Package firefox: Information

Source package: firefox
Version: 58.0.2-alt1
Build time:  Feb 12, 2018, 11:31 PM in the task #200448
Category: Networking/WWW
Report package bug
License: MPL/GPL/LGPL
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox (x86_64, i586)
firefox-debuginfo (x86_64, i586)
rpm-build-firefox (noarch)

Maintainer: Alexey Gladkov


    1. fontconfig-devel
    2. libcairo-devel
    3. libjpeg-devel
    4. libX11-devel
    5. libXScrnSaver-devel
    6. /dev/shm
    7. libXcomposite-devel
    8. libpulseaudio-devel
    9. libXdamage-devel
    10. libXext-devel
    11. libXft-devel
    12. gcc-c++
    13. libXt-devel
    14. libcurl-devel
    15. libvpx-devel
    16. libdbus-devel
    17. libdbus-glib-devel
    18. libalsa-devel
    19. libwireless-devel
    20. /proc
    21. libevent-devel
    22. libshell
    23. libffi-devel
    24. rust
    25. libfreetype-devel
    26. rust-cargo
    27. alternatives
    28. llvm4.0
    29. llvm4.0-devel
    30. llvm4.0-libs
    31. autoconf_2.13
    32. autoconf_2.13
    33. libstartup-notification-devel
    34. pkgconfig(nspr) >= 4.17
    35. pkgconfig(nss) >= 3.33.0
    36. mozilla-common-devel
    37. libgio-devel
    38. browser-plugins-npapi-devel
    39. bzlib-devel
    40. chrpath
    41. rpm-build-mozilla.org
    42. clang4.0
    43. clang4.0-devel
    44. rpm-macros-alternatives
    45. libnotify-devel
    46. libnss-devel-static
    47. python-module-distribute
    48. unzip
    49. libGL-devel
    50. python-module-pip
    51. libopus-devel
    52. libgtk+2-devel
    53. libgtk+3-devel
    54. python-modules-compiler
    55. python-modules-json
    56. python-modules-logging
    57. xorg-cf-files
    58. python-modules-sqlite3
    59. yasm
    60. gst-plugins1.0-devel
    61. libhunspell-devel
    62. gstreamer1.0-devel
    63. zip
    64. zlib-devel
    65. libpixman-devel
    66. libproxy-devel

Last changed


Feb. 11, 2018 Alexey Gladkov 58.0.2-alt1
- New release (58.0.2).
- Fixed:
  + CVE-2018-5091: Use-after-free with DTMF timers
  + CVE-2018-5092: Use-after-free in Web Workers
  + CVE-2018-5093: Buffer overflow in WebAssembly during Memory/Table resizing
  + CVE-2018-5094: Buffer overflow in WebAssembly with garbage collection on uninitialized memory
  + CVE-2018-5095: Integer overflow in Skia library during edge builder allocation
  + CVE-2018-5097: Use-after-free when source document is manipulated during XSLT
  + CVE-2018-5098: Use-after-free while manipulating form input elements
  + CVE-2018-5099: Use-after-free with widget listener
  + CVE-2018-5100: Use-after-free when IsPotentiallyScrollable arguments are freed from memory
  + CVE-2018-5101: Use-after-free with floating first-letter style elements
  + CVE-2018-5102: Use-after-free in HTML media elements
  + CVE-2018-5103: Use-after-free during mouse event handling
  + CVE-2018-5104: Use-after-free during font face manipulation
  + CVE-2018-5105: WebExtensions can save and execute files on local file system without user prompts
  + CVE-2018-5106: Developer Tools can expose style editor information cross-origin through service worker
  + CVE-2018-5107: Printing process will follow symlinks for local file access
  + CVE-2018-5108: Manually entered blob URL can be accessed by subsequent private browsing tabs
  + CVE-2018-5109: Audio capture prompts and starts with incorrect origin attribution
  + CVE-2018-5110: Cursor can be made invisible on OS X
  + CVE-2018-5111: URL spoofing in addressbar through drag and drop
  + CVE-2018-5112: Extension development tools panel can open a non-relative URL in the panel
  + CVE-2018-5113: WebExtensions can load non-HTTPS pages with browser.identity.launchWebAuthFlow
  + CVE-2018-5114: The old value of a cookie changed to HttpOnly remains accessible to scripts
  + CVE-2018-5115: Background network requests can open HTTP authentication in unrelated foreground tabs
  + CVE-2018-5116: WebExtension ActiveTab permission allows cross-origin frame content access
  + CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right
  + CVE-2018-5118: Activity Stream images can attempt to load local content through file:
  + CVE-2018-5119: Reader view will load cross-origin content in violation of CORS headers
  + CVE-2018-5121: OS X Tibetan characters render incompletely in the addressbar
  + CVE-2018-5122: Potential integer overflow in DoCrypt
  + CVE-2018-5090: Memory safety bugs fixed in Firefox 58
  + CVE-2018-5089: Memory safety bugs fixed in Firefox 58 and Firefox ESR 52.6
  + CVE-2018-5124: Sanitize HTML fragments created for chrome-privileged documents
Jan. 6, 2018 Alexey Gladkov 57.0.4-alt1
- New release (57.0.4).
- Fixed:
  + Speculative execution side-channel attack ("Spectre")
  + CVE-2017-7845: Buffer overflow when drawing and validating elements with ANGLE library using Direct 3D 9
Dec. 8, 2017 Alexey Gladkov 57.0.1-alt2
- Enable dbus support (ALT#34275).
- Change chrome packaging format to omni (ALT#34285).