Сопровождающий Pavel Vasenkov в ветке p10: Информация
Имя сопровождающего: Pavel Vasenkov (pav)
Собрано source пакетов в данной ветке: 13
-
- @ruby
Последние изменения
22 апреля 2026 г. 20:59
#415763 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
20 апреля 2026 г. Pavel Vasenkov:
- Backport new version.
15 апреля 2026 г. 16:48
#414980 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
11 апреля 2026 г. Pavel Vasenkov:
- Backport new version.
1 апреля 2026 г. 17:19
#412433 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
25 марта 2026 г. Pavel Vasenkov:
- Backport new version.
29 декабря 2025 г. 11:46
#403755 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
25 декабря 2025 г. Pavel Vasenkov:
- Backport new version.
16 декабря 2025 г. 11:34
#390652 отправлено Pavel Vasenkov
New_expat_version_with_deps
Быстрая библиотека разбора XML для Erlang на основе Expat
Imath is library of 2D and 3D vector, matrix, and math operations for graphics
19 марта 2025 г. Ivan A. Melnikov:
- NMU:
+ added --without=python knob to avoid dependency on
boost-python e.g. during bootstrap (asheplyakov@);
+ drop python3-module-breathe build dependency that is
relevant only for building docs.Средство синтаксичского анализа XML, написанное на языке C
11 декабря 2025 г. Pavel Vasenkov:
- Fixed: + CVE-2024-8176 Improper restriction of xml entity expansion depth in libexpat.
2 декабря 2025 г. 12:07
#400894 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
24 ноября 2025 г. Pavel Vasenkov:
- Backport new version.
23 ноября 2025 г. 0:17
#400630 отправлено Pavel Vasenkov
New_version
Java library for working with real-world HTML
28 октября 2025 г. Pavel Vasenkov:
- new version
19 ноября 2025 г. 13:36
#396669 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
16 ноября 2025 г. Pavel Vasenkov:
- disable build for armh
12 июля 2025 г. 1:48
#387679 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
21 мая 2025 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2025-4918 Out-of-bounds access when resolving Promise objects + CVE-2025-4919 Out-of-bounds access when optimizing linear sums
20 июня 2025 г. 19:39
#384290 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
30 апреля 2025 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2025-2817 Privilege escalation in Firefox Updater + CVE-2025-4082 WebGL shader attribute memory corruption in Firefox for macOS + CVE-2025-4083 Process isolation bypass using "javascript:" URI links in cross-origin frames + CVE-2025-4084 Potential local code execution in "copy as cURL" command + CVE-2025-4087 Unsafe attribute access during XPath parsing + CVE-2025-4091 Memory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10 + CVE-2025-4093 Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10
5 мая 2025 г. 18:45
#381846 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
29 марта 2025 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2025-2857 Incorrect handle could lead to sandbox escapes
6 марта 2025 г. 16:05
#375522 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
13 февраля 2025 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2025-1009 Use-after-free in XSLT + CVE-2025-1010 Use-after-free in Custom Highlight + CVE-2025-1011 A bug in WebAssembly code generation could result in a crash + CVE-2025-1012 Use-after-free during concurrent delazification + CVE-2024-11704 Potential double-free vulnerability in PKCS#7 decryption handling + CVE-2025-1013 Potential opening of private browsing tabs in normal browsing windows + CVE-2025-1014 Certificate length was not properly checked + CVE-2025-1016 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and + CVE-2025-1017 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7
5 февраля 2025 г. 18:04
#370772 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
9 января 2025 г. Ajrat Makhmutov:
- New ESR version. - Security fixes: + CVE-2025-0237: WebChannel APIs susceptible to confused deputy attack + CVE-2025-0238: Use-after-free when breaking lines in text + CVE-2025-0239: Alt-Svc ALPN validation failure when redirected + CVE-2025-0240: Compartment mismatch when parsing JavaScript JSON module + CVE-2025-0241: Memory corruption when using JavaScript Text Segmentation + CVE-2025-0242: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6 + CVE-2025-0243: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6
13 января 2025 г. 18:10
#366695 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser
21 декабря 2024 г. Ajrat Makhmutov:
- New ESR version. - Fix FTBFS with python 3.12.8.
12 ноября 2024 г. 11:33
#360951 отправлено Pavel Vasenkov
New_ersion_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
28 октября 2024 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2024-5702 Use-after-free in networking + CVE-2024-5688 Use-after-free in JavaScript object transplant + CVE-2024-5690 External protocol handlers leaked by timing attack + CVE-2024-5691 Sandboxed iframes were able to bypass sandbox restrictions to open a new window + CVE-2024-5692 Bypass of file name restrictions during saving + CVE-2024-5693 Cross-Origin Image leak via Offscreen Canvas + CVE-2024-5696 Memory Corruption in Text Fragments + CVE-2024-5700 Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12 + CVE-2024-7652 Type Confusion in Async Generators in Javascript Engine + CVE-2024-6600 Memory corruption in WebGL API + CVE-2024-6601 Race condition in permission assignment + CVE-2024-6602 Memory corruption in NSS + CVE-2024-6603 Memory corruption in thread creation + CVE-2024-6604 Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13 + CVE-2024-7519 Out of bounds memory access in graphics shared memory handling + CVE-2024-7521 Incomplete WebAssembly exception handing + CVE-2024-7522 Out of bounds read in editor component + CVE-2024-7525 Missing permission check when creating a StreamFilter + CVE-2024-7526 Uninitialized memory used by WebGL + CVE-2024-7527 Use-after-free in JavaScript garbage collection + CVE-2024-7529 Document content could partially obscure security prompts + CVE-2024-8381 Type confusion when looking up a property name in a "with" block + CVE-2024-8382 Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran + CVE-2024-8384 Garbage collection could mis-color cross-compartment objects in OOM conditions + CVE-2024-9392 Compromised content process can bypass site isolation + CVE-2024-9393 Cross-origin access to PDF contents through multipart responses + CVE-2024-9394 Cross-origin access to JSON contents through multipart responses + CVE-2024-9401 Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 + CVE-2024-9680 Use-after-free in Animation timeline
2 ноября 2024 г. 17:08
#360964 отправлено Pavel Vasenkov
New_version_with_CVE
Thunderbird is Mozilla's e-mail client
29 октября 2024 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2024-3852 GetBoundName in the JIT returned the wrong object + CVE-2024-3854 Out-of-bounds-read after mis-optimized switch statement + CVE-2024-3857 Incorrect JITting of arguments led to use-after-free during garbage collection + CVE-2024-2609 Permission prompt input delay could expire when not in focus + CVE-2024-3859 Integer-overflow led to out-of-bounds-read in the OpenType sanitizer + CVE-2024-3861 Potential use-after-free due to AlignedBuffer self-move + CVE-2024-3863 Download Protections were bypassed by .xrm-ms files on Windows + CVE-2024-3302 Denial of Service using HTTP/2 CONTINUATION frames + CVE-2024-3864 Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10 + CVE-2024-4367 Arbitrary JavaScript execution in PDF.js + CVE-2024-4767 IndexedDB files retained in private browsing mode + CVE-2024-4768 Potential permissions request bypass via clickjacking + CVE-2024-4769 Cross-origin responses could be distinguished between script and non-script content-types + CVE-2024-4770 Use-after-free could occur when printing to PDF + CVE-2024-4777 Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 + CVE-2024-5702 Use-after-free in networking + CVE-2024-5688 Use-after-free in JavaScript object transplant + CVE-2024-5690 External protocol handlers leaked by timing attack + CVE-2024-5691 Sandboxed iframes were able to bypass sandbox restrictions to open a new window + CVE-2024-5692 Bypass of file name restrictions during saving + CVE-2024-5693 Cross-Origin Image leak via Offscreen Canvas + CVE-2024-5696 Memory Corruption in Text Fragments + CVE-2024-5700 Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12 + CVE-2024-7652 Type Confusion in Async Generators in Javascript Engine + CVE-2024-6600 Memory corruption in WebGL API + CVE-2024-6601 Race condition in permission assignment + CVE-2024-6602 Memory corruption in NSS + CVE-2024-6603 Memory corruption in thread creation + CVE-2024-6604 Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13 + CVE-2024-7519 Out of bounds memory access in graphics shared memory handling + CVE-2024-7521 Incomplete WebAssembly exception handing + CVE-2024-7522 Out of bounds read in editor component + CVE-2024-7525 Missing permission check when creating a StreamFilter + CVE-2024-7526 Uninitialized memory used by WebGL + CVE-2024-7527 Use-after-free in JavaScript garbage collection + CVE-2024-7529 Document content could partially obscure security prompts + CVE-2024-7519 Out of bounds memory access in graphics shared memory handling + CVE-2024-7521 Incomplete WebAssembly exception handing + CVE-2024-7522 Out of bounds read in editor component + CVE-2024-7525 Missing permission check when creating a StreamFilter + CVE-2024-7526 Uninitialized memory used by WebGL + CVE-2024-7527 Use-after-free in JavaScript garbage collection + CVE-2024-7529 Document content could partially obscure security prompts
28 мая 2024 г. 17:57
#348463 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
19 мая 2024 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2024-4367 Arbitrary JavaScript execution in PDF.js + CVE-2024-4767 IndexedDB files retained in private browsing mode + CVE-2024-4768 Potential permissions request bypass via clickjacking + CVE-2024-4769 Cross-origin responses could be distinguished between script and non-script content-types + CVE-2024-4770 Use-after-free could occur when printing to PDF + CVE-2024-4777 Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11
23 апреля 2024 г. 19:08
#345277 отправлено Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
16 апреля 2024 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2024-3852 GetBoundName in the JIT returned the wrong object + CVE-2024-3854 Out-of-bounds-read after mis-optimized switch statement + CVE-2024-3857 Incorrect JITting of arguments led to use-after-free during garbage collection + CVE-2024-2609 Permission prompt input delay could expire when not in focus + CVE-2024-3859 Integer-overflow led to out-of-bounds-read in the OpenType sanitizer + CVE-2024-3861 Potential use-after-free due to AlignedBuffer self-move + CVE-2024-3863 Download Protections were bypassed by .xrm-ms files on Windows + CVE-2024-3302 Denial of Service using HTTP/2 CONTINUATION frames + CVE-2024-3864 Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10
9 апреля 2024 г. 21:23
#344254 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
3 апреля 2024 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2024-0743 Crash in NSS TLS method + CVE-2024-2605 Windows Error Reporter could be used as a Sandbox escape vector + CVE-2024-2607 JIT code failed to save return registers on Armv7-A + CVE-2024-2608 Integer overflow could have led to out of bounds write + CVE-2024-2616 Improve handling of out-of-memory conditions in ICU + CVE-2023-5388 NSS susceptible to timing attack against RSA decryption + CVE-2024-2610 Improper handling of html and body tags enabled CSP nonce leakage + CVE-2024-2611 Clickjacking vulnerability could have led to a user accidentally granting permissions + CVE-2024-2612 Self referencing object could have potentially led to a use-after-free + CVE-2024-2614 Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9 + CVE-2024-29944 Privileged JavaScript Execution via Event Handlers
8 апреля 2024 г. 17:58
#344280 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
3 апреля 2024 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2024-0743 Crash in NSS TLS method + CVE-2024-2605 Windows Error Reporter could be used as a Sandbox escape vector + CVE-2024-2607 JIT code failed to save return registers on Armv7-A + CVE-2024-2608 Integer overflow could have led to out of bounds write + CVE-2024-2616 Improve handling of out-of-memory conditions in ICU + CVE-2023-5388 NSS susceptible to timing attack against RSA decryption + CVE-2024-2610 Improper handling of html and body tags enabled CSP nonce leakage + CVE-2024-2611 Clickjacking vulnerability could have led to a user accidentally granting permissions + CVE-2024-2612 Self referencing object could have potentially led to a use-after-free + CVE-2024-2614 Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9
20 марта 2024 г. 16:32
#342581 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
12 марта 2024 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2024-1936 Leaking of encrypted email subjects to other conversations
14 марта 2024 г. 22:01
#341796 отправлено Pavel Vasenkov
New_version
Security and system auditing tool
1 марта 2024 г. Pavel Vasenkov:
- update new release 3.0.9 (Closed: #49562)
5 марта 2024 г. 20:25
#341263 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
21 февраля 2024 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2024-1546 Out-of-bounds memory read in networking channels + CVE-2024-1547 Alert dialog could have been spoofed on another site + CVE-2024-1548 Fullscreen Notification could have been hidden by select element + CVE-2024-1549 Custom cursor could obscure the permission dialog + CVE-2024-1550 Mouse cursor re-positioned unexpectedly could have led to unintended permission grants + CVE-2024-1551 Multipart HTTP Responses would accept the Set-Cookie header in response parts + CVE-2024-1552 Incorrect code generation on 32-bit ARM devices + CVE-2024-1553 Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8
9 февраля 2024 г. 22:58
#339729 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
4 февраля 2024 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2024-0741 Out of bounds write in ANGLE + CVE-2024-0742 Failure to update user input timestamp + CVE-2024-0746 Crash when listing printers on Linux + CVE-2024-0747 Bypass of Content Security Policy when directive unsafe-inline was set + CVE-2024-0749 Phishing site popup could show local origin in address bar + CVE-2024-0750 Potential permissions request bypass via clickjacking + CVE-2024-0751 Privilege escalation through devtools + CVE-2024-0753 HSTS policy on subdomain could bypass policy of upper domain + CVE-2024-0755 Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7
28 декабря 2023 г. 22:30
#336859 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
20 декабря 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-6856 Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with Mesa VM driver + CVE-2023-6865 Potential exposure of uninitialized data in EncryptingOutputStream + CVE-2023-6857 Symlinks may resolve to smaller than expected buffers + CVE-2023-6858 Heap buffer overflow in nsTextFragment + CVE-2023-6859 Use-after-free in PR_GetIdentitiesLayer + CVE-2023-6860 Potential sandbox escape due to VideoBridge lack of texture validation + CVE-2023-6867 Clickjacking permission prompts using the popup transition + CVE-2023-6861 Heap buffer overflow affected nsWindow::PickerOpen(void) in headless mode + CVE-2023-6862 Use-after-free in nsDNSService + CVE-2023-6863 Undefined behavior in ShutdownObserver() + CVE-2023-6864 Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6
24 ноября 2023 г. 10:17
#334058 отправлено Pavel Vasenkov
new_version
Daemon fo gather statistics about the TCP and UDP packets
AT Computing's System & Process Monitor
22 ноября 2023 г. Leontiy Volodin:
- Fix version (ALT #48545)
14 ноября 2023 г. 19:08
#333444 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
2 ноября 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-5721 Queued up rendering could have allowed websites to clickjack + CVE-2023-5732 Address bar spoofing via bidirectional characters + CVE-2023-5724 Large WebGL draw could have led to a crash + CVE-2023-5725 WebExtensions could open arbitrary URLs + CVE-2023-5726 Full screen notification obscured by file open dialog on macOS + CVE-2023-5727 Download Protections were bypassed by .msix, .msixbundle, .appx, and .appxbundle files on Windows + CVE-2023-5728 Improper object tracking during GC in the JavaScript engine could have led to a crash. + CVE-2023-5730 Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4.1
19 октября 2023 г. 17:37
#330014 отправлено Pavel Vasenkov
New_version
E-book reader application
GUI prototyping tool
18 сентября 2023 г. Pavel Vasenkov:
- ExcludeArch: i386 i486 i586 i686 i786 i886 i986 pentium2 pentium3 pentium4 k6 athlon athlon_xp ppc64le
configure firefox for a livecd environment
18 сентября 2023 г. Pavel Vasenkov:
- ExcludeArch: i386 i486 i586 i686 i786 i886 i986 pentium2 pentium3 pentium4 k6 athlon athlon_xp ppc64le
start the browser for a suitable webkiosk environment
19 сентября 2023 г. Pavel Vasenkov:
- ExcludeArch: i386 i486 i586 i686 i786 i886 i986 pentium2 pentium3 pentium4 k6 athlon athlon_xp ppc64le
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
16 октября 2023 г. Pavel Vasenkov:
- Fix check dependencies error for GLIBC_PRIVATE
28 сентября 2023 г. 13:24
#330025 отправлено Pavel Vasenkov
New_version
Netscape Network Security Services(NSS)
31 июля 2023 г. Alexey Gladkov:
- New version (3.92). - Certificate Authority Changes: + Add CN=Atos TrustedRoot Root CA ECC G2 2020 + Add CN=Atos TrustedRoot Root CA RSA G2 2020 + Add CN=LAWtrust Root CA2 (4096) + Add CN=SSL.com Client ECC Root CA 2022 + Add CN=SSL.com Client RSA Root CA 2022 + Add CN=SSL.com TLS ECC Root CA 2022 + Add CN=SSL.com TLS RSA Root CA 2022 + Add CN=Sectigo Public Email Protection Root E46 + Add CN=Sectigo Public Email Protection Root R46 + Add CN=Sectigo Public Server Authentication Root E46 + Add CN=Sectigo Public Server Authentication Root R46 + Remove CN=Chambers of Commerce Root,OU=http://www.chambersign.org + Remove CN=E-Tugra Certification Authority,OU=E-Tugra Sertifikasyon Merkezi + Remove CN=E-Tugra Global Root CA ECC v3,OU=E-Tugra Trust Center + Remove CN=E-Tugra Global Root CA RSA v3,OU=E-Tugra Trust Center + Remove CN=Hongkong Post Root CA 1
21 июля 2023 г. 15:16
#324723 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
27 июня 2023 г. Pavel Vasenkov:
- Fixes: Unstable name collisions
Build failure with GCC 1321 июня 2023 г. 13:17
#322595 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
7 июня 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-34414 Click-jacking certificate exceptions through rendering lag + CVE-2023-34416 Memory safety bugs fixed in Firefox 114 and Firefox ESR 102.12
6 июня 2023 г. 20:00
#321602 отправлено Pavel Vasenkov
New_build
System call fuzz tester
19 мая 2023 г. Pavel Vasenkov:
- Fix removing depricated i810 definations
26 мая 2023 г. 22:27
#321098 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
17 мая 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-32205 Browser prompts could have been obscured by popups + CVE-2023-32206 Crash in RLBox Expat driver + CVE-2023-32207 Potential permissions request bypass via clickjacking + CVE-2023-32211 Content process crash due to invalid wasm code + CVE-2023-32212 Potential spoof due to obscured address bar + CVE-2023-32213 Potential memory corruption in FileReader::DoReadData() + CVE-2023-32214 Potential DoS via exposed protocol handlers + CVE-2023-32215 Memory safety bugs fixed in Thunderbird 102.11
24 мая 2023 г. 19:08
#320576 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
15 мая 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-32205 Browser prompts could have been obscured by popups + CVE-2023-32206 Crash in RLBox Expat driver + CVE-2023-32207 Potential permissions request bypass via clickjacking + CVE-2023-32211 Content process crash due to invalid wasm code + CVE-2023-32212 Potential spoof due to obscured address bar + CVE-2023-32213 Potential memory corruption in FileReader::DoReadData() + CVE-2023-32214 Potential DoS via exposed protocol handlers + CVE-2023-32215 Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
12 мая 2023 г. 21:41
#319671 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
19 апреля 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-29531 Out-of-bound memory access in WebGL on macOS + CVE-2023-29532 Mozilla Maintenance Service Write-lock bypass + CVE-2023-29533 Fullscreen notification obscured + CVE-2023-1999 Double-free in libwebp + CVE-2023-29535 Potential Memory Corruption following Garbage Collector compaction + CVE-2023-29536 Invalid free from JavaScript code + CVE-2023-29539 Content-Disposition filename truncation leads to Reflected File Download + CVE-2023-29541 Files with malicious extensions could have been downloaded unsafely on Linux + CVE-2023-29542 Bypass of file download extension restrictions + CVE-2023-29545 Windows Save As dialog resolved environment variables + CVE-2023-1945 Memory Corruption in Safe Browsing Code + CVE-2023-29548 Incorrect optimization result on ARM64 + CVE-2023-29550 Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10
11 мая 2023 г. 11:00
#319782 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
19 апреля 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-29531 Out-of-bound memory access in WebGL on macOS + CVE-2023-29532 Mozilla Maintenance Service Write-lock bypass + CVE-2023-29533 Fullscreen notification obscured + CVE-2023-1999 Double-free in libwebp + CVE-2023-29535 Potential Memory Corruption following Garbage Collector compaction + CVE-2023-29536 Invalid free from JavaScript code + CVE-2023-0547 Revocation status of S/Mime recipient certificates was not checked + CVE-2023-29479 Hang when processing certain OpenPGP messages + CVE-2023-29539 Content-Disposition filename truncation leads to Reflected File Download + CVE-2023-29541 Files with malicious extensions could have been downloaded unsafely on Linux + CVE-2023-29542 Bypass of file download extension restrictions + CVE-2023-29545 Windows Save As dialog resolved environment variables + CVE-2023-1945 Memory Corruption in Safe Browsing Code + CVE-2023-29548 Incorrect optimization result on ARM64 + CVE-2023-29550 Memory safety bugs fixed in Thunderbird 102.10
31 марта 2023 г. 13:55
#317236 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
22 марта 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-25751 Incorrect code generation during JIT compilation + CVE-2023-28164 URL being dragged from a removed cross-origin iframe into the same tab triggered navigation + CVE-2023-28162 Invalid downcast in Worklets + CVE-2023-25752 Potential out-of-bounds when accessing throttled streams + CVE-2023-28163 Windows Save As dialog resolved environment variables + CVE-2023-28176 Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9
31 марта 2023 г. 13:13
#317237 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
22 марта 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-25751 Incorrect code generation during JIT compilation + CVE-2023-28164 URL being dragged from a removed cross-origin iframe into the same tab triggered navigation + CVE-2023-28162 Invalid downcast in Worklets + CVE-2023-25752 Potential out-of-bounds when accessing throttled streams + CVE-2023-28163 Windows Save As dialog resolved environment variables + CVE-2023-28176 Memory safety bugs fixed in Thunderbird 102.9
15 марта 2023 г. 2:19
#316239 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
3 марта 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-25728 Content security policy leak in violation reports using iframes + CVE-2023-25730 Screen hijack via browser fullscreen mode + CVE-2023-0767 Arbitrary memory write via PKCS 12 in NSS + CVE-2023-25735 Potential use-after-free from compartment mismatch in SpiderMonkey + CVE-2023-25737 Invalid downcast in SVGUtils::SetupStrokeGeometry + CVE-2023-25738 Printing on Windows could potentially crash Firefox with some device drivers + CVE-2023-25739 Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext + CVE-2023-25729 Extensions could have opened external schemes without user knowledge + CVE-2023-25732 Out of bounds memory write from EncodeInputStream + CVE-2023-25734 Opening local .url files could cause unexpected network loads + CVE-2023-25742 Web Crypto ImportKey crashes tab + CVE-2023-25744 Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 + CVE-2023-25746 Memory safety bugs fixed in Firefox ESR 102.8
10 марта 2023 г. 22:14
#316084 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
28 февраля 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-0616 User Interface lockup with messages combining S/MIME and OpenPGP + CVE-2023-25728 Content security policy leak in violation reports using iframes + CVE-2023-25730 Screen hijack via browser fullscreen mode + CVE-2023-0767 Arbitrary memory write via PKCS 12 in NSS + CVE-2023-25735 Potential use-after-free from compartment mismatch in SpiderMonkey + CVE-2023-25737 Invalid downcast in SVGUtils::SetupStrokeGeometry + CVE-2023-25738 Printing on Windows could potentially crash Thunderbird with some device drivers + CVE-2023-25739 Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext + CVE-2023-25729 Extensions could have opened external schemes without user knowledge + CVE-2023-25732 Out of bounds memory write from EncodeInputStream + CVE-2023-25734 Opening local .url files could cause unexpected network loads + CVE-2023-25742 Web Crypto ImportKey crashes tab + CVE-2023-25746 Memory safety bugs fixed in Thunderbird 102.8
21 февраля 2023 г. 13:07
#315243 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
18 января 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2022-46871 libusrsctp library out of date + CVE-2023-23598 Arbitrary file read from GTK drag and drop on Linux + CVE-2023-23599 Malicious command could be hidden in devtools output on Windows + CVE-2023-23601 URL being dragged from cross-origin iframe into same tab triggers navigation + CVE-2023-23602 Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers + CVE-2022-46877 Fullscreen notification bypass + CVE-2023-23603 Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive + CVE-2023-23605 Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
9 февраля 2023 г. 16:21
#314605 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
3 февраля 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-0430 Revocation status of S/Mime signature certificates was not checked
26 января 2023 г. 23:43
#314033 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
24 января 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-46871 libusrsctp library out of date + CVE-2023-23598 Arbitrary file read from GTK drag and drop on Linux + CVE-2023-23599 Malicious command could be hidden in devtools output on Windows + CVE-2023-23601 URL being dragged from cross-origin iframe into same tab triggers navigation + CVE-2023-23602 Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers + CVE-2022-46877 Fullscreen notification bypass + CVE-2023-23603 Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive + CVE-2023-23605 Memory safety bugs fixed in Thunderbird 102.7
11 января 2023 г. 18:57
#312449 отправлено Pavel Vasenkov
New_build
System call fuzz tester
24 декабря 2022 г. Pavel Vasenkov:
- Update from upstream - Fix missed header file - Update source url(Closes: #40516)
29 декабря 2022 г. 15:09
#312281 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
23 декабря 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions
23 декабря 2022 г. 15:11
#311857 отправлено Pavel Vasenkov
New_version
Thunderbird is Mozilla's e-mail client
16 декабря 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-46880 Use-after-free in WebGL + CVE-2022-46872 Arbitrary file read from a compromised content process + CVE-2022-46881 Memory corruption in WebGL + CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions + CVE-2022-46875 Download Protections were bypassed by .atloc and .ftploc files on Mac OS + CVE-2022-46882 Use-after-free in WebGL + CVE-2022-46878 Memory safety bugs fixed in Thunderbird 102.6
22 декабря 2022 г. 20:26
#311776 отправлено Pavel Vasenkov
New_version
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
14 декабря 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2022-46880 Use-after-free in WebGL + CVE-2022-46872 Arbitrary file read from a compromised content process + CVE-2022-46881 Memory corruption in WebGL + CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions + CVE-2022-46875 Download Protections were bypassed by .atloc and .ftploc files on Mac OS + CVE-2022-46882 Use-after-free in WebGL + CVE-2022-46878 Memory safety bugs fixed in Firefox 108 and Firefox ESR 102.6
14 декабря 2022 г. 23:16
#311456 отправлено Pavel Vasenkov
bug_fixed
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
9 декабря 2022 г. Pavel Vasenkov:
- Build with llvm-version 12 instead llvm-version 13 (Closes: #44436)
13 декабря 2022 г. 20:11
#311239 отправлено Pavel Vasenkov
new_version
Thunderbird is Mozilla's e-mail client
5 декабря 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-45414 Quoting from an HTML email with certain tags will trigger network requests and load remote content, regardless of a configuration