Package firefox: Information

Source package: firefox
Version: 58.0.2-alt0.M80P.1
Build time:  Feb 15, 2018, 11:37 PM in the task #200523
Category: Networking/WWW
Report package bug
License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox (x86_64, i586)
firefox-debuginfo (x86_64, i586)
rpm-build-firefox (noarch)

Maintainer: Alexey Gladkov


    1. libX11-devel
    2. libXScrnSaver-devel
    3. libpulseaudio-devel
    4. libXcomposite-devel
    5. fontconfig-devel
    6. libXdamage-devel
    7. libXext-devel
    8. libcairo-devel
    9. libhunspell-devel
    10. /proc
    11. libXft-devel
    12. libXt-devel
    13. libjpeg-devel
    14. libalsa-devel
    15. gcc-c++
    16. libvpx-devel
    17. libcurl-devel
    18. libdbus-devel
    19. libdbus-glib-devel
    20. libwireless-devel
    21. libshell
    22. rust
    23. rust-cargo
    24. libevent-devel
    25. libstartup-notification-devel
    26. libffi-devel
    27. alternatives
    28. rpm-build-mozilla.org
    29. pkgconfig(nspr) >= 4.17
    30. libfreetype-devel
    31. pkgconfig(nss) >= 3.33.0
    32. rpm-macros-alternatives
    33. llvm4.0
    34. llvm4.0-devel
    35. llvm4.0-libs
    36. autoconf_2.13
    37. autoconf_2.13
    38. libnotify-devel
    39. libnss-devel-static
    40. unzip
    41. python-module-distribute
    42. mozilla-common-devel
    43. python-module-pip
    44. python-modules-compiler
    45. python-modules-json
    46. gst-plugins1.0-devel
    47. dev-minimal
    48. python-modules-logging
    49. gstreamer1.0-devel
    50. browser-plugins-npapi-devel
    51. python-modules-sqlite3
    52. libgio-devel
    53. bzlib-devel
    54. clang4.0
    55. clang4.0-devel
    56. chrpath
    57. xorg-cf-files
    58. yasm
    59. libopus-devel
    60. libGL-devel
    61. zip
    62. libpixman-devel
    63. libgtk+2-devel
    64. zlib-devel
    65. libgtk+3-devel
    66. libproxy-devel

Last changed


Feb. 13, 2018 Andrey Cherepanov 58.0.2-alt0.M80P.1
- Backport new version to p8 branch.
Feb. 11, 2018 Alexey Gladkov 58.0.2-alt1
- New release (58.0.2).
- Fixed:
  + CVE-2018-5091: Use-after-free with DTMF timers
  + CVE-2018-5092: Use-after-free in Web Workers
  + CVE-2018-5093: Buffer overflow in WebAssembly during Memory/Table resizing
  + CVE-2018-5094: Buffer overflow in WebAssembly with garbage collection on uninitialized memory
  + CVE-2018-5095: Integer overflow in Skia library during edge builder allocation
  + CVE-2018-5097: Use-after-free when source document is manipulated during XSLT
  + CVE-2018-5098: Use-after-free while manipulating form input elements
  + CVE-2018-5099: Use-after-free with widget listener
  + CVE-2018-5100: Use-after-free when IsPotentiallyScrollable arguments are freed from memory
  + CVE-2018-5101: Use-after-free with floating first-letter style elements
  + CVE-2018-5102: Use-after-free in HTML media elements
  + CVE-2018-5103: Use-after-free during mouse event handling
  + CVE-2018-5104: Use-after-free during font face manipulation
  + CVE-2018-5105: WebExtensions can save and execute files on local file system without user prompts
  + CVE-2018-5106: Developer Tools can expose style editor information cross-origin through service worker
  + CVE-2018-5107: Printing process will follow symlinks for local file access
  + CVE-2018-5108: Manually entered blob URL can be accessed by subsequent private browsing tabs
  + CVE-2018-5109: Audio capture prompts and starts with incorrect origin attribution
  + CVE-2018-5110: Cursor can be made invisible on OS X
  + CVE-2018-5111: URL spoofing in addressbar through drag and drop
  + CVE-2018-5112: Extension development tools panel can open a non-relative URL in the panel
  + CVE-2018-5113: WebExtensions can load non-HTTPS pages with browser.identity.launchWebAuthFlow
  + CVE-2018-5114: The old value of a cookie changed to HttpOnly remains accessible to scripts
  + CVE-2018-5115: Background network requests can open HTTP authentication in unrelated foreground tabs
  + CVE-2018-5116: WebExtension ActiveTab permission allows cross-origin frame content access
  + CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right
  + CVE-2018-5118: Activity Stream images can attempt to load local content through file:
  + CVE-2018-5119: Reader view will load cross-origin content in violation of CORS headers
  + CVE-2018-5121: OS X Tibetan characters render incompletely in the addressbar
  + CVE-2018-5122: Potential integer overflow in DoCrypt
  + CVE-2018-5090: Memory safety bugs fixed in Firefox 58
  + CVE-2018-5089: Memory safety bugs fixed in Firefox 58 and Firefox ESR 52.6
  + CVE-2018-5124: Sanitize HTML fragments created for chrome-privileged documents
Jan. 10, 2018 Andrey Cherepanov 57.0.4-alt0.M80P.1
- Backport new version to p8 branch