xulrunner/xulrunner.changes
branchfirefox14
changeset 497 f188ba3bcc70
parent 495 8ed13b37e5fb
child 501 e1d2a183f691
equal deleted inserted replaced
496:3c23dab1c5d9 497:f188ba3bcc70
     1 -------------------------------------------------------------------
     1 -------------------------------------------------------------------
     2 Sat Jul 14 19:33:44 UTC 2012 - wr@rosenauer.org
     2 Sat Jul 14 19:33:44 UTC 2012 - wr@rosenauer.org
     3 
     3 
     4 - update to 14.0.1 (bnc#)
     4 - update to 14.0.1 (bnc#771583)
       
     5   * MFSA 2012-42/CVE-2012-1949/CVE-2012-1948
       
     6     Miscellaneous memory safety hazards
       
     7   * MFSA 2012-43/CVE-2012-1950
       
     8     Incorrect URL displayed in addressbar through drag and drop
       
     9   * MFSA 2012-44/CVE-2012-1951/CVE-2012-1954/CVE-2012-1953/CVE-2012-1952
       
    10     Gecko memory corruption
       
    11   * MFSA 2012-45/CVE-2012-1955 (bmo#757376)
       
    12     Spoofing issue with location
       
    13   * MFSA 2012-46/CVE-2012-1966 (bmo#734076)
       
    14     XSS through data: URLs
       
    15   * MFSA 2012-47/CVE-2012-1957 (bmo#750096)
       
    16     Improper filtering of javascript in HTML feed-view
       
    17   * MFSA 2012-48/CVE-2012-1958 (bmo#750820)
       
    18     use-after-free in nsGlobalWindow::PageHidden
       
    19   * MFSA 2012-49/CVE-2012-1959 (bmo#754044, bmo#737559)
       
    20     Same-compartment Security Wrappers can be bypassed
       
    21   * MFSA 2012-50/CVE-2012-1960 (bmo#761014)
       
    22     Out of bounds read in QCMS
       
    23   * MFSA 2012-51/CVE-2012-1961 (bmo#761655)
       
    24     X-Frame-Options header ignored when duplicated
       
    25   * MFSA 2012-52/CVE-2012-1962 (bmo#764296)
       
    26     JSDependentString::undepend string conversion results in memory
       
    27     corruption
       
    28   * MFSA 2012-53/CVE-2012-1963 (bmo#767778)
       
    29     Content Security Policy 1.0 implementation errors cause data
       
    30     leakage
       
    31   * MFSA 2012-55/CVE-2012-1965 (bmo#758990)
       
    32     feed: URLs with an innerURI inherit security context of page
       
    33   * MFSA 2012-56/CVE-2012-1967 (bmo#758344)
       
    34     Code execution through javascript: URLs
     5 - license change from tri license to MPL-2.0
    35 - license change from tri license to MPL-2.0
     6 - require NSS 3.13.5
    36 - require NSS 3.13.5
     7 - PPC fixes:
    37 - PPC fixes:
     8   * reenabled mozilla-yarr-pcre.patch to fix build for PPC
    38   * reenabled mozilla-yarr-pcre.patch to fix build for PPC
     9   * add patches for bmo#750620 and bmo#746112
    39   * add patches for bmo#750620 and bmo#746112
    10   * fix xpcshell segfault on ppc
    40   * fix xpcshell segfault on ppc
       
    41 - build plugin-container on every arch
    11 
    42 
    12 -------------------------------------------------------------------
    43 -------------------------------------------------------------------
    13 Sat Jun  2 09:16:34 UTC 2012 - wr@rosenauer.org
    44 Sat Jun  2 09:16:34 UTC 2012 - wr@rosenauer.org
    14 
    45 
    15 - update to 13.0 (bnc#765204)
    46 - update to 13.0 (bnc#765204)