MozillaFirefox/MozillaFirefox.changes
branchfirefox56
changeset 996 84d25951c2db
parent 994 9fc447b00040
child 997 ca8a6ac7fbf6
equal deleted inserted replaced
995:37c56dbf929f 996:84d25951c2db
     1 -------------------------------------------------------------------
     1 -------------------------------------------------------------------
     2 Sun Sep 17 08:07:43 UTC 2017 - wr@rosenauer.org
     2 Sat Sep 30 20:10:50 UTC 2017 - zaitor@opensuse.org
     3 
     3 
     4 - update to Firefox 56.0b12
     4 - Drop libgnomeui-devel, and replace it with pkgconfig(gconf-2.0),
       
     5   pkgconfig(gtk+-2.0), pkgconfig(gtk+-unix-print-2.0),
       
     6   pkgconfig(glib-2.0), pkgconfig(gobject-2.0) and
       
     7   pkgconfig(gdk-x11-2.0) BuildRequires, align with what configure
       
     8   looks for.
       
     9 
       
    10 -------------------------------------------------------------------
       
    11 Thu Sep 28 08:28:29 UTC 2017 - wr@rosenauer.org
       
    12 
       
    13 - update to Firefox 56.0 (boo#1060445)
       
    14   * Firefox Screenshots
     5   * Find Options/Preferences more quickly with new search function
    15   * Find Options/Preferences more quickly with new search function
     6   * Media is no longer auto-played when opened in a background tab
    16   * Media is no longer auto-played when opened in a background tab
     7   * Enable CSS Grid Layout View
    17   * Enable CSS Grid Layout View
       
    18   MFSA 2017-21
       
    19   * CVE-2017-7793 (bmo#1371889)
       
    20     Use-after-free with Fetch API
       
    21   * CVE-2017-7817 (bmo#1356596) (Android-only)
       
    22     Firefox for Android address bar spoofing through fullscreen mode
       
    23   * CVE-2017-7818 (bmo#1363723)
       
    24     Use-after-free during ARIA array manipulation
       
    25   * CVE-2017-7819 (bmo#1380292)
       
    26     Use-after-free while resizing images in design mode
       
    27   * CVE-2017-7824 (bmo#1398381)
       
    28     Buffer overflow when drawing and validating elements with ANGLE
       
    29   * CVE-2017-7805 (bmo#1377618) (fixed via NSS requirement)
       
    30     Use-after-free in TLS 1.2 generating handshake hashes
       
    31   * CVE-2017-7812 (bmo#1379842)
       
    32     Drag and drop of malicious page content to the tab bar can open locally stored files
       
    33   * CVE-2017-7814 (bmo#1376036)
       
    34     Blob and data URLs bypass phishing and malware protection warnings
       
    35   * CVE-2017-7813 (bmo#1383951)
       
    36     Integer truncation in the JavaScript parser
       
    37   * CVE-2017-7825 (bmo#1393624, bmo#1390980) (OSX-only)
       
    38     OS X fonts render some Tibetan and Arabic unicode characters as spaces
       
    39   * CVE-2017-7815 (bmo#1368981)
       
    40     Spoofing attack with modal dialogs on non-e10s installations
       
    41   * CVE-2017-7816 (bmo#1380597)
       
    42     WebExtensions can load about: URLs in extension UI
       
    43   * CVE-2017-7821 (bmo#1346515)
       
    44     WebExtensions can download and open non-executable files without user interaction
       
    45   * CVE-2017-7823 (bmo#1396320)
       
    46     CSP sandbox directive did not create a unique origin
       
    47   * CVE-2017-7822 (bmo#1368859)
       
    48     WebCrypto allows AES-GCM with 0-length IV
       
    49   * CVE-2017-7820 (bmo#1378207)
       
    50     Xray wrapper bypass with new tab and web console
       
    51   * CVE-2017-7811
       
    52     Memory safety bugs fixed in Firefox 56
       
    53   * CVE-2017-7810
       
    54     Memory safety bugs fixed in Firefox 56 and Firefox ESR 52.4
     8 - requires NSPR 4.16 and NSS 3.32.1
    55 - requires NSPR 4.16 and NSS 3.32.1
       
    56 - rebased patches
       
    57 
       
    58 -------------------------------------------------------------------
       
    59 Thu Sep 28 07:53:13 UTC 2017 - dimstar@opensuse.org
       
    60 
       
    61 - Add alsa-devel BuildRequires: we care for ALSA support to be
       
    62   built and thus need to ensure we get the dependencies in place.
       
    63   In the past, alsa-devel was pulled in by accident: we
       
    64   buildrequire libgnome-devel. This required esound-devel and that
       
    65   in turn pulled in alsa-devel for us. libgnome is being fixed to
       
    66   no longer require esound-devel.
     9 
    67 
    10 -------------------------------------------------------------------
    68 -------------------------------------------------------------------
    11 Mon Sep  4 18:27:44 UTC 2017 - wr@rosenauer.org
    69 Mon Sep  4 18:27:44 UTC 2017 - wr@rosenauer.org
    12 
    70 
    13 - update to Firefox 55.0.3
    71 - update to Firefox 55.0.3