Package firefox-esr: Information

Source package: firefox-esr
Version: 68.3.0-alt1
Build time:  Dec 5, 2019, 06:23 PM in the task #242314
Category: Networking/WWW
Report package bug
License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox-esr (x86_64, ppc64le, i586, aarch64)
firefox-esr-debuginfo (x86_64, ppc64le, i586, aarch64)
firefox-esr-wayland (noarch)

Maintainer: Andrey Cherepanov


    1. libvpx5-devel
    2. libcurl-devel
    3. libwireless-devel
    4. python3-base
    5. libdbus-devel
    6. libdbus-glib-devel
    7. alternatives
    8. /dev/shm
    9. libxkbcommon-devel
    10. autoconf_2.13
    11. autoconf_2.13
    12. libshell
    13. libevent-devel
    14. libffi-devel
    15. browser-plugins-npapi-devel
    16. bzlib-devel
    17. lld-devel
    18. /proc
    19. llvm7.0-devel
    20. libfreetype-devel
    21. chrpath
    22. clang7.0
    23. clang7.0-devel
    24. libstartup-notification-devel
    25. libstdc++-devel
    26. pkgconfig(nspr) >= 4.21
    27. pkgconfig(nss) >= 3.45.0
    28. mozilla-common-devel
    29. nasm
    30. gst-plugins1.0-devel
    31. gstreamer1.0-devel
    32. libGL-devel
    33. node
    34. rpm-build-mozilla.org
    35. libgio-devel
    36. libnotify-devel
    37. python-module-distribute
    38. libnss-devel-static
    39. rpm-macros-alternatives
    40. python-module-pip
    41. rust >= 1.35.0
    42. rust-cargo >= 1.35.0
    43. python-modules-compiler
    44. python-modules-json
    45. python-modules-logging
    46. python-modules-sqlite3
    47. libX11-devel
    48. libopus-devel
    49. fontconfig-devel
    50. libXScrnSaver-devel
    51. libXcomposite-devel
    52. libXcursor-devel
    53. libXdamage-devel
    54. libXext-devel
    55. libXft-devel
    56. libXi-devel
    57. libgtk+2-devel
    58. libgtk+3-devel
    59. libXt-devel
    60. libpixman-devel
    61. libcairo-devel
    62. libalsa-devel
    63. libhunspell-devel
    64. libjpeg-devel
    65. libpulseaudio-devel
    66. unzip
    67. xorg-cf-files
    68. yasm
    69. libproxy-devel
    70. zip
    71. zlib-devel

Last changed


Dec. 5, 2019 Andrey Cherepanov 68.3.0-alt1
- New ESR version (68.3.0).
  + CVE-2019-17008 Use-after-free in worker destruction
  + CVE-2019-13722 Stack corruption due to incorrect number of arguments in WebRTC code
  + CVE-2019-11745 Out of bounds write in NSS when encrypting with a block cipher
  + CVE-2019-17009 Updater temporary files accessible to unprivileged processes
  + CVE-2019-17010 Use-after-free when performing device orientation checks
  + CVE-2019-17005 Buffer overflow in plain text serializer
  + CVE-2019-17011 Use-after-free when retrieving a document in antitracking
  + CVE-2019-17012 Memory safety bugs fixed in Firefox 71 and Firefox ESR 68.3
Oct. 27, 2019 Andrey Cherepanov 68.2.0-alt1
- New ESR version (68.2.0).
- Fixed:
  + CVE-2019-15903 Heap overflow in expat library in XML_GetCurrentLineNumber
  + CVE-2019-11757 Use-after-free when creating index updates in IndexedDB
  + CVE-2019-11758 Potentially exploitable crash due to 360 Total Security
  + CVE-2019-11759 Stack buffer overflow in HKDF output
  + CVE-2019-11760 Stack buffer overflow in WebRTC networking
  + CVE-2019-11761 Unintended access to a privileged JSONView object
  + CVE-2019-11762 document.domain-based origin isolation has same-origin-property violation
  + CVE-2019-11763 Incorrect HTML parsing results in XSS bypass technique
  + CVE-2019-11764 Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2
Sept. 19, 2019 Andrey Cherepanov 68.1.0-alt2
- Fix open context menu (thanks george@).