Package firefox-esr-wayland: Information

  • Default inline alert: A new version of the package has been build

    Task #: #323806
    Build time: Jun 30, 2023, 10:42 PM
    New version: 102.12.0-alt2
Binary package: firefox-esr-wayland
Version: 91.11.0-alt1
Architecture: ppc64le
Build time:  Jun 29, 2022, 08:04 PM in the task #302834
Source package: firefox-esr
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: Firefox Wayland launcher.
Description: 
The firefox-wayland package contains launcher and desktop file
to run Firefox natively on Wayland.

Maintainer: Andrey Cherepanov


Last changed


June 29, 2022 Pavel Vasenkov 91.11.0-alt1
- New ESR version.
- Security fixes:
  + CVE-2022-34479 A popup window could be resized in a way to overlay the address bar with web content
  + CVE-2022-34470 Use-after-free in nsSHistory
  + CVE-2022-34468 CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI
  + CVE-2022-34481 Potential integer overflow in ReplaceElementsAt
  + CVE-2022-31744 CSP bypass enabling stylesheet injection
  + CVE-2022-34472 Unavailable PAC file resulted in OCSP requests being blocked
  + CVE-2022-34478 Microsoft protocols can be attacked if a user accepts a prompt
  + CVE-2022-2200 Undesired attributes could be set as part of prototype pollution
  + CVE-2022-34484 Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11
June 3, 2022 Pavel Vasenkov 91.10.0-alt1
- New ESR version.
- Security fixes:
  + CVE-2022-31736 Cross-Origin resource's length leaked
  + CVE-2022-31737 Heap buffer overflow in WebGL
  + CVE-2022-31738 Browser window spoof using fullscreen mode
  + CVE-2022-31739 Attacker-influenced path traversal when saving downloaded files
  + CVE-2022-31740 Register allocation problem in WASM on arm64
  + CVE-2022-31741 Uninitialized variable leads to invalid memory read
  + CVE-2022-31742 Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information
  + CVE-2022-31747 Memory safety bugs fixed in Firefox 101 and Firefox ESR 91.10
May 22, 2022 Pavel Vasenkov 91.9.1-alt1
- New ESR version.
- Security fixes:
  + CVE-2022-1802 Prototype pollution in Top-Level Await implementation
  + CVE-2022-1529 Untrusted input used in JavaScript object indexing, leading to prototype pollution