1 ------------------------------------------------------------------- |
1 ------------------------------------------------------------------- |
2 Sat Jul 14 18:33:47 UTC 2012 - wr@rosenauer.org |
2 Sat Jul 14 18:33:47 UTC 2012 - wr@rosenauer.org |
3 |
3 |
4 - update to 10.0.6esr (bnc#) |
4 - update to 10.0.6esr (bnc#771583) |
|
5 * MFSA 2012-42/CVE-2012-1948 |
|
6 Miscellaneous memory safety hazards |
|
7 * MFSA 2012-43/CVE-2012-1950 |
|
8 Incorrect URL displayed in addressbar through drag and drop |
|
9 * MFSA 2012-44/CVE-2012-1951/CVE-2012-1954/CVE-2012-1953/CVE-2012-1952 |
|
10 Gecko memory corruption |
|
11 * MFSA 2012-45/CVE-2012-1955 (bmo#757376) |
|
12 Spoofing issue with location |
|
13 * MFSA 2012-46/CVE-2012-1966 (bmo#734076) |
|
14 XSS through data: URLs |
|
15 * MFSA 2012-47/CVE-2012-1957 (bmo#750096) |
|
16 Improper filtering of javascript in HTML feed-view |
|
17 * MFSA 2012-48/CVE-2012-1958 (bmo#750820) |
|
18 use-after-free in nsGlobalWindow::PageHidden |
|
19 * MFSA 2012-49/CVE-2012-1959 (bmo#754044, bmo#737559) |
|
20 Same-compartment Security Wrappers can be bypassed |
|
21 * MFSA 2012-51/CVE-2012-1961 (bmo#761655) |
|
22 X-Frame-Options header ignored when duplicated |
|
23 * MFSA 2012-52/CVE-2012-1962 (bmo#764296) |
|
24 JSDependentString::undepend string conversion results in memory |
|
25 corruption |
|
26 * MFSA 2012-53/CVE-2012-1963 (bmo#767778) |
|
27 Content Security Policy 1.0 implementation errors cause data |
|
28 leakage |
|
29 * MFSA 2012-54/CVE-2012-1964 (bmo#633691) |
|
30 Clickjacking of certificate warning page |
|
31 * MFSA 2012-55/CVE-2012-1965 (bmo#758990) |
|
32 feed: URLs with an innerURI inherit security context of page |
|
33 * MFSA 2012-56/CVE-2012-1967 (bmo#758344) |
|
34 Code execution through javascript: URLs |
5 - require NSS 3.13.5 |
35 - require NSS 3.13.5 |
6 |
36 |
7 ------------------------------------------------------------------- |
37 ------------------------------------------------------------------- |
8 Fri Jun 1 20:23:57 UTC 2012 - wr@rosenauer.org |
38 Fri Jun 1 20:23:57 UTC 2012 - wr@rosenauer.org |
9 |
39 |