MozillaFirefox/MozillaFirefox.changes
changeset 778 9483ff78d5a0
parent 777 f1c5ccf4d1a7
child 780 c20a07035a80
--- a/MozillaFirefox/MozillaFirefox.changes	Sat Oct 11 10:33:51 2014 +0200
+++ b/MozillaFirefox/MozillaFirefox.changes	Thu Oct 16 21:20:22 2014 +0200
@@ -1,11 +1,47 @@
 -------------------------------------------------------------------
-Sun Oct  5 16:10:28 UTC 2014 - wr@rosenauer.org
-
-- update to Firefox 33.0b9
+Wed Oct 15 08:05:33 UTC 2014 - wr@rosenauer.org
+
+- fix build for all ppc by not enabling elf-hack
+  (bnc#901213)
+
+-------------------------------------------------------------------
+Sat Oct 11 08:48:24 UTC 2014 - wr@rosenauer.org
+
+- update to Firefox 33.0 (bnc#900941)
+  New features:
+  * OpenH264 support (sandboxed)
+  * Enhanced Tiles
+  * Improved search experience through the location bar
+  * Slimmer and faster JavaScript strings
+  * New CSP (Content Security Policy) backend
+  * Support for connecting to HTTP proxy over HTTPS
+  * Improved reliability of the session restoration
+  * Proprietary window.crypto properties/functions removed
+  Security:
+  * MFSA 2014-74/CVE-2014-1574/CVE-2014-1575
+    Miscellaneous memory safety hazards
+  * MFSA 2014-75/CVE-2014-1576 (bmo#1041512)
+    Buffer overflow during CSS manipulation
+  * MFSA 2014-76/CVE-2014-1577 (bmo#1012609)
+    Web Audio memory corruption issues with custom waveforms
+  * MFSA 2014-77/CVE-2014-1578 (bmo#1063327)
+    Out-of-bounds write with WebM video
+  * MFSA 2014-78/CVE-2014-1580 (bmo#1063733)
+    Further uninitialized memory use during GIF rendering
+  * MFSA 2014-79/CVE-2014-1581 (bmo#1068218)
+    Use-after-free interacting with text directionality
+  * MFSA 2014-80/CVE-2014-1582/CVE-2014-1584 (bmo#1049095, bmo#1066190)
+    Key pinning bypasses
+  * MFSA 2014-81/CVE-2014-1585/CVE-2014-1586 (bmo#1062876, bmo#1062981)
+    Inconsistent video sharing within iframe
+  * MFSA 2014-82/CVE-2014-1583 (bmo#1015540)
+    Accessing cross-origin objects via the Alarms API
+    (only relevant for installed web apps)
 - requires NSPR 4.10.7
 - requires NSS 3.17.1
-- removed obsolete patch:
+- removed obsolete patches:
   * mozilla-ppc.patch
+  * mozilla-libproxy-compat.patch
 - added basic appdata information
 
 -------------------------------------------------------------------