Package rpm-build-firefox: Information

    Binary package: rpm-build-firefox
    Version: 68.0.1-alt0.M80P.1
    Architecture: noarch
    Build time:  Oct 15, 2019, 09:24 PM in the task #236175
    Source package: firefox
    Report package bug
    License: MPL/GPL/LGPL
    Summary: RPM helper macros to rebuild firefox packages
    Description: 
    These helper macros provide possibility to rebuild
    firefox packages by some Alt Linux Team Policy compatible way.

    Maintainer: Alexey Gladkov


    Last changed


    Sept. 9, 2019 Andrey Cherepanov 68.0.1-alt0.M80P.1
    - Backport new version with security fixes to p8 branch.
    Aug. 1, 2019 Alexey Gladkov 68.0.1-alt1
    - New release (68.0.1).
    July 11, 2019 Alexey Gladkov 68.0-alt1
    - New release (68.0).
    - Fixed:
      + CVE-2019-9811: Sandbox escape via installation of malicious language pack
      + CVE-2019-11711: Script injection within domain through inner window reuse
      + CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects
      + CVE-2019-11713: Use-after-free with HTTP/2 cached stream
      + CVE-2019-11714: NeckoChild can trigger crash when accessed off of main thread
      + CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
      + CVE-2019-11715: HTML parsing error can contribute to content XSS
      + CVE-2019-11716: globalThis not enumerable until accessed
      + CVE-2019-11717: Caret character improperly escaped in origins
      + CVE-2019-11718: Activity Stream writes unsanitized content to innerHTML
      + CVE-2019-11719: Out-of-bounds read when importing curve25519 private key
      + CVE-2019-11720: Character encoding XSS vulnerability
      + CVE-2019-11721: Domain spoofing through unicode latin 'kra' character
      + CVE-2019-11730: Same-origin policy treats all files in a directory as having the same-origin
      + CVE-2019-11723: Cookie leakage during add-on fetching across private browsing boundaries
      + CVE-2019-11724: Retired site input.mozilla.org has remote troubleshooting permissions
      + CVE-2019-11725: Websocket resources bypass safebrowsing protections
      + CVE-2019-11727: PKCS#1 v1.5 signatures can be used for TLS 1.3
      + CVE-2019-11728: Port scanning through Alt-Svc header
      + CVE-2019-11710: Memory safety bugs fixed in Firefox 68
      + CVE-2019-11709: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8