MozillaFirefox/MozillaFirefox.changes
branchfirefox80
changeset 1141 edb0ebe8cccc
parent 1140 a9aa543a508a
child 1142 c5e32127317c
equal deleted inserted replaced
1140:a9aa543a508a 1141:edb0ebe8cccc
       
     1 -------------------------------------------------------------------
       
     2 Sat Aug 22 06:52:01 UTC 2020 - Wolfgang Rosenauer <wr@rosenauer.org>
       
     3 
       
     4 - Mozilla Firefox 80.0
       
     5   MFSA 2020-36 (bsc#1175686)
       
     6   * CVE-2020-15663 (bmo#1643199)
       
     7     Downgrade attack on the Mozilla Maintenance Service could
       
     8     have resulted in escalation of privilege
       
     9   * CVE-2020-15664 (bmo#1658214)
       
    10     Attacker-induced prompt for extension installation
       
    11   * CVE-2020-12401 (bmo#1631573)
       
    12     Timing-attack on ECDSA signature generation
       
    13   * CVE-2020-6829 (bmo#1631583)
       
    14     P-384 and P-521 vulnerable to an electro-magnetic side
       
    15     channel attack on signature generation
       
    16   * CVE-2020-12400 (bmo#1623116)
       
    17     P-384 and P-521 vulnerable to a side channel attack on
       
    18     modular inversion
       
    19   * CVE-2020-15665 (bmo#1651636)
       
    20     Address bar not reset when choosing to stay on a page after
       
    21     the beforeunload dialog is shown
       
    22   * CVE-2020-15666 (bmo#1450853)
       
    23     MediaError message property leaks cross-origin response
       
    24     status
       
    25   * CVE-2020-15667 (bmo#1653371)
       
    26     Heap overflow when processing an update file
       
    27   * CVE-2020-15668 (bmo#1651520)
       
    28     Data Race when reading certificate information
       
    29   * CVE-2020-15670 (bmo#1651001, bmo#1651449, bmo#1653626,
       
    30     bmo#1656957)
       
    31     Memory safety bugs fixed in Firefox 80 and Firefox ESR 78.2
       
    32 - requires
       
    33   * NSPR 4.27
       
    34   * NSS 3.55
       
    35 - added mozilla-system-nspr.patch (bmo#1661096)
       
    36 - exclude ga-IE locale as it's failing to build
       
    37 - rollback parallelize locale build because it breaks bookmarks
       
    38   (boo#1167976)
       
    39 - preserve original default bookmark file during langpack build
       
    40   (boo#1167976)
       
    41 - add some ccache output during build
       
    42 
     1 -------------------------------------------------------------------
    43 -------------------------------------------------------------------
     2 Thu Aug 20 13:07:33 UTC 2020 - Martin Liška <mliska@suse.cz>
    44 Thu Aug 20 13:07:33 UTC 2020 - Martin Liška <mliska@suse.cz>
     3 
    45 
     4 - Use new memoryperjob _constraints instead of %limit_build macro.
    46 - Use new memoryperjob _constraints instead of %limit_build macro.
     5 
    47