MozillaFirefox/firefox-esr.changes
branchesr10
changeset 532 cde8c37e1592
parent 499 f5a9af1c8605
child 549 eed5124a1ab3
--- a/MozillaFirefox/firefox-esr.changes	Thu Jul 19 00:11:54 2012 +0200
+++ b/MozillaFirefox/firefox-esr.changes	Tue Aug 28 20:52:20 2012 +0200
@@ -1,3 +1,29 @@
+-------------------------------------------------------------------
+Sun Aug 26 13:56:19 UTC 2012 - wr@rosenauer.org
+
+- update to Firefox 10.0.7esr (bnc#777588)
+  * MFSA 2012-57/CVE-2012-1970
+    Miscellaneous memory safety hazards
+  * MFSA 2012-58/CVE-2012-1972/CVE-2012-1973/CVE-2012-1974/CVE-2012-1975
+    CVE-2012-1976/CVE-2012-3956/CVE-2012-3957/CVE-2012-3958/CVE-2012-3959
+    CVE-2012-3960/CVE-2012-3961/CVE-2012-3962/CVE-2012-3963/CVE-2012-3964
+    Use-after-free issues found using Address Sanitizer
+  * MFSA 2012-61/CVE-2012-3966 (bmo#775794, bmo#775793)
+    Memory corruption with bitmap format images with negative height
+  * MFSA 2012-62/CVE-2012-3967/CVE-2012-3968
+    WebGL use-after-free and memory corruption
+  * MFSA 2012-63/CVE-2012-3969/CVE-2012-3970
+    SVG buffer overflow and use-after-free issues
+  * MFSA 2012-65/CVE-2012-3972 (bmo#746855)
+    Out-of-bounds read in format-number in XSLT
+  * MFSA 2012-69/CVE-2012-3976 (bmo#768568)
+    Incorrect site SSL certificate data display
+  * MFSA 2012-70/CVE-2012-3978 (bmo#770429)
+    Location object security checks bypassed by chrome code
+  * MFSA 2012-72/CVE-2012-3980 (bmo#771859)
+    Web console eval capable of executing chrome-privileged code
+- fixed gcc 4.7 related build errors
+
 -------------------------------------------------------------------
 Sat Jul 14 18:27:24 UTC 2012 - wr@rosenauer.org