MozillaFirefox/MozillaFirefox.changes
branchfirefox16
changeset 557 a24d7d7781bf
parent 551 5f1c6d51a4a2
child 558 12c9e11b93f2
equal deleted inserted replaced
555:a8c0d77272f6 557:a24d7d7781bf
     1 -------------------------------------------------------------------
     1 -------------------------------------------------------------------
     2 Sun Oct  7 21:40:14 UTC 2012 - wr@rosenauer.org
     2 Sun Oct  7 21:40:14 UTC 2012 - wr@rosenauer.org
     3 
     3 
     4 - update to Firefox 16.0 (bnc#783533)
     4 - update to Firefox 16.0 (bnc#783533)
       
     5   * MFSA 2012-74/CVE-2012-3982/CVE-2012-3983
       
     6     Miscellaneous memory safety hazards
       
     7   * MFSA 2012-75/CVE-2012-3984 (bmo#575294)
       
     8     select element persistance allows for attacks
       
     9   * MFSA 2012-76/CVE-2012-3985 (bmo#655649)
       
    10     Continued access to initial origin after setting document.domain
       
    11   * MFSA 2012-77/CVE-2012-3986 (bmo#775868)
       
    12     Some DOMWindowUtils methods bypass security checks
       
    13   * MFSA 2012-79/CVE-2012-3988 (bmo#725770)
       
    14     DOS and crash with full screen and history navigation
       
    15   * MFSA 2012-80/CVE-2012-3989 (bmo#783867)
       
    16     Crash with invalid cast when using instanceof operator
       
    17   * MFSA 2012-81/CVE-2012-3991 (bmo#783260)
       
    18     GetProperty function can bypass security checks
       
    19   * MFSA 2012-82/CVE-2012-3994 (bmo#765527)
       
    20     top object and location property accessible by plugins
       
    21   * MFSA 2012-83/CVE-2012-3993/CVE-2012-4184 (bmo#768101, bmo#780370)
       
    22     Chrome Object Wrapper (COW) does not disallow acces to privileged
       
    23     functions or properties
       
    24   * MFSA 2012-84/CVE-2012-3992 (bmo#775009)
       
    25     Spoofing and script injection through location.hash
       
    26   * MFSA 2012-85/CVE-2012-3995/CVE-2012-4179/CVE-2012-4180/
       
    27     CVE-2012-4181/CVE-2012-4182/CVE-2012-4183
       
    28     Use-after-free, buffer overflow, and out of bounds read issues
       
    29     found using Address Sanitizer
       
    30   * MFSA 2012-86/CVE-2012-4185/CVE-2012-4186/CVE-2012-4187/
       
    31     CVE-2012-4188
       
    32     Heap memory corruption issues found using Address Sanitizer
     5 - requires NSPR 4.9.2
    33 - requires NSPR 4.9.2
     6 - improve GStreamer integration (bmo#760140)
    34 - improve GStreamer integration (bmo#760140)
     7 - removed upstreamed mozilla-crashreporter-restart-args.patch
    35 - removed upstreamed mozilla-crashreporter-restart-args.patch
     8 - webapprt now included
    36 - webapprt now included
     9 - use kmozillahelper's new REVEAL command (bnc#777415)
    37 - use kmozillahelper's new REVEAL command (bnc#777415)