Package firefox: Information

Source package: firefox
Version: 57.0.1-alt0.M80P.1
Build time:  Dec 8, 2017, 05:42 PM in the task #195836
Category: Networking/WWW
Report package bug
License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox (x86_64, i586)
firefox-debuginfo (x86_64, i586)
rpm-build-firefox (noarch)

Maintainer: Alexey Gladkov


    1. libalsa-devel
    2. libvpx-devel
    3. libcurl-devel
    4. libwireless-devel
    5. /dev/shm
    6. libdbus-c++-devel
    7. libdbus-devel
    8. libshell
    9. alternatives
    10. rust
    11. rust-cargo
    12. llvm4.0
    13. llvm4.0-devel
    14. llvm4.0-libs
    15. /proc
    16. libevent-devel
    17. libstartup-notification-devel
    18. autoconf_2.13
    19. autoconf_2.13
    20. libffi-devel
    21. mozilla-common-devel
    22. libnotify-devel
    23. libfreetype-devel
    24. libnss-devel-static
    25. libopus-devel
    26. browser-plugins-npapi-devel
    27. pkgconfig(nspr) >= 4.17
    28. bzlib-devel
    29. pkgconfig(nss) >= 3.33.0
    30. rpm-build-mozilla.org
    31. rpm-macros-alternatives
    32. libGL-devel
    33. unzip
    34. chrpath
    35. clang4.0
    36. clang4.0-devel
    37. libpixman-devel
    38. gst-plugins1.0-devel
    39. gstreamer1.0-devel
    40. libgio-devel
    41. xorg-cf-files
    42. python-module-distribute
    43. libproxy-devel
    44. yasm
    45. python-module-pip
    46. zip
    47. zlib-devel
    48. python-modules-compiler
    49. python-modules-json
    50. python-modules-logging
    51. libX11-devel
    52. python-modules-sqlite3
    53. libpulseaudio-devel
    54. libXcomposite-devel
    55. fontconfig-devel
    56. libXScrnSaver-devel
    57. gcc-c++
    58. libXft-devel
    59. libXdamage-devel
    60. libXext-devel
    61. libhunspell-devel
    62. libXt-devel
    63. libgtk+2-devel
    64. libjpeg-devel
    65. libgtk+3-devel
    66. libcairo-devel

Last changed


Dec. 5, 2017 Andrey Cherepanov 57.0.1-alt0.M80P.1
- Backport new version to p8 branch
Dec. 4, 2017 Alexey Gladkov 57.0.1-alt1
- New release (57.0.1).
Nov. 21, 2017 Alexey Gladkov 57.0-alt1
- New release (57.0).
- Fixed:
  + CVE-2017-7828: Use-after-free of PressShell while restyling layout
  + CVE-2017-7830: Cross-origin URL information leak through Resource Timing API
  + CVE-2017-7831: Information disclosure of exposed properties on JavaScript proxy objects
  + CVE-2017-7832: Domain spoofing through use of dotless 'i' character followed by accent markers
  + CVE-2017-7833: Domain spoofing with Arabic and Indic vowel marker characters
  + CVE-2017-7834: data: URLs opened in new tabs bypass CSP protections
  + CVE-2017-7835: Mixed content blocking incorrectly applies with redirects
  + CVE-2017-7836: Pingsender dynamically loads libcurl on Linux and OS X
  + CVE-2017-7837: SVG loaded as <img> can use meta tags to set cookies
  + CVE-2017-7838: Failure of individual decoding of labels in international domain names triggers punycode display of entire IDN
  + CVE-2017-7839: Control characters before javascript: URLs defeats self-XSS prevention mechanism
  + CVE-2017-7840: Exported bookmarks do not strip script elements from user-supplied tags
  + CVE-2017-7842: Referrer Policy is not always respected for <link> elements
  + CVE-2017-7827: Memory safety bugs fixed in Firefox 57
  + CVE-2017-7826: Memory safety bugs fixed in Firefox 57 and Firefox ESR 52.5