MozillaFirefox/MozillaFirefox.changes
branchfirefox67
changeset 1094 a25638dad81d
parent 1093 3942c205588b
child 1096 4c248180e576
equal deleted inserted replaced
1093:3942c205588b 1094:a25638dad81d
     1 -------------------------------------------------------------------
     1 -------------------------------------------------------------------
     2 Tue May 14 10:34:08 UTC 2019 - Wolfgang Rosenauer <wr@rosenauer.org>
     2 Sun May 19 20:40:30 UTC 2019 - Wolfgang Rosenauer <wr@rosenauer.org>
     3 
     3 
     4 - Mozilla Firefox 67.0
     4 - Mozilla Firefox 67.0
     5   * Firefox 67 will be able to run different Firefox installs side by side
     5   * Firefox 67 will be able to run different Firefox installs side by side
     6     https://blog.nightly.mozilla.org/2019/01/14/moving-to-a-profile-per-install-architecture/
     6     https://blog.nightly.mozilla.org/2019/01/14/moving-to-a-profile-per-install-architecture/
     7   * Tabs can now be pinned from the Page Actions menu in the address bar
     7   * Tabs can now be pinned from the Page Actions menu in the address bar
    17     transparency for when you are synced, sharing data across devices
    17     transparency for when you are synced, sharing data across devices
    18     and with Firefox. Personalize the appearance of the menu with your
    18     and with Firefox. Personalize the appearance of the menu with your
    19     own avatar
    19     own avatar
    20   * Enable FIDO U2F API, and permit registrations for Google Accounts
    20   * Enable FIDO U2F API, and permit registrations for Google Accounts
    21   * Enabled AV1 support on Linux
    21   * Enabled AV1 support on Linux
       
    22   MFSA 2019-13
       
    23   * CVE-2019-9815 (bmo#1546544)
       
    24     Disable hyperthreading on content JavaScript threads on macOS
       
    25   * CVE-2019-9816 (bmo#1536768)
       
    26     Type confusion with object groups and UnboxedObjects
       
    27   * CVE-2019-9817 (bmo#1540221)
       
    28     Stealing of cross-domain images using canvas
       
    29   * CVE-2019-9818 (bmo#1542581) (Windows only)
       
    30     Use-after-free in crash generation server
       
    31   * CVE-2019-9819 (bmo#1532553)
       
    32     Compartment mismatch with fetch API
       
    33   * CVE-2019-9820 (bmo#1536405)
       
    34     Use-after-free of ChromeEventHandler by DocShell
       
    35   * CVE-2019-9821 (bmo#1539125)
       
    36     Use-after-free in AssertWorkerThread
       
    37   * CVE-2019-11691 (bmo#1542465)
       
    38     Use-after-free in XMLHttpRequest
       
    39   * CVE-2019-11692 (bmo#1544670)
       
    40     Use-after-free removing listeners in the event listener manager
       
    41   * CVE-2019-11693 (bmo#1532525)
       
    42     Buffer overflow in WebGL bufferdata on Linux
       
    43   * CVE-2019-7317 (bmo#1542829)
       
    44     Use-after-free in png_image_free of libpng library
       
    45   * CVE-2019-11694 (bmo#1534196) (Windows only)
       
    46     Uninitialized memory memory leakage in Windows sandbox
       
    47   * CVE-2019-11695 (bmo#1445844)
       
    48     Custom cursor can render over user interface outside of web content
       
    49   * CVE-2019-11696 (bmo#1392955)
       
    50     Java web start .JNLP files are not recognized as executable files
       
    51     for download prompts
       
    52   * CVE-2019-11697 (bmo#1440079)
       
    53     Pressing key combinations can bypass installation prompt delays and
       
    54     install extensions
       
    55   * CVE-2019-11698 (bmo#1543191)
       
    56     Theft of user history data through drag and drop of hyperlinks
       
    57     to and from bookmarks
       
    58   * CVE-2019-11700 (bmo#1549833) (Windows only)
       
    59     res: protocol can be used to open known local files
       
    60   * CVE-2019-11699 (bmo#1528939)
       
    61     Incorrect domain name highlighting during page navigation
       
    62   * CVE-2019-11701 (bmo#1518627)
       
    63     webcal: protocol default handler loads vulnerable web page
       
    64   * CVE-2019-9814 (bmo#1527592, bmo#1534536, bmo#1520132, bmo#1543159,
       
    65     bmo#1539393, bmo#1459932, bmo#1459182, bmo#1516425)
       
    66     Memory safety bugs fixed in Firefox 67
       
    67   * CVE-2019-9800 (bmo#1540166, bmo#1534593, bmo#1546327, bmo#1540136,
       
    68     bmo#1538736, bmo#1538042, bmo#1535612, bmo#1499719, bmo#1499108,
       
    69     bmo#1538619, bmo#1535194, bmo#1516325, bmo#1542324, bmo#1542097,
       
    70     bmo#1532465, bmo#1533554, bmo#1541580)
       
    71     Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7
    22 - requires
    72 - requires
    23   * rust/cargo >= 1.32
    73   * rust/cargo >= 1.32
    24   * mozilla-nspr >= 4.21
    74   * mozilla-nspr >= 4.21
    25   * mozilla-nss >= 3.43
    75   * mozilla-nss >= 3.43
    26   * rust-cbindgen >= 0.8.2
    76   * rust-cbindgen >= 0.8.2
    27 - rebased patches
    77 - rebased patches
    28 - KDE integration for default browser detection is broken in this revision
    78 - KDE integration for default browser detection is broken in this revision
       
    79 
       
    80 -------------------------------------------------------------------
       
    81 Fri May 17 12:04:49 UTC 2019 - Guillaume GARDET <guillaume.gardet@opensuse.org>
       
    82 
       
    83 - Fix armv7 build with:
       
    84   * mozilla-disable-wasm-emulate-arm-unaligned-fp-access.patch
    29 
    85 
    30 -------------------------------------------------------------------
    86 -------------------------------------------------------------------
    31 Fri May 10 10:30:05 UTC 2019 - Manfred Hollstein <manfred.h@gmx.net>
    87 Fri May 10 10:30:05 UTC 2019 - Manfred Hollstein <manfred.h@gmx.net>
    32 
    88 
    33 - Mozilla Firefox 66.0.5
    89 - Mozilla Firefox 66.0.5