Package firefox: Information

Source package: firefox
Version: 73.0.1-alt1
Build time:  Feb 27, 2020, 01:44 PM in the task #247014
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox (x86_64, ppc64le, i586, aarch64)
firefox-config-privacy (noarch)
firefox-debuginfo (x86_64, ppc64le, i586, aarch64)
firefox-wayland (noarch)
rpm-build-firefox (noarch)

Maintainer: Alexey Gladkov


    1. libvpx5-devel
    2. libcurl-devel
    3. libdbus-devel
    4. libdbus-glib-devel
    5. /dev/shm
    6. libwireless-devel
    7. libdrm-devel
    8. libxkbcommon-devel
    9. libshell
    10. alternatives
    11. libevent-devel
    12. /proc
    13. libffi-devel
    14. rust >= 1.40.0
    15. rust-cargo >= 1.40.0
    16. autoconf_2.13
    17. autoconf_2.13
    18. libfreetype-devel
    19. lld-devel
    20. libstartup-notification-devel
    21. llvm7.0-devel
    22. libstdc++-devel
    23. pkgconfig(nspr) >= 4.25
    24. pkgconfig(nss) >= 3.49.2
    25. browser-plugins-npapi-devel
    26. bzlib-devel
    27. libGL-devel
    28. chrpath
    29. clang7.0
    30. clang7.0-devel
    31. mozilla-common-devel
    32. libgio-devel
    33. nasm
    34. python-module-pip
    35. node
    36. python-module-setuptools
    37. gst-plugins1.0-devel
    38. unzip
    39. python-modules-compiler
    40. python-modules-json
    41. python-modules-logging
    42. gstreamer1.0-devel
    43. python-modules-sqlite3
    44. python2-base
    45. rpm-build-mozilla.org
    46. libnotify-devel
    47. rpm-macros-alternatives
    48. xorg-cf-files
    49. libnss-devel-static
    50. yasm
    51. zip
    52. zlib-devel
    53. libcairo-devel
    54. libgtk+2-devel
    55. libgtk+3-devel
    56. libX11-devel
    57. libXcomposite-devel
    58. libXScrnSaver-devel
    59. fontconfig-devel
    60. libXcursor-devel
    61. libXi-devel
    62. libXdamage-devel
    63. libopus-devel
    64. libXext-devel
    65. libhunspell-devel
    66. libalsa-devel
    67. libXft-devel
    68. libXt-devel
    69. libjpeg-devel
    70. libpulseaudio-devel
    71. libpixman-devel
    72. libproxy-devel

Last changed


Feb. 19, 2020 Alexey Gladkov 73.0.1-alt1
- New release (73.0.1).
Feb. 17, 2020 Alexey Gladkov 73.0-alt1
- New release (73.0).
- Security fixes:
  + CVE-2020-6796: Missing bounds check on shared memory read in the parent process
  + CVE-2020-6797: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX
  + CVE-2020-6798: Incorrect parsing of template tag could result in JavaScript injection
  + CVE-2020-6799: Arbitrary code execution when opening pdf links from other applications, when Firefox is configured as default pdf reader
  + CVE-2020-6800: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5
  + CVE-2020-6801: Memory safety bugs fixed in Firefox 73
Jan. 23, 2020 Alexey Gladkov 72.0.2-alt1
- New release (72.0.2).
- Security fixes:
  + CVE-2019-17015: Memory corruption in parent process during new content process initialization on Windows
  + CVE-2019-17016: Bypass of @namespace CSS sanitization during pasting
  + CVE-2019-17017: Type Confusion in XPCVariant.cpp
  + CVE-2019-17018: Windows Keyboard in Private Browsing Mode may retain word suggestions
  + CVE-2019-17019: Python files could be inadvertently executed upon opening a download
  + CVE-2019-17020: Content Security Policy not applied to XSL stylesheets applied to XML documents
  + CVE-2019-17021: Heap address disclosure in parent process during content process initialization on Windows
  + CVE-2019-17022: CSS sanitization does not escape HTML tags
  + CVE-2019-17023: NSS may negotiate TLS 1.2 or below after a TLS 1.3 HelloRetryRequest had been sent
  + CVE-2019-17024: Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4
  + CVE-2019-17025: Memory safety bugs fixed in Firefox 72
  + CVE-2019-17026: IonMonkey type confusion with StoreElementHole and FallibleStoreElement