Package firefox: Information
Default inline alert: Version in the repository: 136.0.2-alt1
Source package: firefox
Version: 136.0-alt1
Build time: Mar 11, 2025, 08:02 PM in the task #376916
Category: Networking/WWW
Report package bugHome page: https://www.mozilla.org/firefox/
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
List of RPM packages built from this SRPM:
firefox (x86_64, i586, aarch64)
firefox-config-privacy (x86_64, i586, aarch64)
firefox-debuginfo (x86_64, i586, aarch64)
firefox (x86_64, i586, aarch64)
firefox-config-privacy (x86_64, i586, aarch64)
firefox-debuginfo (x86_64, i586, aarch64)
Maintainer: Ajrat Makhmutov
List of contributors:
Ajrat Makhmutov
Alexey Gladkov
Sergey Bolshakov
Gleb Fotengauer-Malinovskiy
Ivan Zakharyaschev
Konstantin Lepikhov
Ajrat Makhmutov
Alexey Gladkov
Sergey Bolshakov
Gleb Fotengauer-Malinovskiy
Ivan Zakharyaschev
Konstantin Lepikhov
Last changed
March 11, 2025 Ajrat Makhmutov 136.0-alt1
- New version (136.0). - Security fixes: + CVE-2025-1930: AudioIPC StreamData could trigger a use-after-free in the Browser process + CVE-2025-1939: Tapjacking in Android Custom Tabs using transition animations + CVE-2025-1931: Use-after-free in WebTransportChild + CVE-2025-1932: Inconsistent comparator in XSLT sorting led to out-of-bounds access + CVE-2025-1933: JIT corruption of WASM i32 return values on 64-bit CPUs + CVE-2025-1940: Android Intent confirmation prompt tapjacking using Select options + CVE-2024-9956: Passkey phishing within Bluetooth range + CVE-2025-1934: Unexpected GC during RegExp bailout processing + CVE-2025-1941: Lock screen setting bypass in Firefox Focus for Android + CVE-2025-1942: Disclosure of uninitialized memory when .toUpperCase() causes string to get longer + CVE-2025-1935: Clickjacking the registerProtocolHandler info-bar + CVE-2025-1936: Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents + CVE-2025-1937: Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8 + CVE-2025-1938: Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8 + CVE-2025-1943: Memory safety bugs fixed in Firefox 136 and Thunderbird 136
Feb. 19, 2025 Ajrat Makhmutov 135.0.1-alt1
- New version (135.0.1). - Security fixes: + CVE-2025-1414: Memory safety bugs fixed in Firefox 135.0.1
Feb. 10, 2025 Ajrat Makhmutov 135.0-alt1
- New version (135.0). - Security fixes: + CVE-2025-1009: Use-after-free in XSLT + CVE-2025-1010: Use-after-free in Custom Highlight + CVE-2025-1018: Fullscreen notification is not displayed when fullscreen is re-requested + CVE-2025-1011: A bug in WebAssembly code generation could result in a crash + CVE-2025-1012: Use-after-free during concurrent delazification + CVE-2025-1019: Fullscreen notification not properly displayed + CVE-2025-1013: Potential opening of private browsing tabs in normal browsing windows + CVE-2025-1014: Certificate length was not properly checked + CVE-2025-1016: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7 + CVE-2025-1017: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7 + CVE-2025-1020: Memory safety bugs fixed in Firefox 135 and Thunderbird 135