Sisyphus repository
Last update: 2017-05-30 09:06:06 +0400 | SRPMs: 17882 | Sign in or Sign up
en ru uk br
ALT Linux repositories
hide window
Sisyphus: 53.0.2-alt1
p8: 53.0.2-alt0.M80P.1
t7: 45.9.0-alt0.M70P.1

Group :: Networking/WWW
Source RPM: firefox

 Main   Changelog   Spec   Patches   Sources   Download   Gear   Bugs and FR (27/155)   Repocop 

Current version: 53.0.2-alt1
Built: 22 days ago
Size: 208 MB
Repocop status: ok

Home page:   http://www.mozilla.org/projects/firefox/

License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description:

The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

Current maintainer: Alexey Gladkov

List of contributors: ACL: List of rpms provided by this srpm:
  • firefox
  • firefox-debuginfo
  • rpm-build-firefox
Recent changes (last three changelog entries):

2017-05-07 Alexey Gladkov <legion at altlinux.ru> 53.0.2-alt1

    - New release (53.0.2).
    - Fixed:
    + CVE-2017-5031: Use after free in ANGLE

2017-05-01 Alexey Gladkov <legion at altlinux.ru> 53.0-alt1

    - New release (53.0).
    - Built with internal hunspell.
    - Fixed:
    + CVE-2017-5433: Use-after-free in SMIL animation functions
    + CVE-2017-5435: Use-after-free during transaction processing in the editor
    + CVE-2017-5436: Out-of-bounds write with malicious font in Graphite 2
    + CVE-2017-5461: Out-of-bounds write in Base64 encoding in NSS
    + CVE-2017-5459: Buffer overflow in WebGL
    + CVE-2017-5466: Origin confusion when reloading isolated data:text/html URL
    + CVE-2017-5434: Use-after-free during focus handling
    + CVE-2017-5432: Use-after-free in text input selection
    + CVE-2017-5460: Use-after-free in frame selection
    + CVE-2017-5438: Use-after-free in nsAutoPtr during XSLT processing
    + CVE-2017-5439: Use-after-free in nsTArray Length() during XSLT processing
    + CVE-2017-5440: Use-after-free in txExecutionState destructor during XSLT processing
    + CVE-2017-5441: Use-after-free with selection during scroll events
    + CVE-2017-5442: Use-after-free during style changes
    + CVE-2017-5464: Memory corruption with accessibility and DOM manipulation
    + CVE-2017-5443: Out-of-bounds write during BinHex decoding
    + CVE-2017-5444: Buffer overflow while parsing application/http-index-format content
    + CVE-2017-5446: Out-of-bounds read when HTTP/2 DATA frames are sent with incorrect data
    + CVE-2017-5447: Out-of-bounds read during glyph processing
    + CVE-2017-5465: Out-of-bounds read in ConvolvePixel
    + CVE-2017-5448: Out-of-bounds write in ClearKeyDecryptor
    + CVE-2016-10196: Vulnerabilities in Libevent library
    + CVE-2017-5454: Sandbox escape allowing file system read access through file picker
    + CVE-2017-5455: Sandbox escape through internal feed reader APIs
    + CVE-2017-5456: Sandbox escape allowing local file system access
    + CVE-2017-5469: Potential Buffer overflow in flex-generated code
    + CVE-2017-5445: Uninitialized values used while parsing application/http-index-format content
    + CVE-2017-5449: Crash during bidirectional unicode manipulation with animation
    + CVE-2017-5450: Addressbar spoofing using javascript: URI on Firefox for Android
    + CVE-2017-5451: Addressbar spoofing with onblur event
    + CVE-2017-5462: DRBG flaw in NSS
    + CVE-2017-5463: Addressbar spoofing through reader view on Firefox for Android
    + CVE-2017-5467: Memory corruption when drawing Skia content
    + CVE-2017-5452: Addressbar spoofing during scrolling with editable content on Firefox for Android
    + CVE-2017-5453: HTML injection into RSS Reader feed preview page through TITLE element
    + CVE-2017-5458: Drag and drop of javascript: URLs can allow for self-XSS
    + CVE-2017-5468: Incorrect ownership model for Private Browsing information
    + CVE-2017-5430: Memory safety bugs fixed in Firefox 53 and Firefox ESR 52.1
    + CVE-2017-5429: Memory safety bugs fixed in Firefox 53, Firefox ESR 45.9, and Firefox ESR 52.1

2017-03-15 Alexey Gladkov <legion at altlinux.ru> 52.0-alt1

    - New release (52.0).
    - Built with internal icu.
    - Fixed:
    + CVE-2017-5400: asm.js JIT-spray bypass of ASLR and DEP
    + CVE-2017-5401: Memory Corruption when handling ErrorResult
    + CVE-2017-5402: Use-after-free working with events in FontFace objects
    + CVE-2017-5403: Use-after-free using addRange to add range to an incorrect root object
    + CVE-2017-5404: Use-after-free working with ranges in selections
    + CVE-2017-5406: Segmentation fault in Skia with canvas operations
    + CVE-2017-5407: Pixel and history stealing via floating-point timing side channel with SVG filters
    + CVE-2017-5410: Memory corruption during JavaScript garbage collection incremental sweeping
    + CVE-2017-5411: Use-after-free in Buffer Storage in libGLES
    + CVE-2017-5409: File deletion via callback parameter in Mozilla Windows Updater and Maintenance Service
    + CVE-2017-5408: Cross-origin reading of video captions in violation of CORS
    + CVE-2017-5412: Buffer overflow read in SVG filters
    + CVE-2017-5413: Segmentation fault during bidirectional operations
    + CVE-2017-5414: File picker can choose incorrect default directory
    + CVE-2017-5415: Addressbar spoofing through blob URL
    + CVE-2017-5416: Null dereference crash in HttpChannel
    + CVE-2017-5417: Addressbar spoofing by draging and dropping URLs
    + CVE-2017-5425: Overly permissive Gecko Media Plugin sandbox regular expression access
    + CVE-2017-5426: Gecko Media Plugin sandbox is not started if seccomp-bpf filter is running
    + CVE-2017-5427: Non-existent chrome.manifest file loaded during startup
    + CVE-2017-5418: Out of bounds read when parsing HTTP digest authorization responses
    + CVE-2017-5419: Repeated authentication prompts lead to DOS attack
    + CVE-2017-5420: Javascript: URLs can obfuscate addressbar location
    + CVE-2017-5405: FTP response codes can cause use of uninitialized values for ports
    + CVE-2017-5421: Print preview spoofing
    + CVE-2017-5422: DOS attack by using view-source: protocol repeatedly in one hyperlink
    + CVE-2017-5399: Memory safety bugs fixed in Firefox 52
    + CVE-2017-5398: Memory safety bugs fixed in Firefox 52 and Firefox ESR 45.8

 
© 2009–2016 Igor Zubkov