Package firefox-esr: Information

Source package: firefox-esr
Version: 60.2.0-alt1
Build time:  Sep 11, 2018, 07:09 PM in the task #212803
Category: Networking/WWW
Report package bug
License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser
component, written using the XUL user interface language and designed to
be cross-platform.

List of rpms provided by this srpm:
firefox-esr (x86_64, i586, aarch64)
firefox-esr-debuginfo (x86_64, i586, aarch64)

Maintainer: Andrey Cherepanov


    1. libvpx-devel
    2. libshell
    3. libwireless-devel
    4. libcurl-devel
    5. libdbus-devel
    6. libdbus-glib-devel
    7. pkgconfig(nspr) >= 4.17
    8. pkgconfig(nss) >= 3.36.4
    9. libstartup-notification-devel
    10. libstdc++-devel
    11. /dev/shm
    12. alternatives
    13. libevent-devel
    14. libffi-devel
    15. autoconf_2.13
    16. libfreetype-devel
    17. autoconf_2.13
    18. python-module-distribute
    19. lld-devel
    20. llvm6.0-devel
    21. python-module-pip
    22. /proc
    23. python-modules-compiler
    24. browser-plugins-npapi-devel
    25. python-modules-json
    26. python-modules-logging
    27. bzlib-devel
    28. python-modules-sqlite3
    29. libgio-devel
    30. chrpath
    31. clang6.0
    32. clang6.0-devel
    33. gst-plugins1.0-devel
    34. rust >= 1.24.1
    35. gstreamer1.0-devel
    36. rust-cargo >= 0.25.0
    37. libcairo-devel
    38. rpm-build-mozilla.org
    39. rpm-macros-alternatives
    40. libGL-devel
    41. libnotify-devel
    42. libX11-devel
    43. libgtk+2-devel
    44. libgtk+3-devel
    45. libnss-devel-static
    46. libhunspell-devel
    47. libjpeg-devel
    48. mozilla-common-devel
    49. libopus-devel
    50. fontconfig-devel
    51. libXScrnSaver-devel
    52. unzip
    53. libXcomposite-devel
    54. libpixman-devel
    55. yasm
    56. xorg-cf-files
    57. libXcursor-devel
    58. libXdamage-devel
    59. libXext-devel
    60. zip
    61. zlib-devel
    62. libXt-devel
    63. libXft-devel
    64. libXi-devel
    65. libalsa-devel
    66. libproxy-devel
    67. libpulseaudio-devel

Last changed


Sept. 10, 2018 Andrey Cherepanov 60.2.0-alt1
- New ESR version (60.2.0).
- Fixed:
  + CVE-2018-12377 Use-after-free in refresh driver timers
  + CVE-2018-12378 Use-after-free in IndexedDB
  + CVE-2018-12379 Out-of-bounds write with malicious MAR file
  + CVE-2017-16541 Proxy bypass using automount and autofs
  + CVE-2018-12381 Dragging and dropping Outlook email message results in page navigation
  + CVE-2018-12376 Memory safety bugs fixed in Firefox 62 and Firefox ESR 60.2
June 26, 2018 Andrey Cherepanov 60.1.0-alt1
- New ESR version (60.1.0).
- Fixed:
  + CVE-2018-12359 Buffer overflow using computed size of canvas element
  + CVE-2018-12360 Use-after-free when using focus()
  + CVE-2018-12361 Integer overflow in SwizzleData
  + CVE-2018-12362 Integer overflow in SSSE3 scaler
  + CVE-2018-5156 Media recorder segmentation fault when track type is changed during capture
  + CVE-2018-12363 Use-after-free when appending DOM nodes
  + CVE-2018-12364 CSRF attacks through 307 redirects and NPAPI plugins
  + CVE-2018-12365 Compromised IPC child process can list local filenames
  + CVE-2018-12371 Integer overflow in Skia library during edge builder allocation
  + CVE-2018-12366 Invalid data handling during QCMS transformations
  + CVE-2018-12367 Timing attack mitigation of PerformanceNavigationTiming
  + CVE-2018-12368 No warning when opening executable SettingContent-ms files
  + CVE-2018-12369 WebExtension security permission checks bypassed by embedded experiments
  + CVE-2018-5187 Memory safety bugs fixed in Firefox 60 and Firefox ESR 60.1
  + CVE-2018-5188 Memory safety bugs fixed in Firefox 60, Firefox ESR 60.1, and Firefox ESR 52.9
June 18, 2018 Andrey Cherepanov 60.0.2-alt2
- Fix build for aarch64 (thanks legion@).