Package firefox-esr: Information

Source package: firefox-esr
Version: 115.8.0-alt1
Latest version according to Repology
Build time:  Feb 22, 2024, 04:26 PM in the task #341225
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox-esr (x86_64, i586, armh, aarch64)
firefox-esr-config-privacy (x86_64, i586, armh, aarch64)
firefox-esr-debuginfo (x86_64, i586, armh, aarch64)
firefox-esr-wayland (x86_64, i586, armh, aarch64)

Maintainer: Andrey Cherepanov



    1. /dev/shm
    2. /proc
    3. alternatives
    4. autoconf_2.13
    5. autoconf_2.13
    6. browser-plugins-npapi-devel
    7. bzlib-devel
    8. chrpath
    9. clang15.0
    10. clang15.0-devel
    11. fontconfig-devel
    12. glibc-kernheaders-generic
    13. gst-plugins1.0-devel
    14. gstreamer1.0-devel
    15. libGL-devel
    16. libX11-devel
    17. libXScrnSaver-devel
    18. libXcomposite-devel
    19. libXcursor-devel
    20. libXdamage-devel
    21. libXext-devel
    22. libXft-devel
    23. libXi-devel
    24. libXt-devel
    25. libalsa-devel
    26. libaom-devel
    27. libcairo-devel
    28. libnotify-devel
    29. libnss-devel-static
    30. python3(click)
    31. python3(curses)
    32. rust >= 1.65.0
    33. libopus-devel
    34. rpm-build-mozilla.org
    35. rust-cargo >= 1.65.0
    36. libcurl-devel
    37. libdav1d-devel
    38. rpm-macros-alternatives
    39. python3(setuptools)
    40. python3(hamcrest)
    41. python3(imp)
    42. python3(sqlite3)
    43. libpixman-devel
    44. unzip
    45. libproxy-devel
    46. xorg-cf-files
    47. yasm
    48. zip
    49. zlib-devel
    50. libpulseaudio-devel
    51. python3-base
    52. libdbus-devel
    53. libdbus-glib-devel
    54. libdrm-devel
    55. python3(pip)
    56. libshell
    57. libevent-devel
    58. libffi-devel
    59. libstartup-notification-devel
    60. libstdc++-devel
    61. libfreetype-devel
    62. libwireless-devel
    63. libxkbcommon-devel
    64. libgio-devel
    65. lld15.0-devel
    66. llvm15.0-devel
    67. libvpx-devel
    68. mozilla-common-devel
    69. nasm
    70. node
    71. pkgconfig(alsa)
    72. pkgconfig(aom)
    73. pkgconfig(bzip2)
    74. pkgconfig(cairo)
    75. pkgconfig(dav1d)
    76. pkgconfig(dbus-1)
    77. pkgconfig(dbus-glib-1)
    78. pkgconfig(dri)
    79. pkgconfig(fontconfig)
    80. pkgconfig(freetype2)
    81. pkgconfig(gio-2.0)
    82. pkgconfig(graphite2)
    83. pkgconfig(gtk+-2.0)
    84. pkgconfig(gtk+-3.0)
    85. pkgconfig(harfbuzz)
    86. pkgconfig(hunspell)
    87. pkgconfig(icu-i18n)
    88. pkgconfig(libcurl)
    89. pkgconfig(libdrm)
    90. pkgconfig(libevent)
    91. pkgconfig(libffi)
    92. pkgconfig(libjpeg)
    93. pkgconfig(libnotify)
    94. pkgconfig(libproxy-1.0)
    95. pkgconfig(libpulse)
    96. pkgconfig(libstartup-notification-1.0)
    97. pkgconfig(nspr) >= 4.35
    98. pkgconfig(nss) >= 3.86
    99. pkgconfig(opus)
    100. pkgconfig(pixman-1)
    101. pkgconfig(vpx)
    102. pkgconfig(x11)
    103. pkgconfig(xcomposite)
    104. pkgconfig(xcursor)
    105. pkgconfig(xdamage)
    106. pkgconfig(xext)
    107. pkgconfig(xft)
    108. pkgconfig(xi)
    109. pkgconfig(xkbcommon)
    110. pkgconfig(xrandr)
    111. pkgconfig(xscrnsaver)
    112. pkgconfig(xt)
    113. pkgconfig(xtst)
    114. pkgconfig(zlib)
    115. libgtk+2-devel
    116. libgtk+3-devel
    117. libhunspell-devel
    118. libjpeg-devel

Last changed


Feb. 21, 2024 Pavel Vasenkov 115.8.0-alt1
- New ESR version.
- Security fixes
  + CVE-2024-1546 Out-of-bounds memory read in networking channels
  + CVE-2024-1547 Alert dialog could have been spoofed on another site
  + CVE-2024-1548 Fullscreen Notification could have been hidden by select element
  + CVE-2024-1549 Custom cursor could obscure the permission dialog
  + CVE-2024-1550 Mouse cursor re-positioned unexpectedly could have led to unintended permission grants
  + CVE-2024-1551 Multipart HTTP Responses would accept the Set-Cookie header in response parts
  + CVE-2024-1552 Incorrect code generation on 32-bit ARM devices
  + CVE-2024-1553 Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8
Feb. 6, 2024 Alexey Sheplyakov 115.7.0-alt2
- Reverted malicious upstream commit
  https://hg.mozilla.org/integration/autoland/rev/a03a9c72d1db3716adffc6968cfb6eb43c6fcd74
  which forces firefox to autoremove yandex, mail.ru, vk search extensions.
  Note: reverting that (and some similar) commit is a necessary condition to
  make firefox obey the search engine settings specified in policies.json.
  Alas it might be not enough. The problem is that firefox is tightly
  integrated with services provided by Mozilla corporation, such as bookmark
  sync, telemetry, captive portal detection, you name it. Reportedly a similar
  malware has been deployed there, thus yandex search extension (or in fact any
  extension) can be removed remotely (that is, without user consent) if the user
  is signed in into mozilla account, sends telemetry data to mozilla, etc.
  Perhaps it's time to make unmozilla firefox (similarly to ungoogled chromium).
- policies.json: use yandex search by default (Closes: #43516).
Feb. 4, 2024 Pavel Vasenkov 115.7.0-alt1
- New ESR version.
- Security fixes
  + CVE-2024-0741 Out of bounds write in ANGLE
  + CVE-2024-0742 Failure to update user input timestamp
  + CVE-2024-0746 Crash when listing printers on Linux
  + CVE-2024-0747 Bypass of Content Security Policy when directive unsafe-inline was set
  + CVE-2024-0749 Phishing site popup could show local origin in address bar
  + CVE-2024-0750 Potential permissions request bypass via clickjacking
  + CVE-2024-0751 Privilege escalation through devtools
  + CVE-2024-0753 HSTS policy on subdomain could bypass policy of upper domain
  + CVE-2024-0755 Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7