author | Wolfgang Rosenauer <wr@rosenauer.org> |
Fri, 19 Jun 2015 17:20:28 +0200 | |
changeset 861 | aa12e155bdd8 |
parent 857 | ab297940ae8a |
child 862 | 390088186660 |
permissions | -rw-r--r-- |
539
b1134fe91f9a
merge latest changes from firefox16
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
536
diff
changeset
|
1 |
------------------------------------------------------------------- |
861 | 2 |
Wed Jun 17 10:48:49 UTC 2015 - wr@rosenauer.org |
3 |
||
4 |
- update to Firefox 39.0b6 |
|
857 | 5 |
- dropped mozilla-prefer_plugin_pref.patch as this feature is |
6 |
likely not worth maintaining further |
|
7 |
- rebased patches |
|
8 |
- require NSS 3.19.1 |
|
9 |
||
10 |
------------------------------------------------------------------- |
|
854 | 11 |
Sun Jun 7 07:09:12 UTC 2015 - wr@rosenauer.org |
12 |
||
13 |
- update to Firefox 38.0.6 |
|
855 | 14 |
* fixes bmo#1171730 which is not really relevant to oS builds |
15 |
- fix KDE regression from 38.0.5 builds (bsc#933439) |
|
854 | 16 |
|
17 |
------------------------------------------------------------------- |
|
853 | 18 |
Sat May 23 21:13:49 UTC 2015 - wr@rosenauer.org |
19 |
||
20 |
- update to Firefox 38.0.5 |
|
21 |
* Keep track of articles and videos with Pocket |
|
22 |
* Clean formatting for articles and blog posts with Reader View |
|
23 |
* Share the active tab or window in a Hello conversation |
|
24 |
- add changes file as source for SRPM (bsc#932142) |
|
25 |
||
26 |
------------------------------------------------------------------- |
|
852 | 27 |
Fri May 15 10:40:19 UTC 2015 - normand@linux.vnet.ibm.com |
28 |
||
29 |
- add mozilla-add-glibcxx_use_cxx11_abi.patch grabbed from |
|
30 |
https://bugzilla.mozilla.org/show_bug.cgi?id=1153109 |
|
31 |
||
32 |
------------------------------------------------------------------- |
|
33 |
Fri May 15 07:37:46 UTC 2015 - wr@rosenauer.org |
|
34 |
||
35 |
- update to Firefox 38.0.1 |
|
36 |
stability and regression fixes |
|
37 |
* Systems with first generation NVidia Optimus graphics cards |
|
38 |
may crash on start-up |
|
39 |
* Users who import cookies from Google Chrome can end up with |
|
40 |
broken websites |
|
41 |
* Large animated images may fail to play and may stop other |
|
42 |
images from loading |
|
43 |
||
44 |
------------------------------------------------------------------- |
|
851 | 45 |
Sun May 10 07:07:49 UTC 2015 - wr@rosenauer.org |
46 |
||
852 | 47 |
- update to Firefox 38.0 (bnc#930622) |
48 |
* New tab-based preferences |
|
49 |
* Ruby annotation support |
|
50 |
* more info: https://www.mozilla.org/en-US/firefox/38.0/releasenotes/ |
|
51 |
security fixes: |
|
52 |
* MFSA 2015-46/CVE-2015-2708/CVE-2015-2709 |
|
53 |
Miscellaneous memory safety hazards |
|
54 |
* MFSA 2015-47/VE-2015-0797 (bmo#1080995) |
|
55 |
Buffer overflow parsing H.264 video with Linux Gstreamer |
|
56 |
* MFSA 2015-48/CVE-2015-2710 (bmo#1149542) |
|
57 |
Buffer overflow with SVG content and CSS |
|
58 |
* MFSA 2015-49/CVE-2015-2711 (bmo#1113431) |
|
59 |
Referrer policy ignored when links opened by middle-click and |
|
60 |
context menu |
|
61 |
* MFSA 2015-50/CVE-2015-2712 (bmo#1152280) |
|
62 |
Out-of-bounds read and write in asm.js validation |
|
63 |
* MFSA 2015-51/CVE-2015-2713 (bmo#1153478) |
|
64 |
Use-after-free during text processing with vertical text enabled |
|
65 |
* MFSA 2015-53/CVE-2015-2715 (bmo#988698) |
|
66 |
Use-after-free due to Media Decoder Thread creation during shutdown |
|
67 |
* MFSA 2015-54/CVE-2015-2716 (bmo#1140537) |
|
68 |
Buffer overflow when parsing compressed XML |
|
69 |
* MFSA 2015-55/CVE-2015-2717 (bmo#1154683) |
|
70 |
Buffer overflow and out-of-bounds read while parsing MP4 video |
|
71 |
metadata |
|
72 |
* MFSA 2015-56/CVE-2015-2718 (bmo#1146724) |
|
73 |
Untrusted site hosting trusted page can intercept webchannel |
|
74 |
responses |
|
75 |
* MFSA 2015-57/CVE-2011-3079 (bmo#1087565) |
|
76 |
Privilege escalation through IPC channel messages |
|
850 | 77 |
- requires NSS 3.18.1 |
851 | 78 |
- removed obsolete patches: |
79 |
* mozilla-skia-bmo1136958.patch |
|
80 |
- remove gnomevfs build options as it is removed from sources |
|
81 |
- rebased patches |
|
850 | 82 |
|
83 |
------------------------------------------------------------------- |
|
84 |
Fri Apr 17 16:39:20 UTC 2015 - wr@rosenauer.org |
|
85 |
||
86 |
- update to Firefox 37.0.2 (bnc#928116) |
|
87 |
* MFSA 2015-45/CVE-2015-2706 (bmo#1141081) |
|
88 |
Memory corruption during failed plugin initialization |
|
845 | 89 |
|
90 |
------------------------------------------------------------------- |
|
844 | 91 |
Fri Apr 3 08:27:24 UTC 2015 - wr@rosenauer.org |
92 |
||
93 |
- update to Firefox 37.0.1 (bnc#926166) |
|
94 |
* MFSA 2015-43/CVE-2015-0798 (bmo#1147597) (Android only) |
|
95 |
Loading privileged content through Reader mode |
|
96 |
* MFSA 2015-44/CVE-2015-0799 (bmo#1148328) |
|
97 |
Certificate verification bypass through the HTTP/2 Alt-Svc header |
|
98 |
||
99 |
------------------------------------------------------------------- |
|
100 |
Sat Mar 28 09:46:48 UTC 2015 - wr@rosenauer.org |
|
101 |
||
102 |
- update to Firefox 37.0 (bnc#925368) |
|
103 |
* Heartbeat user rating system |
|
104 |
* Yandex set as default search provider for the Turkish locale |
|
105 |
* Bing search now uses HTTPS for secure searching |
|
106 |
* Improved protection against site impersonation via OneCRL |
|
107 |
centralized certificate revocation |
|
108 |
* Opportunistically encrypt HTTP traffic where the server supports |
|
109 |
HTTP/2 AltSvc |
|
110 |
* some more behaviour changes for TLS |
|
111 |
security fixes: |
|
112 |
* MFSA 2015-30/CVE-2015-0814/CVE-2015-0815 |
|
113 |
Miscellaneous memory safety hazards |
|
114 |
* MFSA 2015-31/CVE-2015-0813 (bmo#1106596)) |
|
115 |
Use-after-free when using the Fluendo MP3 GStreamer plugin |
|
116 |
* MFSA 2015-32/CVE-2015-0812 (bmo#1128126) |
|
117 |
Add-on lightweight theme installation approval bypassed through |
|
118 |
MITM attack |
|
119 |
* MFSA 2015-33/CVE-2015-0816 (bmo#1144991) |
|
120 |
resource:// documents can load privileged pages |
|
121 |
* MFSA-2015-34/CVE-2015-0811 (bmo#1132468) |
|
122 |
Out of bounds read in QCMS library |
|
123 |
* MFSA-2015-35/CVE-2015-0810 (bmo#1125013) |
|
124 |
Cursor clickjacking with flash and images (OS X only) |
|
125 |
* MFSA-2015-36/CVE-2015-0808 (bmo#1109552) |
|
126 |
Incorrect memory management for simple-type arrays in WebRTC |
|
127 |
* MFSA-2015-37/CVE-2015-0807 (bmo#1111834) |
|
128 |
CORS requests should not follow 30x redirections after preflight |
|
129 |
* MFSA-2015-38/CVE-2015-0805/CVE-2015-0806 (bmo#1135511, bmo#1099437) |
|
130 |
Memory corruption crashes in Off Main Thread Compositing |
|
131 |
* MFSA-2015-39/CVE-2015-0803/CVE-2015-0804 (bmo#1134560) |
|
132 |
Use-after-free due to type confusion flaws |
|
133 |
* MFSA-2015-40/CVE-2015-0801 (bmo#1146339) |
|
134 |
Same-origin bypass through anchor navigation |
|
135 |
* MFSA-2015-41/CVE-2015-0800/CVE-2012-2808 |
|
136 |
PRNG weakness allows for DNS poisoning on Android (only) |
|
137 |
* MFSA-2015-42/CVE-2015-0802 (bmo#1124898) |
|
138 |
Windows can retain access to privileged content on navigation |
|
139 |
to unprivileged pages |
|
140 |
- removed obsolete patches |
|
837 | 141 |
* mozilla-bmo1088588.patch |
844 | 142 |
* mozilla-bmo1108834.patch |
836
12530a091878
prepare 37 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
831
diff
changeset
|
143 |
- requires NSPR 4.10.8 |
12530a091878
prepare 37 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
831
diff
changeset
|
144 |
|
12530a091878
prepare 37 beta cycle
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
831
diff
changeset
|
145 |
------------------------------------------------------------------- |
844 | 146 |
Tue Mar 24 15:35:24 UTC 2015 - dvaleev@suse.com |
147 |
||
148 |
- Fix builds with skia on Power |
|
149 |
mozilla-skia-be-le.patch (patch from #bmo1136958) |
|
150 |
mozilla-bmo1108834.patch |
|
151 |
mozilla-bmo1005535.patch |
|
152 |
||
153 |
------------------------------------------------------------------- |
|
839 | 154 |
Sat Mar 21 09:03:12 UTC 2015 - wr@rosenauer.org |
155 |
||
840 | 156 |
- update to Firefox 36.0.4 (bnc#923534) |
839 | 157 |
* MFSA 2015-28/CVE-2015-0818 (bmo#1144988) |
158 |
Privilege escalation through SVG navigation |
|
159 |
* MFSA 2015-29/CVE-2015-0817 (bmo#1145255) |
|
160 |
Code execution through incorrect JavaScript bounds checking |
|
161 |
elimination |
|
162 |
||
163 |
------------------------------------------------------------------- |
|
164 |
Fri Mar 20 15:02:33 UTC 2015 - dimstar@opensuse.org |
|
165 |
||
166 |
- Copy the icons to /usr/share/icons instead of symlinking them: |
|
167 |
in preparation for containerized apps (e.g. xdg-app) as well as |
|
168 |
AppStream metadata extraction, there are a couple locations that |
|
169 |
need to be real files for system integration (.desktop files, |
|
170 |
icons, mime-type info). |
|
171 |
||
172 |
------------------------------------------------------------------- |
|
838 | 173 |
Sat Mar 7 07:40:56 UTC 2015 - wr@rosenauer.org |
174 |
||
175 |
- update to Firefox 36.0.1 |
|
176 |
Bugfixes: |
|
177 |
* Disable the usage of the ANY DNS query type (bmo#1093983) |
|
178 |
* Hello may become inactive until restart (bmo#1137469) |
|
179 |
* Print preferences may not be preserved (bmo#1136855) |
|
180 |
* Hello contact tabs may not be visible (bmo#1137141) |
|
181 |
* Accept hostnames that include an underscore character ("_") |
|
182 |
(bmo#1136616) |
|
183 |
* WebGL may use significant memory with Canvas2d (bmo#1137251) |
|
184 |
* Option -remote has been restored (bmo#1080319) |
|
840 | 185 |
- added mozilla-skia-bmo1136958.patch to fix build issues for |
186 |
ARM and PPC |
|
838 | 187 |
|
188 |
------------------------------------------------------------------- |
|
832 | 189 |
Fri Feb 20 22:53:39 UTC 2015 - wr@rosenauer.org |
190 |
||
191 |
- update to Firefox 36.0 (bnc#917597) |
|
828 | 192 |
* mozilla-xremote-client was removed |
193 |
* added libclearkey.so media plugin |
|
832 | 194 |
* Pinned tiles on the new tab page can be synced |
195 |
* Support for the full HTTP/2 protocol. HTTP/2 enables a faster, |
|
196 |
more scalable, and more responsive web. |
|
197 |
* Locale added: Uzbek (uz) |
|
835 | 198 |
security fixes: |
199 |
* MFSA 2015-11/CVE-2015-0835/CVE-2015-0836 |
|
200 |
Miscellaneous memory safety hazards |
|
201 |
* MFSA 2015-12/CVE-2015-0833 (bmo#945192) |
|
202 |
Invoking Mozilla updater will load locally stored DLL files |
|
203 |
(Windows only) |
|
204 |
* MFSA 2015-13/CVE-2015-0832 (bmo#1065909) |
|
205 |
Appended period to hostnames can bypass HPKP and HSTS protections |
|
206 |
* MFSA 2015-14/CVE-2015-0830 (bmo#1110488) |
|
207 |
Malicious WebGL content crash when writing strings |
|
208 |
* MFSA 2015-15/CVE-2015-0834 (bmo#1098314) |
|
209 |
TLS TURN and STUN connections silently fail to simple TCP connections |
|
210 |
* MFSA 2015-16/CVE-2015-0831 (bmo#1130514) |
|
211 |
Use-after-free in IndexedDB |
|
212 |
* MFSA 2015-17/CVE-2015-0829 (bmo#1128939) |
|
213 |
Buffer overflow in libstagefright during MP4 video playback |
|
214 |
* MFSA 2015-18/CVE-2015-0828 (bmo#1030667, bmo#988675) |
|
215 |
Double-free when using non-default memory allocators with a |
|
216 |
zero-length XHR |
|
217 |
* MFSA 2015-19/CVE-2015-0827 (bmo#1117304) |
|
218 |
Out-of-bounds read and write while rendering SVG content |
|
219 |
* MFSA 2015-20/CVE-2015-0826 (bmo#1092363) |
|
220 |
Buffer overflow during CSS restyling |
|
221 |
* MFSA 2015-21/CVE-2015-0825 (bmo#1092370) |
|
222 |
Buffer underflow during MP3 playback |
|
223 |
* MFSA 2015-22/CVE-2015-0824 (bmo#1095925) |
|
224 |
Crash using DrawTarget in Cairo graphics library |
|
225 |
* MFSA 2015-23/CVE-2015-0823 (bmo#1098497) |
|
226 |
Use-after-free in Developer Console date with OpenType Sanitiser |
|
227 |
* MFSA 2015-24/CVE-2015-0822 (bmo#1110557) |
|
228 |
Reading of local files through manipulation of form autocomplete |
|
229 |
* MFSA 2015-25/CVE-2015-0821 (bmo#1111960) |
|
230 |
Local files or privileged URLs in pages can be opened into new tabs |
|
231 |
* MFSA 2015-26/CVE-2015-0819 (bmo#1079554) |
|
232 |
UI Tour whitelisted sites in background tab can spoof foreground |
|
233 |
tabs |
|
234 |
* MFSA 2015-27CVE-2015-0820 (bmo#1125398) |
|
235 |
Caja Compiler JavaScript sandbox bypass |
|
832 | 236 |
- rebased patches |
830 | 237 |
- requires NSS 3.17.4 |
238 |
||
239 |
------------------------------------------------------------------- |
|
240 |
Sat Jan 31 18:37:38 UTC 2015 - wr@rosenauer.org |
|
241 |
||
242 |
- update to Firefox 35.0.1 |
|
243 |
* With the Enhanced Steam extension, Firefox could crash (bmo#1123732) |
|
244 |
* Kerberos authentication did not work with alias (bmo#1108971) |
|
245 |
* SVG / CSS animation had a regression causing rendering issues on |
|
246 |
websites like openstreemap.org (bmo#1083079) |
|
247 |
* On Godaddy webmail, Firefox could crash (bmo#1113121) |
|
248 |
* document.baseURI did not get updated to document.location after |
|
249 |
base tag was removed from DOM for site with a CSP (bmo#1121857) |
|
250 |
* With a Right-to-left (RTL) version of Firefox, the text selection |
|
251 |
could be broken (bmo#1104036) |
|
252 |
* CSP had a change in behavior with regard to case sensitivity |
|
253 |
resources loading (bmo#1122445) |
|
828 | 254 |
|
255 |
------------------------------------------------------------------- |
|
826 | 256 |
Sat Jan 10 18:36:37 UTC 2015 - wr@rosenauer.org |
257 |
||
258 |
- update to Firefox 35.0 (bnc#910669) |
|
827 | 259 |
notable features: |
260 |
* Firefox Hello with new rooms-based conversations model |
|
261 |
* Implemented HTTP Public Key Pinning Extension (for enhanced |
|
262 |
authentication of encrypted connections) |
|
263 |
security fixes: |
|
264 |
* MFSA 2015-01/CVE-2014-8634/CVE-2014-8635 |
|
265 |
Miscellaneous memory safety hazards |
|
266 |
* MFSA 2015-02/CVE-2014-8637 (bmo#1094536) |
|
267 |
Uninitialized memory use during bitmap rendering |
|
268 |
* MFSA 2015-03/CVE-2014-8638 (bmo#1080987) |
|
269 |
sendBeacon requests lack an Origin header |
|
270 |
* MFSA 2015-04/CVE-2014-8639 (bmo#1095859) |
|
271 |
Cookie injection through Proxy Authenticate responses |
|
272 |
* MFSA 2015-05/CVE-2014-8640 (bmo#1100409) |
|
273 |
Read of uninitialized memory in Web Audio |
|
274 |
* MFSA 2015-06/CVE-2014-8641 (bmo#1108455) |
|
275 |
Read-after-free in WebRTC |
|
276 |
* MFSA 2015-07/CVE-2014-8643 (bmo#1114170) (Windows-only) |
|
277 |
Gecko Media Plugin sandbox escape |
|
278 |
* MFSA 2015-08/CVE-2014-8642 (bmo#1079658) |
|
279 |
Delegated OCSP responder certificates failure with |
|
280 |
id-pkix-ocsp-nocheck extension |
|
281 |
* MFSA 2015-09/CVE-2014-8636 (bmo#987794) |
|
282 |
XrayWrapper bypass through DOM objects |
|
807
f54c68340963
Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
806
diff
changeset
|
283 |
- rebased patches |
809
af47260a332c
morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
807
diff
changeset
|
284 |
- dropped explicit support for everything older than 12.3 |
af47260a332c
morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
807
diff
changeset
|
285 |
(including SLES11) |
af47260a332c
morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
807
diff
changeset
|
286 |
* merge firefox-kde.patch and firefox-kde-114.patch |
af47260a332c
morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
807
diff
changeset
|
287 |
* dropped mozilla-sle11.patch |
af47260a332c
morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
807
diff
changeset
|
288 |
- reworked specfile to build conditionally based on release channel |
af47260a332c
morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
807
diff
changeset
|
289 |
either Firefox or Firefox Developer Edition |
af47260a332c
morphed Aurora packaging into Firefox Developer Edition
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
807
diff
changeset
|
290 |
- added mozilla-openaes-decl.patch to fix implicit declarations |
819
5a18bd66e46c
[Bug 908892] Updated Firefox (33.0-1.90.1 -> 34.0.5-1.94.3) crashes in tracker-miner-firefox
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
818
diff
changeset
|
291 |
- obsolete tracker-miner-firefox < 0.15 because it leads to startup |
5a18bd66e46c
[Bug 908892] Updated Firefox (33.0-1.90.1 -> 34.0.5-1.94.3) crashes in tracker-miner-firefox
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
818
diff
changeset
|
292 |
crashes (bnc#908892) |
807
f54c68340963
Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
806
diff
changeset
|
293 |
|
f54c68340963
Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
806
diff
changeset
|
294 |
------------------------------------------------------------------- |
820 | 295 |
Sat Dec 13 22:13:00 UTC 2014 - Led <ledest@gmail.com> |
296 |
||
297 |
- fix bashism in mozilla.sh script |
|
298 |
||
299 |
------------------------------------------------------------------- |
|
813
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
300 |
Sat Nov 29 21:23:03 UTC 2014 - wr@rosenauer.org |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
301 |
|
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
302 |
- update to Firefox 34.0.5 (bnc#908009) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
303 |
* Default search engine changed to Yahoo! for North America |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
304 |
* Default search engine changed to Yandex for Belarusian, Kazakh, |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
305 |
and Russian locales |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
306 |
* Improved search bar (en-US only) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
307 |
* Firefox Hello real-time communication client |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
308 |
* Easily switch themes/personas directly in the Customizing mode |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
309 |
* Implementation of HTTP/2 (draft14) and ALPN |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
310 |
* Disabled SSLv3 |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
311 |
* MFSA 2014-83/CVE-2014-1587/CVE-2014-1588 |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
312 |
Miscellaneous memory safety hazards |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
313 |
* MFSA 2014-84/CVE-2014-1589 (bmo#1043787) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
314 |
XBL bindings accessible via improper CSS declarations |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
315 |
* MFSA 2014-85/CVE-2014-1590 (bmo#1087633) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
316 |
XMLHttpRequest crashes with some input streams |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
317 |
* MFSA 2014-86/CVE-2014-1591 (bmo#1069762) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
318 |
CSP leaks redirect data via violation reports |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
319 |
* MFSA 2014-87/CVE-2014-1592 (bmo#1088635) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
320 |
Use-after-free during HTML5 parsing |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
321 |
* MFSA 2014-88/CVE-2014-1593 (bmo#1085175) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
322 |
Buffer overflow while parsing media content |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
323 |
* MFSA 2014-89/CVE-2014-1594 (bmo#1074280) |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
324 |
Bad casting from the BasicThebesLayer to BasicContainerLayer |
9e3063dcc69e
Firefox 34.0.5 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
811
diff
changeset
|
325 |
- rebased patches |
806 | 326 |
- limit linker memory usage for %ix86 |
807
f54c68340963
Aurora 35.0 (20141115) uplift
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
806
diff
changeset
|
327 |
- rebased patches |
805 | 328 |
|
329 |
------------------------------------------------------------------- |
|
801
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
330 |
Fri Nov 7 20:14:32 UTC 2014 - wr@rosenauer.org |
787 | 331 |
|
332 |
- update to Firefox 33.1 |
|
802 | 333 |
* Adding DuckDuckGo as a search option (upstream) |
334 |
* Forget Button added |
|
335 |
* Enhanced Tiles |
|
336 |
* Privacy tour introduced |
|
797
3b2d52457c91
fix typo on Recommends
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
789
diff
changeset
|
337 |
- fix typo in GStreamer Recommends |
787 | 338 |
|
339 |
------------------------------------------------------------------- |
|
801
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
340 |
Tue Nov 4 18:00:35 UTC 2014 - guillaume@opensuse.org |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
341 |
|
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
342 |
- Disable elf-hack for aarch64 |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
343 |
- Enable EGL for aarch64 |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
344 |
- Limit RAM usage during link for %arm |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
345 |
- Fix _constraints for ARM |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
346 |
|
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
347 |
------------------------------------------------------------------- |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
348 |
Mon Nov 3 11:36:04 UTC 2014 - dmueller@suse.com |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
349 |
|
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
350 |
- use proper macros for ARM |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
351 |
|
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
352 |
------------------------------------------------------------------- |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
353 |
Mon Nov 3 11:26:23 UTC 2014 - josua.mayer97@gmail.com |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
354 |
|
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
355 |
- use '--disable-optimize' not only on 32-bit x86, but on 32-bit arm too |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
356 |
to fix compiling. |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
357 |
- pass '-Wl,--no-keep-memory' to linker to reduce required memory during |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
358 |
linking on arm. |
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
359 |
|
f5f6f5547c2b
merge changes from OBS Factory submissions
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
797
diff
changeset
|
360 |
------------------------------------------------------------------- |
788 | 361 |
Thu Oct 30 11:31:05 UTC 2014 - wr@rosenauer.org |
362 |
||
363 |
- update to Firefox 33.0.2 |
|
364 |
* Fix a startup crash with some combination of hardware and drivers |
|
365 |
33.0.1 |
|
366 |
* Firefox displays a black screen at start-up with certain |
|
367 |
graphics drivers |
|
368 |
- adjusted _constraints for ARM |
|
369 |
||
370 |
------------------------------------------------------------------- |
|
786 | 371 |
Tue Oct 28 15:23:09 UTC 2014 - josua.mayer97@gmail.com |
372 |
||
373 |
- added mozilla-bmo1088588.patch to fix build with EGL (bmo#1088588) |
|
785 | 374 |
|
375 |
------------------------------------------------------------------- |
|
781
4ee017942f28
use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
780
diff
changeset
|
376 |
Sat Oct 25 08:45:43 UTC 2014 - wr@rosenauer.org |
4ee017942f28
use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
780
diff
changeset
|
377 |
|
4ee017942f28
use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
780
diff
changeset
|
378 |
- define /usr/share/myspell as additional dictionary location |
4ee017942f28
use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
780
diff
changeset
|
379 |
and remove add-plugins.sh finally (bnc#900639) |
4ee017942f28
use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
780
diff
changeset
|
380 |
|
4ee017942f28
use /usr/share/myspell directly and remove add-plugins.sh
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
780
diff
changeset
|
381 |
------------------------------------------------------------------- |
780
c20a07035a80
use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
777
diff
changeset
|
382 |
Sun Oct 19 12:59:28 UTC 2014 - vindex17@outlook.it |
c20a07035a80
use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
777
diff
changeset
|
383 |
|
c20a07035a80
use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
777
diff
changeset
|
384 |
- use Firefox default optimization flags instead of -Os |
c20a07035a80
use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
777
diff
changeset
|
385 |
- specfile cleanup |
c20a07035a80
use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
777
diff
changeset
|
386 |
|
c20a07035a80
use Firefox default optimization flags instead of -Os
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
777
diff
changeset
|
387 |
------------------------------------------------------------------- |
777 | 388 |
Wed Oct 15 08:05:33 UTC 2014 - wr@rosenauer.org |
389 |
||
390 |
- fix build for all ppc by not enabling elf-hack |
|
391 |
(bnc#901213) |
|
392 |
||
393 |
------------------------------------------------------------------- |
|
776
fd46c2b70724
prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
774
diff
changeset
|
394 |
Sat Oct 11 08:48:24 UTC 2014 - wr@rosenauer.org |
fd46c2b70724
prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
774
diff
changeset
|
395 |
|
777 | 396 |
- update to Firefox 33.0 (bnc#900941) |
397 |
New features: |
|
398 |
* OpenH264 support (sandboxed) |
|
399 |
* Enhanced Tiles |
|
400 |
* Improved search experience through the location bar |
|
401 |
* Slimmer and faster JavaScript strings |
|
402 |
* New CSP (Content Security Policy) backend |
|
403 |
* Support for connecting to HTTP proxy over HTTPS |
|
404 |
* Improved reliability of the session restoration |
|
405 |
* Proprietary window.crypto properties/functions removed |
|
406 |
Security: |
|
407 |
* MFSA 2014-74/CVE-2014-1574/CVE-2014-1575 |
|
408 |
Miscellaneous memory safety hazards |
|
409 |
* MFSA 2014-75/CVE-2014-1576 (bmo#1041512) |
|
410 |
Buffer overflow during CSS manipulation |
|
411 |
* MFSA 2014-76/CVE-2014-1577 (bmo#1012609) |
|
412 |
Web Audio memory corruption issues with custom waveforms |
|
413 |
* MFSA 2014-77/CVE-2014-1578 (bmo#1063327) |
|
414 |
Out-of-bounds write with WebM video |
|
415 |
* MFSA 2014-78/CVE-2014-1580 (bmo#1063733) |
|
416 |
Further uninitialized memory use during GIF rendering |
|
417 |
* MFSA 2014-79/CVE-2014-1581 (bmo#1068218) |
|
418 |
Use-after-free interacting with text directionality |
|
419 |
* MFSA 2014-80/CVE-2014-1582/CVE-2014-1584 (bmo#1049095, bmo#1066190) |
|
420 |
Key pinning bypasses |
|
421 |
* MFSA 2014-81/CVE-2014-1585/CVE-2014-1586 (bmo#1062876, bmo#1062981) |
|
422 |
Inconsistent video sharing within iframe |
|
423 |
* MFSA 2014-82/CVE-2014-1583 (bmo#1015540) |
|
424 |
Accessing cross-origin objects via the Alarms API |
|
425 |
(only relevant for installed web apps) |
|
765 | 426 |
- requires NSPR 4.10.7 |
773 | 427 |
- requires NSS 3.17.1 |
776
fd46c2b70724
prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
774
diff
changeset
|
428 |
- removed obsolete patches: |
773 | 429 |
* mozilla-ppc.patch |
776
fd46c2b70724
prepare 33.0 final release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
774
diff
changeset
|
430 |
* mozilla-libproxy-compat.patch |
774
f61bd1cd52c2
added basic appstream appdata information
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
773
diff
changeset
|
431 |
- added basic appdata information |
769 | 432 |
|
433 |
------------------------------------------------------------------- |
|
434 |
Sat Sep 20 13:33:51 UTC 2014 - wr@rosenauer.org |
|
435 |
||
436 |
- update to Firefox 32.0.2 |
|
437 |
* just a version bump for our builds |
|
438 |
* fixed the in application update process for certain environments |
|
439 |
(in application update is not enabled in openSUSE and Linux |
|
440 |
is unaffected in any case) |
|
441 |
- build with --disable-optimize for 13.1 and above for i586 to |
|
442 |
workaround miscompilations (bnc#896624) |
|
767 | 443 |
- use some more build flags to align with upstream |
765 | 444 |
|
445 |
------------------------------------------------------------------- |
|
761 | 446 |
Sat Sep 13 16:58:16 UTC 2014 - wr@rosenauer.org |
447 |
||
448 |
- update to Firefox 32.0.1 |
|
449 |
* fixed stability issues for computers with multiple graphics cards |
|
450 |
* mixed content icon may be incorrectly displayed instead of lock |
|
451 |
icon for SSL sites in 32.0 ( |
|
452 |
* WebRTC: setRemoteDescription() silently fails if no success |
|
453 |
callback is specified (bmo#1063971) |
|
454 |
||
455 |
------------------------------------------------------------------- |
|
759
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
456 |
Sun Aug 31 07:44:54 UTC 2014 - wr@rosenauer.org |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
457 |
|
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
458 |
- update to Firefox 32.0 (bnc#894370) |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
459 |
* MFSA 2014-67/CVE-2014-1553/CVE-2014-1554/CVE-2014-1562 |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
460 |
Miscellaneous memory safety hazards |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
461 |
* MFSA 2014-68/CVE-2014-1563 (bmo#1018524) |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
462 |
Use-after-free during DOM interactions with SVG |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
463 |
* MFSA 2014-69/CVE-2014-1564 (bmo#1045977) |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
464 |
Uninitialized memory use during GIF rendering |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
465 |
* MFSA 2014-70/CVE-2014-1565 (bmo#1047831) |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
466 |
Out-of-bounds read in Web Audio audio timeline |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
467 |
* MFSA 2014-72/CVE-2014-1567 (bmo#1037641) |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
468 |
Use-after-free setting text directionality |
748
72ba5129e5fd
full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
746
diff
changeset
|
469 |
- rebased patches |
756 | 470 |
- requires NSS 3.16.4 |
748
72ba5129e5fd
full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
746
diff
changeset
|
471 |
- removed upstreamed patch |
72ba5129e5fd
full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
746
diff
changeset
|
472 |
* mozilla-aarch64-bmo-810631.patch |
72ba5129e5fd
full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
746
diff
changeset
|
473 |
|
72ba5129e5fd
full rebase to Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
746
diff
changeset
|
474 |
------------------------------------------------------------------- |
759
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
475 |
Wed Aug 20 13:50:58 CEST 2014 - behlert@suse.de |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
476 |
|
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
477 |
- adapted _constraints, used more than 3900MB on s390x during |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
478 |
last build |
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
479 |
|
b2ae89c6dea9
Firefox 32.0 goes production
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
756
diff
changeset
|
480 |
------------------------------------------------------------------- |
753 | 481 |
Sun Jul 20 18:11:44 UTC 2014 - wr@rosenauer.org |
482 |
||
483 |
- update to Firefox 31.0 (bnc#887746) |
|
484 |
* MFSA 2014-56/CVE-2014-1547/CVE-2014-1548 |
|
485 |
Miscellaneous memory safety hazards |
|
486 |
* MFSA 2014-57/CVE-2014-1549 (bmo#1020205) |
|
487 |
Buffer overflow during Web Audio buffering for playback |
|
488 |
* MFSA 2014-58/CVE-2014-1550 (bmo#1020411) |
|
489 |
Use-after-free in Web Audio due to incorrect control message ordering |
|
490 |
* MFSA 2014-60/CVE-2014-1561 (bmo#1000514, bmo#910375) |
|
491 |
Toolbar dialog customization event spoofing |
|
492 |
* MFSA 2014-61/CVE-2014-1555 (bmo#1023121) |
|
493 |
Use-after-free with FireOnStateChange event |
|
494 |
* MFSA 2014-62/CVE-2014-1556 (bmo#1028891) |
|
495 |
Exploitable WebGL crash with Cesium JavaScript library |
|
496 |
* MFSA 2014-63/CVE-2014-1544 (bmo#963150) |
|
497 |
Use-after-free while when manipulating certificates in the trusted cache |
|
498 |
(solved with NSS 3.16.2 requirement) |
|
499 |
* MFSA 2014-64/CVE-2014-1557 (bmo#913805) |
|
500 |
Crash in Skia library when scaling high quality images |
|
501 |
* MFSA 2014-65/CVE-2014-1558/CVE-2014-1559/CVE-2014-1560 |
|
502 |
(bmo#1015973, bmo#1026022, bmo#997795) |
|
503 |
Certificate parsing broken by non-standard character encoding |
|
504 |
* MFSA 2014-66/CVE-2014-1552 (bmo#985135) |
|
505 |
IFRAME sandbox same-origin access through redirect |
|
506 |
- use EGL on ARM |
|
746
b441942b2a3f
update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
744
diff
changeset
|
507 |
- rebased patches |
b441942b2a3f
update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
744
diff
changeset
|
508 |
- requires NSS 3.16.2 |
753 | 509 |
- requires python-devel (not only python) |
746
b441942b2a3f
update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
744
diff
changeset
|
510 |
|
b441942b2a3f
update meta data for Aurora 32
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
744
diff
changeset
|
511 |
------------------------------------------------------------------- |
744
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
512 |
Mon Jun 9 08:28:17 UTC 2014 - wr@rosenauer.org |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
513 |
|
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
514 |
- update to Firefox 30.0 (bnc#881874) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
515 |
* MFSA 2014-48/CVE-2014-1533/CVE-2014-1534 |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
516 |
(bmo#921622, bmo#967354, bmo#969517, bmo#969549, bmo#973874, |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
517 |
bmo#978652, bmo#978811, bmo#988719, bmo#990868, bmo#991981, |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
518 |
bmo#992274, bmo#994907, bmo#995679, bmo#995816, bmo#995817, |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
519 |
bmo#996536, bmo#996715, bmo#999651, bmo#1000598, |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
520 |
bmo#1000960, bmo#1002340, bmo#1005578, bmo#1007223, |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
521 |
bmo#1009952, bmo#1011007) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
522 |
Miscellaneous memory safety hazards (rv:30.0) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
523 |
* MFSA 2014-49/CVE-2014-1536/CVE-2014-1537/CVE-2014-1538 |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
524 |
(bmo#989994, bmo#999274, bmo#1005584) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
525 |
Use-after-free and out of bounds issues found using Address |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
526 |
Sanitizer |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
527 |
* MFSA 2014-50/CVE-2014-1539 (bmo#995603) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
528 |
Clickjacking through cursor invisability after Flash interaction |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
529 |
* MFSA 2014-51/CVE-2014-1540 (bmo#978862) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
530 |
Use-after-free in Event Listener Manager |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
531 |
* MFSA 2014-52/CVE-2014-1541 (bmo#1000185) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
532 |
Use-after-free with SMIL Animation Controller |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
533 |
* MFSA 2014-53/CVE-2014-1542 (bmo#991533) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
534 |
Buffer overflow in Web Audio Speex resampler |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
535 |
* MFSA 2014-54/CVE-2014-1543 (bmo#1011859) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
536 |
Buffer overflow in Gamepad API |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
537 |
* MFSA 2014-55/CVE-2014-1545 (bmo#1018783) |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
538 |
Out of bounds write in NSPR |
733
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
539 |
- rebased patches |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
540 |
- removed obsolete patches |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
541 |
* firefox-browser-css.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
542 |
* mozilla-aarch64-bmo-962488.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
543 |
* mozilla-aarch64-bmo-963023.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
544 |
* mozilla-aarch64-bmo-963024.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
545 |
* mozilla-aarch64-bmo-963027.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
546 |
* mozilla-ppc64-xpcom.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
547 |
* mozilla-ppc64le-javascript.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
548 |
* mozilla-ppc64le-libffi.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
549 |
* mozilla-ppc64le-mfbt.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
550 |
* mozilla-ppc64le-webrtc.patch |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
551 |
* mozilla-ppc64le-xpcom.patch |
744
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
552 |
* mozilla-ppc64le-build.patch |
e2d94ddb82f0
manual merge from 30.0 release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
738
diff
changeset
|
553 |
- requires NSPR 4.10.6 |
725 | 554 |
- enabled GStreamer 1.0 usage for 13.2 and above |
555 |
||
556 |
------------------------------------------------------------------- |
|
738 | 557 |
Sat May 10 06:09:37 UTC 2014 - wr@rosenauer.org |
558 |
||
559 |
- update to Firefox 29.0.1 |
|
560 |
* Seer disabled by default (bmo#1005958) |
|
561 |
* Session Restore failed with a corrupted sessionstore.js file |
|
562 |
(bmo#1001167) |
|
563 |
* pdf.js printing white page (bmo#1003707, bnc#876833) |
|
733
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
564 |
- general.useragent.locale gets overwritten with en-US while it |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
565 |
should be using the active langpack's setting |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
566 |
|
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
567 |
------------------------------------------------------------------- |
727
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
568 |
Sat Apr 26 12:18:07 UTC 2014 - wr@rosenauer.org |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
569 |
|
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
570 |
- update to Firefox 29.0 (bnc#875378) |
733
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
571 |
* MFSA 2014-34/CVE-2014-1518/CVE-2014-1519 |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
572 |
Miscellaneous memory safety hazards |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
573 |
* MFSA 2014-36/CVE-2014-1522 (bmo#995289) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
574 |
Web Audio memory corruption issues |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
575 |
* MFSA 2014-37/CVE-2014-1523 (bmo#969226) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
576 |
Out of bounds read while decoding JPG images |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
577 |
* MFSA 2014-38/CVE-2014-1524 (bmo#989183) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
578 |
Buffer overflow when using non-XBL object as XBL |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
579 |
* MFSA 2014-39/CVE-2014-1525 (bmo#989210) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
580 |
Use-after-free in the Text Track Manager for HTML video |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
581 |
* MFSA 2014-41/CVE-2014-1528 (bmo#963962) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
582 |
Out-of-bounds write in Cairo |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
583 |
* MFSA 2014-42/CVE-2014-1529 (bmo#987003) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
584 |
Privilege escalation through Web Notification API |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
585 |
* MFSA 2014-43/CVE-2014-1530 (bmo#895557) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
586 |
Cross-site scripting (XSS) using history navigations |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
587 |
* MFSA 2014-44/CVE-2014-1531 (bmo#987140) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
588 |
Use-after-free in imgLoader while resizing images |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
589 |
* MFSA 2014-45/CVE-2014-1492 (bmo#903885) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
590 |
Incorrect IDNA domain name matching for wildcard certificates |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
591 |
(fixed by NSS 3.16) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
592 |
* MFSA 2014-46/CVE-2014-1532 (bmo#966006) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
593 |
Use-after-free in nsHostResolver |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
594 |
* MFSA 2014-47/CVE-2014-1526 (bmo#988106) |
b2202fea7983
manual forward merge from 29 and 30 branches
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
727
diff
changeset
|
595 |
Debugger can bypass XrayWrappers with JavaScript |
727
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
596 |
- rebased patches |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
597 |
- removed obsolete patches |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
598 |
* firefox-browser-css.patch |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
599 |
* mozilla-aarch64-599882cfb998.diff |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
600 |
* mozilla-aarch64-bmo-963028.patch |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
601 |
* mozilla-aarch64-bmo-963029.patch |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
602 |
* mozilla-aarch64-bmo-963030.patch |
727fef76f8d7
manual merge from firefox29
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
725
diff
changeset
|
603 |
* mozilla-aarch64-bmo-963031.patch |
716
cef565f1c325
update to Firefox 29.0b7
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
715
diff
changeset
|
604 |
- requires NSS 3.16 |
cef565f1c325
update to Firefox 29.0b7
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
715
diff
changeset
|
605 |
- added mozilla-icu-strncat.patch to fix post build checks |
cef565f1c325
update to Firefox 29.0b7
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
715
diff
changeset
|
606 |
|
cef565f1c325
update to Firefox 29.0b7
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
715
diff
changeset
|
607 |
------------------------------------------------------------------- |
715 | 608 |
Mon Apr 7 15:34:31 UTC 2014 - dmueller@suse.com |
609 |
||
610 |
- add mozilla-aarch64-599882cfb998.patch, |
|
611 |
mozilla-aarch64-bmo-810631.patch, |
|
612 |
mozilla-aarch64-bmo-962488.patch, |
|
613 |
mozilla-aarch64-bmo-963030.patch, |
|
614 |
mozilla-aarch64-bmo-963027.patch, |
|
615 |
mozilla-aarch64-bmo-963028.patch, |
|
616 |
mozilla-aarch64-bmo-963029.patch, |
|
617 |
mozilla-aarch64-bmo-963023.patch, |
|
618 |
mozilla-aarch64-bmo-963024.patch, |
|
619 |
mozilla-aarch64-bmo-963031.patch: AArch64 porting |
|
620 |
||
621 |
------------------------------------------------------------------- |
|
714
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
622 |
Mon Mar 24 16:18:44 UTC 2014 - dvaleev@suse.com |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
623 |
|
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
624 |
- Add patch for bmo#973977 |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
625 |
* mozilla-ppc64-xpcom.patch |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
626 |
|
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
627 |
------------------------------------------------------------------- |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
628 |
Mon Mar 24 14:29:12 UTC 2014 - dvaleev@suse.com |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
629 |
|
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
630 |
- Refresh mozilla-ppc64le-xpcom.patch patch |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
631 |
|
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
632 |
------------------------------------------------------------------- |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
633 |
Fri Mar 21 19:01:42 UTC 2014 - dvaleev@suse.com |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
634 |
|
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
635 |
- Adapt mozilla-ppc64le-xpcom.patch to Mozilla > 24.0 build system |
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
636 |
|
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
637 |
------------------------------------------------------------------- |
711
012a5adf5c74
moved to mozilla-release (28.0build2)
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
710
diff
changeset
|
638 |
Sun Mar 16 13:39:15 UTC 2014 - wr@rosenauer.org |
012a5adf5c74
moved to mozilla-release (28.0build2)
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
710
diff
changeset
|
639 |
|
712 | 640 |
- update to Firefox 28.0 (bnc#868603) |
641 |
* MFSA 2014-15/CVE-2014-1493/CVE-2014-1494 |
|
642 |
Miscellaneous memory safety hazards |
|
643 |
* MFSA 2014-17/CVE-2014-1497 (bmo#966311) |
|
644 |
Out of bounds read during WAV file decoding |
|
645 |
* MFSA 2014-18/CVE-2014-1498 (bmo#935618) |
|
646 |
crypto.generateCRMFRequest does not validate type of key |
|
647 |
* MFSA 2014-19/CVE-2014-1499 (bmo#961512) |
|
648 |
Spoofing attack on WebRTC permission prompt |
|
649 |
* MFSA 2014-20/CVE-2014-1500 (bmo#956524) |
|
650 |
onbeforeunload and Javascript navigation DOS |
|
651 |
* MFSA 2014-22/CVE-2014-1502 (bmo#972622) |
|
652 |
WebGL content injection from one domain to rendering in another |
|
653 |
* MFSA 2014-23/CVE-2014-1504 (bmo#911547) |
|
654 |
Content Security Policy for data: documents not preserved by |
|
655 |
session restore |
|
656 |
* MFSA 2014-26/CVE-2014-1508 (bmo#963198) |
|
657 |
Information disclosure through polygon rendering in MathML |
|
658 |
* MFSA 2014-27/CVE-2014-1509 (bmo#966021) |
|
659 |
Memory corruption in Cairo during PDF font rendering |
|
660 |
* MFSA 2014-28/CVE-2014-1505 (bmo#941887) |
|
661 |
SVG filters information disclosure through feDisplacementMap |
|
662 |
* MFSA 2014-29/CVE-2014-1510/CVE-2014-1511 (bmo#982906, bmo#982909) |
|
663 |
Privilege escalation using WebIDL-implemented APIs |
|
664 |
* MFSA 2014-30/CVE-2014-1512 (bmo#982957) |
|
665 |
Use-after-free in TypeObject |
|
666 |
* MFSA 2014-31/CVE-2014-1513 (bmo#982974) |
|
667 |
Out-of-bounds read/write through neutering ArrayBuffer objects |
|
668 |
* MFSA 2014-32/CVE-2014-1514 (bmo#983344) |
|
669 |
Out-of-bounds write through TypedArrayObject after neutering |
|
707 | 670 |
- requires NSPR 4.10.3 and NSS 3.15.5 |
712 | 671 |
- new build dependency (and recommends): |
703 | 672 |
* libpulse |
710
5341dc98d26c
update of PPC64LE patches taken from
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
707
diff
changeset
|
673 |
- update of PowerPC 64 patches (bmo#976648) (pcerny@suse.com) |
711
012a5adf5c74
moved to mozilla-release (28.0build2)
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
710
diff
changeset
|
674 |
- rebased patches |
703 | 675 |
|
676 |
------------------------------------------------------------------- |
|
704 | 677 |
Mon Feb 17 11:59:28 UTC 2014 - wr@rosenauer.org |
678 |
||
679 |
- update to Firefox 27.0.1 |
|
680 |
* Fixed stability issues with Greasemonkey and other JS that used |
|
681 |
ClearTimeoutOrInterval |
|
714
b686e856c800
import PPC64(LE) changes from OBS
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
712
diff
changeset
|
682 |
* JS math correctness issue (bmo#941381) |
704 | 683 |
- incorporate Google API key for geolocation (bnc#864170) |
684 |
- updated list of "other" locales in RPM requirements |
|
685 |
||
686 |
------------------------------------------------------------------- |
|
699 | 687 |
Tue Jan 28 15:45:41 UTC 2014 - wr@rosenauer.org |
688 |
||
700 | 689 |
- update to Firefox 27.0 (bnc#861847) |
690 |
* MFSA 2014-01/CVE-2014-1477/CVE-2014-1478 |
|
691 |
Miscellaneous memory safety hazards (rv:27.0 / rv:24.3) |
|
692 |
* MFSA 2014-02/CVE-2014-1479 (bmo#911864) |
|
693 |
Clone protected content with XBL scopes |
|
694 |
* MFSA 2014-03/CVE-2014-1480 (bmo#916726) |
|
695 |
UI selection timeout missing on download prompts |
|
696 |
* MFSA 2014-04/CVE-2014-1482 (bmo#943803) |
|
697 |
Incorrect use of discarded images by RasterImage |
|
698 |
* MFSA 2014-05/CVE-2014-1483 (bmo#950427) |
|
699 |
Information disclosure with *FromPoint on iframes |
|
700 |
* MFSA 2014-06/CVE-2014-1484 (bmo#953993) |
|
701 |
Profile path leaks to Android system log |
|
702 |
* MFSA 2014-07/CVE-2014-1485 (bmo#910139) |
|
703 |
XSLT stylesheets treated as styles in Content Security Policy |
|
704 |
* MFSA 2014-08/CVE-2014-1486 (bmo#942164) |
|
705 |
Use-after-free with imgRequestProxy and image proccessing |
|
706 |
* MFSA 2014-09/CVE-2014-1487 (bmo#947592) |
|
707 |
Cross-origin information leak through web workers |
|
708 |
* MFSA 2014-10/CVE-2014-1489 (bmo#959531) |
|
709 |
Firefox default start page UI content invokable by script |
|
710 |
* MFSA 2014-11/CVE-2014-1488 (bmo#950604) |
|
711 |
Crash when using web workers with asm.js |
|
712 |
* MFSA 2014-12/CVE-2014-1490/CVE-2014-1491 |
|
713 |
(bmo#934545, bmo#930874, bmo#930857) |
|
714 |
NSS ticket handling issues |
|
715 |
* MFSA 2014-13/CVE-2014-1481(bmo#936056) |
|
716 |
Inconsistent JavaScript handling of access to Window objects |
|
691
18c2dc922e51
update to Firefox 27.0b2
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
689
diff
changeset
|
717 |
- requires NSS 3.15.4 or higher |
18c2dc922e51
update to Firefox 27.0b2
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
689
diff
changeset
|
718 |
- rebased/reworked patches |
697 | 719 |
- removed obsolete mozilla-bug929439.patch |
691
18c2dc922e51
update to Firefox 27.0b2
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
689
diff
changeset
|
720 |
|
18c2dc922e51
update to Firefox 27.0b2
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
689
diff
changeset
|
721 |
------------------------------------------------------------------- |
692 | 722 |
Thu Dec 12 21:19:54 UTC 2013 - uweigand@de.ibm.com |
723 |
||
724 |
- Add support for powerpc64le-linux. |
|
725 |
* mozilla-ppc64le.patch: general support |
|
726 |
* mozilla-libffi-ppc64le.patch: libffi backport |
|
727 |
* mozilla-xpcom-ppc64le.patch: port xpcom |
|
697 | 728 |
- Add build fix from mainline. |
729 |
* mozilla-bug929439.patch |
|
692 | 730 |
|
731 |
------------------------------------------------------------------- |
|
688 | 732 |
Sun Dec 8 20:26:23 UTC 2013 - wr@rosenauer.org |
733 |
||
689 | 734 |
- update to Firefox 26.0 (bnc#854367, bnc#854370) |
686
ab25aac2aa83
Firefox 26.0b5 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
682
diff
changeset
|
735 |
* rebased patches |
688 | 736 |
* requires NSPR 4.10.2 and NSS 3.15.3.1 |
689 | 737 |
* MFSA 2013-104/CVE-2013-5609/CVE-2013-5610 |
738 |
Miscellaneous memory safety hazards |
|
739 |
* MFSA 2013-105/CVE-2013-5611 (bmo#771294) |
|
740 |
Application Installation doorhanger persists on navigation |
|
741 |
* MFSA 2013-106/CVE-2013-5612 (bmo#871161) |
|
742 |
Character encoding cross-origin XSS attack |
|
743 |
* MFSA 2013-107/CVE-2013-5614 (bmo#886262) |
|
744 |
Sandbox restrictions not applied to nested object elements |
|
745 |
* MFSA 2013-108/CVE-2013-5616 (bmo#938341) |
|
746 |
Use-after-free in event listeners |
|
747 |
* MFSA 2013-109/CVE-2013-5618 (bmo#926361) |
|
748 |
Use-after-free during Table Editing |
|
749 |
* MFSA 2013-110/CVE-2013-5619 (bmo#917841) |
|
750 |
Potential overflow in JavaScript binary search algorithms |
|
751 |
* MFSA 2013-111/CVE-2013-6671 (bmo#930281) |
|
752 |
Segmentation violation when replacing ordered list elements |
|
753 |
* MFSA 2013-112/CVE-2013-6672 (bmo#894736) |
|
754 |
Linux clipboard information disclosure though selection paste |
|
755 |
* MFSA 2013-113/CVE-2013-6673 (bmo#970380) |
|
756 |
Trust settings for built-in roots ignored during EV certificate |
|
757 |
validation |
|
758 |
* MFSA 2013-114/CVE-2013-5613 (bmo#930381, bmo#932449) |
|
759 |
Use-after-free in synthetic mouse movement |
|
760 |
* MFSA 2013-115/CVE-2013-5615 (bmo#929261) |
|
761 |
GetElementIC typed array stubs can be generated outside observed |
|
762 |
typesets |
|
763 |
* MFSA 2013-116/CVE-2013-6629/CVE-2013-6630 (bmo#891693) |
|
764 |
JPEG information leak |
|
765 |
* MFSA 2013-117 (bmo#946351) |
|
766 |
Mis-issued ANSSI/DCSSI certificate |
|
767 |
(fixed via NSS 3.15.3.1) |
|
686
ab25aac2aa83
Firefox 26.0b5 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
682
diff
changeset
|
768 |
- removed gecko.js preference file as GStreamer is enabled by |
ab25aac2aa83
Firefox 26.0b5 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
682
diff
changeset
|
769 |
default now |
ab25aac2aa83
Firefox 26.0b5 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
682
diff
changeset
|
770 |
|
ab25aac2aa83
Firefox 26.0b5 update
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
682
diff
changeset
|
771 |
------------------------------------------------------------------- |
681 | 772 |
Thu Oct 24 18:16:19 UTC 2013 - wr@rosenauer.org |
773 |
||
682 | 774 |
- update to Firefox 25.0 (bnc#847708) |
680 | 775 |
* rebased patches |
681 | 776 |
* requires NSS 3.15.2 or above |
682 | 777 |
* MFSA 2013-93/CVE-2013-5590/CVE-2013-5591/CVE-2013-5592 |
778 |
Miscellaneous memory safety hazards |
|
779 |
* MFSA 2013-94/CVE-2013-5593 (bmo#868327) |
|
780 |
Spoofing addressbar through SELECT element |
|
781 |
* MFSA 2013-95/CVE-2013-5604 (bmo#914017) |
|
782 |
Access violation with XSLT and uninitialized data |
|
783 |
* MFSA 2013-96/CVE-2013-5595 (bmo#916580) |
|
784 |
Improperly initialized memory and overflows in some JavaScript |
|
785 |
functions |
|
786 |
* MFSA 2013-97/CVE-2013-5596 (bmo#910881) |
|
787 |
Writing to cycle collected object during image decoding |
|
788 |
* MFSA 2013-98/CVE-2013-5597 (bmo#918864) |
|
789 |
Use-after-free when updating offline cache |
|
790 |
* MFSA 2013-99/CVE-2013-5598 (bmo#920515) |
|
791 |
Security bypass of PDF.js checks using iframes |
|
792 |
* MFSA 2013-100/CVE-2013-5599/CVE-2013-5600/CVE-2013-5601 |
|
793 |
(bmo#915210, bmo#915576, bmo#916685) |
|
794 |
Miscellaneous use-after-free issues found through ASAN fuzzing |
|
795 |
* MFSA 2013-101/CVE-2013-5602 (bmo#897678) |
|
796 |
Memory corruption in workers |
|
797 |
* MFSA 2013-102/CVE-2013-5603 (bmo#916404) |
|
798 |
Use-after-free in HTML document templates |
|
676 | 799 |
|
800 |
------------------------------------------------------------------- |
|
672 | 801 |
Tue Sep 24 07:31:30 UTC 2013 - wr@rosenauer.org |
802 |
||
803 |
- as GStreamer is not automatically required anymore but loaded |
|
804 |
dynamically if available, require it explicitely |
|
805 |
- recommend optional GStreamer plugins for comprehensive media |
|
806 |
support |
|
807 |
||
808 |
------------------------------------------------------------------- |
|
666
0d913ca30238
move greek to the translations-common package (bnc#840551)
Ludwig Nussel <lnussel@suse.de>
parents:
664
diff
changeset
|
809 |
Mon Sep 16 11:59:18 UTC 2013 - lnussel@suse.de |
0d913ca30238
move greek to the translations-common package (bnc#840551)
Ludwig Nussel <lnussel@suse.de>
parents:
664
diff
changeset
|
810 |
|
0d913ca30238
move greek to the translations-common package (bnc#840551)
Ludwig Nussel <lnussel@suse.de>
parents:
664
diff
changeset
|
811 |
- move greek to the translations-common package (bnc#840551) |
0d913ca30238
move greek to the translations-common package (bnc#840551)
Ludwig Nussel <lnussel@suse.de>
parents:
664
diff
changeset
|
812 |
|
0d913ca30238
move greek to the translations-common package (bnc#840551)
Ludwig Nussel <lnussel@suse.de>
parents:
664
diff
changeset
|
813 |
------------------------------------------------------------------- |
664 | 814 |
Sat Sep 14 14:39:58 UTC 2013 - wr@rosenauer.org |
815 |
||
666
0d913ca30238
move greek to the translations-common package (bnc#840551)
Ludwig Nussel <lnussel@suse.de>
parents:
664
diff
changeset
|
816 |
- update to Firefox 24.0 (bnc#840485) |
667 | 817 |
* MFSA 2013-76/CVE-2013-1718/CVE-2013-1719 |
818 |
Miscellaneous memory safety hazards |
|
819 |
* MFSA 2013-77/CVE-2013-1720 (bmo#888820) |
|
820 |
Improper state in HTML5 Tree Builder with templates |
|
821 |
* MFSA 2013-78/CVE-2013-1721 (bmo#890277) |
|
822 |
Integer overflow in ANGLE library |
|
823 |
* MFSA 2013-79/CVE-2013-1722 (bmo#893308) |
|
824 |
Use-after-free in Animation Manager during stylesheet cloning |
|
825 |
* MFSA 2013-80/CVE-2013-1723 (bmo#891292) |
|
826 |
NativeKey continues handling key messages after widget is destroyed |
|
827 |
* MFSA 2013-81/CVE-2013-1724 (bmo#894137) |
|
828 |
Use-after-free with select element |
|
829 |
* MFSA 2013-82/CVE-2013-1725 (bmo#876762) |
|
830 |
Calling scope for new Javascript objects can lead to memory corruption |
|
831 |
* MFSA 2013-85/CVE-2013-1728 (bmo#883686) |
|
832 |
Uninitialized data in IonMonkey |
|
833 |
* MFSA 2013-88/CVE-2013-1730 (bmo#851353) |
|
834 |
Compartment mismatch re-attaching XBL-backed nodes |
|
835 |
* MFSA 2013-89/CVE-2013-1732 (bmo#883514) |
|
836 |
Buffer overflow with multi-column, lists, and floats |
|
837 |
* MFSA 2013-90/CVE-2013-1735/CVE-2013-1736 (bmo#898871, bmo#906301) |
|
838 |
Memory corruption involving scrolling |
|
839 |
* MFSA 2013-91/CVE-2013-1737 (bmo#907727) |
|
840 |
User-defined properties on DOM proxies get the wrong "this" object |
|
841 |
* MFSA 2013-92/CVE-2013-1738 (bmo#887334, bmo#882897) |
|
842 |
GC hazard with default compartments and frame chain restoration |
|
843 |
- enable gstreamer explicitely via pref (gecko.js) |
|
663 | 844 |
- require NSS 3.15.1 |
661 | 845 |
|
846 |
------------------------------------------------------------------- |
|
664 | 847 |
Mon Aug 26 07:35:36 UTC 2013 - wr@rosenauer.org |
848 |
||
849 |
- update to Firefox 23.0.1 |
|
850 |
* Audio static/"burble"/breakup in Firefox to Firefox WebRTC calls |
|
851 |
(bmo#901527) |
|
852 |
||
853 |
------------------------------------------------------------------- |
|
661 | 854 |
Sun Aug 4 18:30:11 UTC 2013 - wr@rosenauer.org |
855 |
||
856 |
- update to Firefox 23.0 (bnc#833389) |
|
857 |
* MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 |
|
858 |
Miscellaneous memory safety hazards |
|
859 |
* MFSA 2013-64/CVE-2013-1704 (bmo#883313) |
|
860 |
Use after free mutating DOM during SetBody |
|
861 |
* MFSA 2013-65/CVE-2013-1705 (bmo#882865) |
|
862 |
Buffer underflow when generating CRMF requests |
|
863 |
* MFSA 2013-67/CVE-2013-1708 (bmo#879924) |
|
864 |
Crash during WAV audio file decoding |
|
865 |
* MFSA 2013-68/CVE-2013-1709 (bmo#838253) |
|
866 |
Document URI misrepresentation and masquerading |
|
867 |
* MFSA 2013-69/CVE-2013-1710 (bmo#871368) |
|
868 |
CRMF requests allow for code execution and XSS attacks |
|
869 |
* MFSA 2013-70/CVE-2013-1711 (bmo#843829) |
|
870 |
Bypass of XrayWrappers using XBL Scopes |
|
871 |
* MFSA 2013-72/CVE-2013-1713 (bmo#887098) |
|
872 |
Wrong principal used for validating URI for some Javascript |
|
873 |
components |
|
874 |
* MFSA 2013-73/CVE-2013-1714 (bmo#879787) |
|
875 |
Same-origin bypass with web workers and XMLHttpRequest |
|
876 |
* MFSA 2013-75/CVE-2013-1717 (bmo#406541, bmo#738397) |
|
877 |
Local Java applets may read contents of local file system |
|
653 | 878 |
- requires NSPR 4.10 and NSS 3.15 |
659 | 879 |
|
880 |
------------------------------------------------------------------- |
|
881 |
Wed Jul 3 17:14:35 UTC 2013 - dmueller@suse.com |
|
882 |
||
883 |
- fix build on ARM (/-g/ matches /-grecord-switches/) |
|
884 |
||
885 |
------------------------------------------------------------------- |
|
886 |
Sat Jun 22 17:48:06 UTC 2013 - wr@rosenauer.org |
|
887 |
||
888 |
- update to Firefox 22.0 (bnc#825935) |
|
650 | 889 |
* removed obsolete patches |
890 |
+ mozilla-qcms-ppc.patch |
|
891 |
+ mozilla-gstreamer-760140.patch |
|
659 | 892 |
* GStreamer support does not build on 12.1 anymore (build only |
893 |
on 12.2 and later) |
|
894 |
* MFSA 2013-49/CVE-2013-1682/CVE-2013-1683 |
|
895 |
Miscellaneous memory safety hazards |
|
896 |
* MFSA 2013-50/CVE-2013-1684/CVE-2013-1685/CVE-2013-1686 |
|
897 |
Memory corruption found using Address Sanitizer |
|
898 |
* MFSA 2013-51/CVE-2013-1687 (bmo#863933, bmo#866823) |
|
899 |
Privileged content access and execution via XBL |
|
900 |
* MFSA 2013-52/CVE-2013-1688 (bmo#873966) |
|
901 |
Arbitrary code execution within Profiler |
|
902 |
* MFSA 2013-53/CVE-2013-1690 (bmo#857883) |
|
903 |
Execution of unmapped memory through onreadystatechange event |
|
904 |
* MFSA 2013-54/CVE-2013-1692 (bmo#866915) |
|
905 |
Data in the body of XHR HEAD requests leads to CSRF attacks |
|
906 |
* MFSA 2013-55/CVE-2013-1693 (bmo#711043) |
|
907 |
SVG filters can lead to information disclosure |
|
908 |
* MFSA 2013-56/CVE-2013-1694 (bmo#848535) |
|
909 |
PreserveWrapper has inconsistent behavior |
|
910 |
* MFSA 2013-57/CVE-2013-1695 (bmo#849791) |
|
911 |
Sandbox restrictions not applied to nested frame elements |
|
912 |
* MFSA 2013-58/CVE-2013-1696 (bmo#761667) |
|
913 |
X-Frame-Options ignored when using server push with multi-part |
|
914 |
responses |
|
915 |
* MFSA 2013-59/CVE-2013-1697 (bmo#858101) |
|
916 |
XrayWrappers can be bypassed to run user defined methods in a |
|
917 |
privileged context |
|
918 |
* MFSA 2013-60/CVE-2013-1698 (bmo#876044) |
|
919 |
getUserMedia permission dialog incorrectly displays location |
|
920 |
* MFSA 2013-61/CVE-2013-1699 (bmo#840882) |
|
921 |
Homograph domain spoofing in .com, .net and .name |
|
650 | 922 |
|
923 |
------------------------------------------------------------------- |
|
924 |
Tue Jun 11 21:06:58 UTC 2013 - dvaleev@suse.com |
|
925 |
||
926 |
- Fix qcms altivec include (mozilla-qcms-ppc.patch) |
|
927 |
||
928 |
------------------------------------------------------------------- |
|
647 | 929 |
Fri May 10 05:25:39 UTC 2013 - wr@rosenauer.org |
930 |
||
931 |
- update to Firefox 21.0 (bnc#819204) |
|
932 |
* removed upstreamed patch firefox-712763.patch |
|
933 |
* removed disabled mozilla-disable-neon-option.patch |
|
934 |
* MFSA 2013-41/CVE-2013-0801/CVE-2013-1669 |
|
935 |
Miscellaneous memory safety hazards |
|
936 |
* MFSA 2013-42/CVE-2013-1670 (bmo#853709) |
|
937 |
Privileged access for content level constructor |
|
938 |
* MFSA 2013-43/CVE-2013-1671 (bmo#842255) |
|
939 |
File input control has access to full path |
|
940 |
* MFSA 2013-46/CVE-2013-1674 (bmo#860971) |
|
941 |
Use-after-free with video and onresize event |
|
942 |
* MFSA 2013-47/CVE-2013-1675 (bmo#866825) |
|
943 |
Uninitialized functions in DOMSVGZoomEvent |
|
944 |
* MFSA 2013-48/CVE-2013-1676/CVE-2013-1677/CVE-2013-1678/ |
|
945 |
CVE-2013-1679/CVE-2013-1680/CVE-2013-1681 |
|
946 |
Memory corruption found using Address Sanitizer |
|
645 | 947 |
|
948 |
------------------------------------------------------------------- |
|
949 |
Tue Apr 9 06:41:31 UTC 2013 - wr@rosenauer.org |
|
950 |
||
951 |
- revert to use GStreamer 0.10 on 12.3 (bnc#814101) |
|
952 |
(remove mozilla-gstreamer-1.patch) |
|
953 |
||
954 |
------------------------------------------------------------------- |
|
640
68ead6c93b7d
Explicitly disable WebRTC support on non-x86, the configure script
schwab@linux-m68k.org
parents:
639
diff
changeset
|
955 |
Fri Apr 5 17:04:11 UTC 2013 - schwab@linux-m68k.org |
68ead6c93b7d
Explicitly disable WebRTC support on non-x86, the configure script
schwab@linux-m68k.org
parents:
639
diff
changeset
|
956 |
|
68ead6c93b7d
Explicitly disable WebRTC support on non-x86, the configure script
schwab@linux-m68k.org
parents:
639
diff
changeset
|
957 |
- Explicitly disable WebRTC support on non-x86, the configure script |
68ead6c93b7d
Explicitly disable WebRTC support on non-x86, the configure script
schwab@linux-m68k.org
parents:
639
diff
changeset
|
958 |
disables it only half-heartedly |
68ead6c93b7d
Explicitly disable WebRTC support on non-x86, the configure script
schwab@linux-m68k.org
parents:
639
diff
changeset
|
959 |
|
68ead6c93b7d
Explicitly disable WebRTC support on non-x86, the configure script
schwab@linux-m68k.org
parents:
639
diff
changeset
|
960 |
------------------------------------------------------------------- |
639 | 961 |
Fri Mar 29 22:15:21 UTC 2013 - wr@rosenauer.org |
962 |
||
963 |
- update to Firefox 20.0 (bnc#813026) |
|
964 |
* requires NSPR 4.9.5 and NSS 3.14.3 |
|
640
68ead6c93b7d
Explicitly disable WebRTC support on non-x86, the configure script
schwab@linux-m68k.org
parents:
639
diff
changeset
|
965 |
* mozilla-webrtc-ppc.patch included upstream |
639 | 966 |
* MFSA 2013-30/CVE-2013-0788/CVE-2013-0789 |
967 |
Miscellaneous memory safety hazards |
|
968 |
* MFSA 2013-31/CVE-2013-0800 (bmo#825721) |
|
969 |
Out-of-bounds write in Cairo library |
|
970 |
* MFSA 2013-35/CVE-2013-0796 (bmo#827106) |
|
971 |
WebGL crash with Mesa graphics driver on Linux |
|
972 |
* MFSA 2013-36/CVE-2013-0795 (bmo#825697) |
|
973 |
Bypass of SOW protections allows cloning of protected nodes |
|
974 |
* MFSA 2013-37/CVE-2013-0794 (bmo#626775) |
|
975 |
Bypass of tab-modal dialog origin disclosure |
|
976 |
* MFSA 2013-38/CVE-2013-0793 (bmo#803870) |
|
977 |
Cross-site scripting (XSS) using timed history navigations |
|
978 |
* MFSA 2013-39/CVE-2013-0792 (bmo#722831) |
|
979 |
Memory corruption while rendering grayscale PNG images |
|
625
9f6e14430916
Bug 806917 - support GStreamer 1.0
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
624
diff
changeset
|
980 |
- use GStreamer 1.0 starting with 12.3 (mozilla-gstreamer-1.patch) |
633 | 981 |
|
982 |
------------------------------------------------------------------- |
|
631 | 983 |
Tue Mar 12 23:08:15 UTC 2013 - dmueller@suse.com |
984 |
||
985 |
- build fixes for armv7hl: |
|
986 |
* disable debug build as armv7hl does not have enough memory |
|
987 |
* disable webrtc on armv7hl as it is non-compiling |
|
988 |
||
989 |
------------------------------------------------------------------- |
|
990 |
Thu Mar 7 19:03:32 UTC 2013 - wr@rosenauer.org |
|
991 |
||
992 |
- update to Firefox 19.0.2 (bnc#808243) |
|
993 |
* MFSA 2013-29/CVE-2013-0787 (bmo#848644) |
|
994 |
Use-after-free in HTML Editor |
|
995 |
||
996 |
------------------------------------------------------------------- |
|
623 | 997 |
Thu Feb 28 22:06:36 UTC 2013 - wr@rosenauer.org |
998 |
||
999 |
- update to Firefox 19.0.1 |
|
1000 |
* blocklist updates |
|
1001 |
||
1002 |
------------------------------------------------------------------- |
|
615
fb49ee6e3828
Firefox 19.0 goes release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
613
diff
changeset
|
1003 |
Sat Feb 16 07:08:55 UTC 2013 - wr@rosenauer.org |
fb49ee6e3828
Firefox 19.0 goes release
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
613
diff
changeset
|
1004 |
|
619 | 1005 |
- update to Firefox 19.0 (bnc#804248) |
1006 |
* MFSA 2013-21/CVE-2013-0783/2013-0784 |
|
1007 |
Miscellaneous memory safety hazards |
|
1008 |
* MFSA 2013-22/CVE-2013-0772 (bmo#801366) |
|
1009 |
Out-of-bounds read in image rendering |
|
1010 |
* MFSA 2013-23/CVE-2013-0765 (bmo#830614) |
|
1011 |
Wrapped WebIDL objects can be wrapped again |
|
1012 |
* MFSA 2013-24/CVE-2013-0773 (bmo#809652) |
|
1013 |
Web content bypass of COW and SOW security wrappers |
|
1014 |
* MFSA 2013-25/CVE-2013-0774 (bmo#827193) |
|
1015 |
Privacy leak in JavaScript Workers |
|
1016 |
* MFSA 2013-26/CVE-2013-0775 (bmo#831095) |
|
1017 |
Use-after-free in nsImageLoadingContent |
|
1018 |
* MFSA 2013-27/CVE-2013-0776 (bmo#796475) |
|
1019 |
Phishing on HTTPS connection through malicious proxy |
|
1020 |
* MFSA 2013-28/CVE-2013-0780/CVE-2013-0782/CVE-2013-0777/ |
|
1021 |
CVE-2013-0778/CVE-2013-0779/CVE-2013-0781 |
|
1022 |
Use-after-free, out of bounds read, and buffer overflow issues |
|
1023 |
found using Address Sanitizer |
|
1024 |
- removed obsolete patches |
|
1025 |
* mozilla-webrtc.patch |
|
1026 |
* mozilla-gstreamer-803287.patch |
|
616
f46af22f1079
Bug 712763 - Backout changes from bug 669272 to keep original window order when restoring a session
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
615
diff
changeset
|
1027 |
- added patch to fix session restore window order (bmo#712763) |
613 | 1028 |
|
1029 |
------------------------------------------------------------------- |
|
611 | 1030 |
Sat Feb 2 08:40:52 UTC 2013 - wr@rosenauer.org |
1031 |
||
1032 |
- update to Firefox 18.0.2 |
|
1033 |
* blocklist and CTP updates |
|
1034 |
* fixes in JS engine |
|
1035 |
||
1036 |
------------------------------------------------------------------- |
|
604 | 1037 |
Wed Jan 16 20:51:55 UTC 2013 - wr@rosenauer.org |
1038 |
||
1039 |
- update to Firefox 18.0.1 |
|
1040 |
* blocklist updates |
|
1041 |
* backed out bmo#677092 (removed patch) |
|
609 | 1042 |
* fixed problems involving HTTP proxy transactions |
604 | 1043 |
|
1044 |
------------------------------------------------------------------- |
|
603
cfcae96df099
imported patch to fix PPC build
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
601
diff
changeset
|
1045 |
Sat Jan 12 17:25:11 UTC 2013 - schwab@linux-m68k.org |
cfcae96df099
imported patch to fix PPC build
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
601
diff
changeset
|
1046 |
|
cfcae96df099
imported patch to fix PPC build
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
601
diff
changeset
|
1047 |
- Fix WebRTC to build on powerpc |
cfcae96df099
imported patch to fix PPC build
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
601
diff
changeset
|
1048 |
|
cfcae96df099
imported patch to fix PPC build
Wolfgang Rosenauer <wr@rosenauer.org>
parents:
601
diff
changeset
|
1049 |
------------------------------------------------------------------- |
600 | 1050 |
Sun Jan 6 21:54:18 UTC 2013 - wr@rosenauer.org |
1051 |
||
1052 |
- update to Firefox 18.0 (bnc#796895) |
|
601 | 1053 |
* MFSA 2013-01/CVE-2013-0749/CVE-2013-0769/CVE-2013-0770 |
1054 |
Miscellaneous memory safety hazards |
|
1055 |
* MFSA 2013-02/CVE-2013-0760/CVE-2013-0762/CVE-2013-0766/CVE-2013-0767 |
|
1056 |
CVE-2013-0761/CVE-2013-0763/CVE-2013-0771/CVE-2012-5829 |
|
1057 |
Use-after-free and buffer overflow issues found using Address Sanitizer |
|
1058 |
* MFSA 2013-03/CVE-2013-0768 (bmo#815795) |
|
1059 |
Buffer Overflow in Canvas |
|
1060 |
* MFSA 2013-04/CVE-2012-0759 (bmo#802026) |
|
1061 |
URL spoofing in addressbar during page loads |
|
1062 |
* MFSA 2013-05/CVE-2013-0744 (bmo#814713) |
|
1063 |
Use-after-free when displaying table with many columns and column groups |
|
1064 |
* MFSA 2013-06/CVE-2013-0751 (bmo#790454) |
|
1065 |
Touch events are shared across iframes |
|
1066 |
* MFSA 2013-07/CVE-2013-0764 (bmo#804237) |
|
1067 |
Crash due to handling of SSL on threads |
|
1068 |
* MFSA 2013-08/CVE-2013-0745 (bmo#794158) |
|
1069 |
AutoWrapperChanger fails to keep objects alive during garbage collection |
|
1070 |
* MFSA 2013-09/CVE-2013-0746 (bmo#816842) |
|
1071 |
Compartment mismatch with quickstubs returned values |
|
1072 |
* MFSA 2013-10/CVE-2013-0747 (bmo#733305) |
|
1073 |
Event manipulation in plugin handler to bypass same-origin policy |
|
1074 |
* MFSA 2013-11/CVE-2013-0748 (bmo#806031) |
|
1075 |
Address space layout leaked in XBL objects |
|
1076 |
* MFSA 2013-12/CVE-2013-0750 (bmo#805121) |
|
1077 |
Buffer overflow in Javascript string concatenation |
|
1078 |
* MFSA 2013-13/CVE-2013-0752 (bmo#805024) |
|
1079 |
Memory corruption in XBL with XML bindings containing SVG |
|
1080 |
* MFSA 2013-14/CVE-2013-0757 (bmo#813901) |
|
1081 |
Chrome Object Wrapper (COW) bypass through changing prototype |
|
1082 |
* MFSA 2013-15/CVE-2013-0758 (bmo#813906) |
|
1083 |
Privilege escalation through plugin objects |
|
1084 |
* MFSA 2013-16/CVE-2013-0753 (bmo#814001) |
|
1085 |
Use-after-free in serializeToStream |
|
1086 |
* MFSA 2013-17/CVE-2013-0754 (bmo#814026) |
|
1087 |
Use-after-free in ListenerManager |
|
1088 |
* MFSA 2013-18/CVE-2013-0755 (bmo#814027) |
|
1089 |
Use-after-free in Vibrate |
|
1090 |
* MFSA 2013-19/CVE-2013-0756 (bmo#814029) |
|