Пакет firefox: Информация

Исходный пакет: firefox
Версия: 64.0-alt1
Собран:  26 декабря 2018 г. 2:18 в задании #218259
Категория: Сети/WWW
Сообщить об ошибке в пакете
Домашняя страница: http://www.mozilla.org/projects/firefox/

Лицензия: MPL/GPL/LGPL
О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Описание: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

Список rpm-пакетов, предоставляемых данным srpm-пакетом:
firefox (x86_64, i586, aarch64)
firefox-debuginfo (x86_64, i586, aarch64)
rpm-build-firefox (noarch)

Сопровождающий: Alexey Gladkov

Список участников:
Alexey Gladkov
Ivan Zakharyaschev
Konstantin Lepikhov

    1. libalsa-devel
    2. libvpx-devel
    3. libcurl-devel
    4. /dev/shm
    5. python3-base
    6. libwireless-devel
    7. libdbus-devel
    8. libdbus-glib-devel
    9. libshell
    10. alternatives
    11. libevent-devel
    12. autoconf_2.13
    13. autoconf_2.13
    14. /proc
    15. pkgconfig(nspr) >= 4.20
    16. pkgconfig(nss) >= 3.40.0
    17. libffi-devel
    18. libstartup-notification-devel
    19. libstdc++-devel
    20. lld-devel
    21. libfreetype-devel
    22. llvm6.0-devel
    23. rust >= 1.24.1
    24. rust-cargo >= 0.25.0
    25. browser-plugins-npapi-devel
    26. bzlib-devel
    27. chrpath
    28. clang6.0
    29. clang6.0-devel
    30. python-module-distribute
    31. python-module-pip
    32. mozilla-common-devel
    33. libnotify-devel
    34. libnss-devel-static
    35. python-modules-compiler
    36. python-modules-json
    37. rpm-build-mozilla.org
    38. libgio-devel
    39. python-modules-logging
    40. rpm-macros-alternatives
    41. python-modules-sqlite3
    42. node
    43. libGL-devel
    44. gst-plugins1.0-devel
    45. gstreamer1.0-devel
    46. libopus-devel
    47. unzip
    48. fontconfig-devel
    49. libpixman-devel
    50. xorg-cf-files
    51. yasm
    52. libgtk+2-devel
    53. libgtk+3-devel
    54. zip
    55. zlib-devel
    56. libXcomposite-devel
    57. libXcursor-devel
    58. libXft-devel
    59. libXdamage-devel
    60. libXi-devel
    61. libX11-devel
    62. libXext-devel
    63. libXScrnSaver-devel
    64. libhunspell-devel
    65. libproxy-devel
    66. libXt-devel
    67. libpulseaudio-devel
    68. libjpeg-devel
    69. libcairo-devel

Последнее изменение


20 декабря 2018 г. Alexey Gladkov 64.0-alt1
- New release (64.0).
- Fixed:
  + CVE-2018-12407: Buffer overflow with ANGLE library when using VertexBuffer11 module
  + CVE-2018-17466: Buffer overflow and out-of-bounds read in ANGLE library with TextureStorage11
  + CVE-2018-18492: Use-after-free with select element
  + CVE-2018-18493: Buffer overflow in accelerated 2D canvas with Skia
  + CVE-2018-18494: Same-origin policy violation using location attribute and performance.getEntries to steal cross-origin URLs
  + CVE-2018-18495: WebExtension content scripts can be loaded in about: pages
  + CVE-2018-18496: Embedded feed preview page can be abused for clickjacking
  + CVE-2018-18497: WebExtensions can load arbitrary URLs through pipe separators
  + CVE-2018-18498: Integer overflow when calculating buffer sizes for images
  + CVE-2018-12406: Memory safety bugs fixed in Firefox 64
  + CVE-2018-12405: Memory safety bugs fixed in Firefox 64 and Firefox ESR 60.4
23 ноября 2018 г. Alexey Gladkov 63.0.3-alt1
- New release (63.0.3).
13 ноября 2018 г. Alexey Gladkov 63.0.1-alt1
- New release (63.0.1).
- Fixed:
  + CVE-2018-12391: HTTP Live Stream audio data is accessible cross-origin
  + CVE-2018-12392: Crash with nested event loops
  + CVE-2018-12393: Integer overflow during Unicode conversion while loading JavaScript
  + CVE-2018-12395: WebExtension bypass of domain restrictions through header rewriting
  + CVE-2018-12396: WebExtension content scripts can execute in disallowed contexts
  + CVE-2018-12397: Missing warning prompt when WebExtension requests local file access
  + CVE-2018-12398: CSP bypass through stylesheet injection in resource URIs
  + CVE-2018-12399: Spoofing of protocol registration notification bar
  + CVE-2018-12400: Favicons are cached in private browsing mode on Firefox for Android
  + CVE-2018-12401: DOS attack through special resource URI parsing
  + CVE-2018-12402: SameSite cookies leak when pages are explicitly saved
  + CVE-2018-12403: Mixed content warning is not displayed when HTTPS page loads a favicon over HTTP
  + CVE-2018-12388: Memory safety bugs fixed in Firefox 63
  + CVE-2018-12390: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3