Package firefox-esr: Information

Source package: firefox-esr
Version: 60.7.0-alt0.M80P.1
Build time:  May 23, 2019, 07:20 PM in the task #229794
Category: Networking/WWW
Report package bug
License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser
component, written using the XUL user interface language and designed to
be cross-platform.

List of rpms provided by this srpm:
firefox-esr (x86_64, i586)
firefox-esr-debuginfo (x86_64, i586)

Maintainer: Andrey Cherepanov


    1. alternatives
    2. libwireless-devel
    3. libshell
    4. autoconf_2.13
    5. autoconf_2.13
    6. libevent-devel
    7. browser-plugins-npapi-devel
    8. bzlib-devel
    9. libffi-devel
    10. libstartup-notification-devel
    11. libstdc++-devel
    12. lld-devel
    13. llvm6.0-devel
    14. chrpath
    15. clang6.0
    16. clang6.0-devel
    17. libfreetype-devel
    18. /proc
    19. pkgconfig(nspr) >= 4.17
    20. pkgconfig(nss) >= 3.36.4
    21. libnotify-devel
    22. mozilla-common-devel
    23. libnss-devel-static
    24. libGL-devel
    25. gst-plugins1.0-devel
    26. gstreamer1.0-devel
    27. libgio-devel
    28. python-module-distribute
    29. python-module-pip
    30. rust >= 1.24.1
    31. fontconfig-devel
    32. rust-cargo >= 0.25.0
    33. python-modules-compiler
    34. libopus-devel
    35. python-modules-json
    36. python-modules-logging
    37. python-modules-sqlite3
    38. rpm-build-mozilla.org
    39. rpm-macros-alternatives
    40. libgtk+2-devel
    41. libgtk+3-devel
    42. libX11-devel
    43. libpixman-devel
    44. libXScrnSaver-devel
    45. libcairo-devel
    46. libXcomposite-devel
    47. libhunspell-devel
    48. libXcursor-devel
    49. libXdamage-devel
    50. libXext-devel
    51. libXft-devel
    52. libproxy-devel
    53. libXi-devel
    54. libvpx-devel
    55. libXt-devel
    56. unzip
    57. libjpeg-devel
    58. libalsa-devel
    59. libcurl-devel
    60. zip
    61. xorg-cf-files
    62. libpulseaudio-devel
    63. zlib-devel
    64. libdbus-devel
    65. yasm
    66. libdbus-glib-devel

Last changed


May 22, 2019 Andrey Cherepanov 60.7.0-alt0.M80P.1
- Backport new version to p8 branch.
May 21, 2019 Andrey Cherepanov 60.7.0-alt1
- New ESR version (60.7.0).
- Fixed:
  + CVE-2019-9815 Disable hyperthreading on content JavaScript threads on macOS
  + CVE-2019-9816 Type confusion with object groups and UnboxedObjects
  + CVE-2019-9817 Stealing of cross-domain images using canvas
  + CVE-2019-9818 Use-after-free in crash generation server
  + CVE-2019-9819 Compartment mismatch with fetch API
  + CVE-2019-9820 Use-after-free of ChromeEventHandler by DocShell
  + CVE-2019-11691 Use-after-free in XMLHttpRequest
  + CVE-2019-11692 Use-after-free removing listeners in the event listener manager
  + CVE-2019-11693 Buffer overflow in WebGL bufferdata on Linux
  + CVE-2019-7317 Use-after-free in png_image_free of libpng library
  + CVE-2019-9797 Cross-origin theft of images with createImageBitmap
  + CVE-2018-18511 Cross-origin theft of images with ImageBitmapRenderingContext
  + CVE-2019-11694 Uninitialized memory memory leakage in Windows sandbox
  + CVE-2019-11698 Theft of user history data through drag and drop of hyperlinks to and from bookmarks
  + CVE-2019-5798 Out-of-bounds read in Skia
  + CVE-2019-9800 Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7
May 5, 2019 Andrey Cherepanov 60.6.2-alt0.M80P.1
- Backport new version to p8 branch.