Package firefox-esr: Information

Source package: firefox-esr
Version: 115.6.0-alt1
Build time:  Dec 28, 2023, 10:30 PM in the task #336859
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox-esr (x86_64, i586, armh, aarch64)
firefox-esr-config-privacy (x86_64, i586, armh, aarch64)
firefox-esr-debuginfo (x86_64, i586, armh, aarch64)
firefox-esr-wayland (x86_64, i586, armh, aarch64)

Maintainer: Andrey Cherepanov


    1. /dev/shm
    2. python3(hamcrest)
    3. libgio-devel
    4. python3(setuptools)
    5. rpm-build-mozilla.org
    6. rpm-macros-alternatives
    7. /proc
    8. libX11-devel
    9. libXScrnSaver-devel
    10. libXcomposite-devel
    11. libXcursor-devel
    12. libXdamage-devel
    13. python3(sqlite3)
    14. libXext-devel
    15. libgtk+2-devel
    16. libXft-devel
    17. libXi-devel
    18. libgtk+3-devel
    19. pkgconfig(alsa)
    20. pkgconfig(aom)
    21. libXt-devel
    22. pkgconfig(bzip2)
    23. pkgconfig(cairo)
    24. pkgconfig(dav1d)
    25. pkgconfig(dbus-1)
    26. pkgconfig(dbus-glib-1)
    27. libvpx-devel
    28. pkgconfig(dri)
    29. libalsa-devel
    30. pkgconfig(fontconfig)
    31. pkgconfig(freetype2)
    32. libhunspell-devel
    33. libaom-devel
    34. pkgconfig(gio-2.0)
    35. pkgconfig(graphite2)
    36. pkgconfig(gtk+-2.0)
    37. pkgconfig(gtk+-3.0)
    38. pkgconfig(harfbuzz)
    39. pkgconfig(hunspell)
    40. pkgconfig(icu-i18n)
    41. pkgconfig(libcurl)
    42. pkgconfig(libdrm)
    43. libjpeg-devel
    44. pkgconfig(libevent)
    45. pkgconfig(libffi)
    46. libwireless-devel
    47. pkgconfig(libjpeg)
    48. pkgconfig(libnotify)
    49. pkgconfig(libproxy-1.0)
    50. pkgconfig(libpulse)
    51. python3(pip)
    52. pkgconfig(libstartup-notification-1.0)
    53. pkgconfig(nspr) >= 4.35
    54. pkgconfig(nss) >= 3.86
    55. pkgconfig(opus)
    56. libxkbcommon-devel
    57. pkgconfig(pixman-1)
    58. pkgconfig(vpx)
    59. pkgconfig(x11)
    60. pkgconfig(xcomposite)
    61. pkgconfig(xcursor)
    62. pkgconfig(xdamage)
    63. pkgconfig(xext)
    64. pkgconfig(xft)
    65. pkgconfig(xi)
    66. pkgconfig(xkbcommon)
    67. pkgconfig(xrandr)
    68. pkgconfig(xscrnsaver)
    69. pkgconfig(xt)
    70. pkgconfig(xtst)
    71. pkgconfig(zlib)
    72. alternatives
    73. autoconf_2.13
    74. autoconf_2.13
    75. lld15.0-devel
    76. llvm15.0-devel
    77. libGL-devel
    78. python3-base
    79. browser-plugins-npapi-devel
    80. bzlib-devel
    81. chrpath
    82. clang15.0
    83. clang15.0-devel
    84. mozilla-common-devel
    85. rust >= 1.65.0
    86. rust-cargo >= 1.65.0
    87. nasm
    88. node
    89. libnotify-devel
    90. libnss-devel-static
    91. python3(click)
    92. unzip
    93. libopus-devel
    94. xorg-cf-files
    95. libpixman-devel
    96. yasm
    97. python3(curses)
    98. zip
    99. zlib-devel
    100. libcairo-devel
    101. libproxy-devel
    102. libcurl-devel
    103. libpulseaudio-devel
    104. fontconfig-devel
    105. glibc-kernheaders-generic
    106. libdav1d-devel
    107. gst-plugins1.0-devel
    108. gstreamer1.0-devel
    109. libdbus-devel
    110. libdbus-glib-devel
    111. libffi-devel
    112. libdrm-devel
    113. libevent-devel
    114. libshell
    115. libfreetype-devel
    116. libstartup-notification-devel
    117. libstdc++-devel

Last changed


Dec. 20, 2023 Pavel Vasenkov 115.6.0-alt1
- New ESR version.
- Security fixes
  + CVE-2023-6856 Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with Mesa VM driver
  + CVE-2023-6865 Potential exposure of uninitialized data in EncryptingOutputStream
  + CVE-2023-6857 Symlinks may resolve to smaller than expected buffers
  + CVE-2023-6858 Heap buffer overflow in nsTextFragment
  + CVE-2023-6859 Use-after-free in PR_GetIdentitiesLayer
  + CVE-2023-6860 Potential sandbox escape due to VideoBridge lack of texture validation
  + CVE-2023-6867 Clickjacking permission prompts using the popup transition
  + CVE-2023-6861 Heap buffer overflow affected nsWindow::PickerOpen(void) in headless mode
  + CVE-2023-6862 Use-after-free in nsDNSService
  + CVE-2023-6863 Undefined behavior in ShutdownObserver()
  + CVE-2023-6864 Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6
Nov. 23, 2023 Pavel Vasenkov 115.5.0-alt1
- New ESR version.
- Security fixes
  + CVE-2023-6204 Out-of-bound memory access in WebGL2 blitFramebuffer
  + CVE-2023-6205 Use-after-free in MessagePort::Entangled
  + CVE-2023-6206 Clickjacking permission prompts using the fullscreen transition
  + CVE-2023-6207 Use-after-free in ReadableByteStreamQueueEntry::Buffer
  + CVE-2023-6208 Using Selection API would copy contents into X11 primary selection.
  + CVE-2023-6209 Incorrect parsing of relative URLs starting with "///"
  + CVE-2023-6212 Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5
Nov. 2, 2023 Pavel Vasenkov 115.4.0-alt1
- New ESR version.
- Security fixes
  + CVE-2023-5721 Queued up rendering could have allowed websites to clickjack
  + CVE-2023-5732 Address bar spoofing via bidirectional characters
  + CVE-2023-5724 Large WebGL draw could have led to a crash
  + CVE-2023-5725 WebExtensions could open arbitrary URLs
  + CVE-2023-5726 Full screen notification obscured by file open dialog on macOS
  + CVE-2023-5727 Download Protections were bypassed by .msix, .msixbundle, .appx, and .appxbundle files on Windows
  + CVE-2023-5728 Improper object tracking during GC in the JavaScript engine could have led to a crash.
  + CVE-2023-5730 Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4.1