Thu Sep 28 07:53:13 UTC 2017 - dimstar@opensuse.org |
|
60 |
|
61 - Add alsa-devel BuildRequires: we care for ALSA support to be |
|
62 built and thus need to ensure we get the dependencies in place. |
|
63 In the past, alsa-devel was pulled in by accident: we |
|
64 buildrequire libgnome-devel. This required esound-devel and that |
|
65 in turn pulled in alsa-devel for us. libgnome is being fixed to |
|
66 no longer require esound-devel. |
9 |
67 |
10 ------------------------------------------------------------------- |
68 ------------------------------------------------------------------- |
11 Mon Sep 4 18:27:44 UTC 2017 - wr@rosenauer.org |
69 Mon Sep 4 18:27:44 UTC 2017 - wr@rosenauer.org |
12 |
70 |
13 - update to Firefox 55.0.3 |
71 - update to Firefox 55.0.3 |