Package firefox-esr: Information

Source package: firefox-esr
Version: 60.4.0-alt1
Build time:  Dec 13, 2018, 09:00 PM in the task #217704
Category: Networking/WWW
Report package bug
License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser
component, written using the XUL user interface language and designed to
be cross-platform.

List of rpms provided by this srpm:
firefox-esr (x86_64, i586)
firefox-esr-debuginfo (x86_64, i586)

Maintainer: Andrey Cherepanov


    1. /proc
    2. libX11-devel
    3. libpulseaudio-devel
    4. libhunspell-devel
    5. libcairo-devel
    6. fontconfig-devel
    7. libjpeg-devel
    8. libvpx-devel
    9. /dev/shm
    10. libXScrnSaver-devel
    11. libXcomposite-devel
    12. libXcursor-devel
    13. libXdamage-devel
    14. libXext-devel
    15. libcurl-devel
    16. libwireless-devel
    17. libXft-devel
    18. libXi-devel
    19. libdbus-devel
    20. libdbus-glib-devel
    21. libXt-devel
    22. libshell
    23. libalsa-devel
    24. libevent-devel
    25. libffi-devel
    26. libstartup-notification-devel
    27. libfreetype-devel
    28. libstdc++-devel
    29. rust >= 1.24.1
    30. rust-cargo >= 0.25.0
    31. lld-devel
    32. llvm6.0-devel
    33. pkgconfig(nspr) >= 4.17
    34. pkgconfig(nss) >= 3.36.4
    35. alternatives
    36. rpm-build-mozilla.org
    37. rpm-macros-alternatives
    38. mozilla-common-devel
    39. libgio-devel
    40. autoconf_2.13
    41. autoconf_2.13
    42. python-module-distribute
    43. libnotify-devel
    44. python-module-pip
    45. libnss-devel-static
    46. python-modules-compiler
    47. python-modules-json
    48. python-modules-logging
    49. python-modules-sqlite3
    50. libGL-devel
    51. browser-plugins-npapi-devel
    52. chrpath
    53. bzlib-devel
    54. clang6.0
    55. clang6.0-devel
    56. gst-plugins1.0-devel
    57. gstreamer1.0-devel
    58. libopus-devel
    59. libgtk+2-devel
    60. libgtk+3-devel
    61. libpixman-devel
    62. unzip
    63. xorg-cf-files
    64. libproxy-devel
    65. yasm
    66. zip
    67. zlib-devel

Last changed


Dec. 11, 2018 Andrey Cherepanov 60.4.0-alt1
- New ESR version (60.4.0)
- Fixed:
  + CVE-2018-17466 Buffer overflow and out-of-bounds read in ANGLE library with TextureStorage11
  + CVE-2018-18492 Use-after-free with select element
  + CVE-2018-18493 Buffer overflow in accelerated 2D canvas with Skia
  + CVE-2018-18494 Same-origin policy violation using location attribute and performance.getEntries to steal cross-origin URLs
  + CVE-2018-18498 Integer overflow when calculating buffer sizes for images
  + CVE-2018-12405 Memory safety bugs fixed in Firefox 64 and Firefox ESR 60.4
Oct. 23, 2018 Andrey Cherepanov 60.3.0-alt1
- New ESR version (60.3.0).
- Fixed:
  + CVE-2018-12391 HTTP Live Stream audio data is accessible cross-origin
  + CVE-2018-12392 Crash with nested event loops
  + CVE-2018-12393 Integer overflow during Unicode conversion while loading JavaScript
  + CVE-2018-12395 WebExtension bypass of domain restrictions through header rewriting
  + CVE-2018-12396 WebExtension content scripts can execute in disallowed contexts
  + CVE-2018-12397 WebExtension can request access to local files without the warning prompt
  + CVE-2018-12389 Memory safety bugs fixed in Firefox ESR 60.3
  + CVE-2018-12390 Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3
Oct. 2, 2018 Andrey Cherepanov 60.2.2-alt1
- New ESR version (60.2.2)
- Fixed:
  + CVE-2018-12386 Type confusion in JavaScript
  + CVE-2018-12387 JavaScript JIT compiler inlines Array.prototype.push with multiple arguments