Пакет firefox: Информация

Исходный пакет: firefox
Версия: 64.0-alt1
Собран:  26 декабря 2018 г. 2:18 в задании #218259
Категория: Сети/WWW
Сообщить об ошибке в пакете
Домашняя страница: http://www.mozilla.org/projects/firefox/

Лицензия: MPL/GPL/LGPL
О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
Описание: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

Список rpm-пакетов, предоставляемых данным srpm-пакетом:
firefox (x86_64, i586, aarch64)
firefox-debuginfo (x86_64, i586, aarch64)
rpm-build-firefox (noarch)

Сопровождающий: Alexey Gladkov

Список участников:
Alexey Gladkov
Ivan Zakharyaschev
Konstantin Lepikhov

    1. libalsa-devel
    2. libvpx-devel
    3. libcurl-devel
    4. python3-base
    5. libdbus-devel
    6. libdbus-glib-devel
    7. libshell
    8. /dev/shm
    9. alternatives
    10. libwireless-devel
    11. autoconf_2.13
    12. libevent-devel
    13. autoconf_2.13
    14. libstartup-notification-devel
    15. libstdc++-devel
    16. libffi-devel
    17. rust >= 1.24.1
    18. libfreetype-devel
    19. pkgconfig(nspr) >= 4.20
    20. rust-cargo >= 0.25.0
    21. pkgconfig(nss) >= 3.40.0
    22. browser-plugins-npapi-devel
    23. bzlib-devel
    24. chrpath
    25. /proc
    26. clang6.0
    27. clang6.0-devel
    28. libnotify-devel
    29. python-module-distribute
    30. libnss-devel-static
    31. lld-devel
    32. llvm6.0-devel
    33. libgio-devel
    34. python-module-pip
    35. rpm-build-mozilla.org
    36. rpm-macros-alternatives
    37. libGL-devel
    38. gst-plugins1.0-devel
    39. python-modules-compiler
    40. gstreamer1.0-devel
    41. python-modules-json
    42. python-modules-logging
    43. python-modules-sqlite3
    44. unzip
    45. libopus-devel
    46. libcairo-devel
    47. xorg-cf-files
    48. libpixman-devel
    49. mozilla-common-devel
    50. libgtk+2-devel
    51. libgtk+3-devel
    52. libhunspell-devel
    53. yasm
    54. zip
    55. fontconfig-devel
    56. zlib-devel
    57. libjpeg-devel
    58. node
    59. libXcomposite-devel
    60. libproxy-devel
    61. libXft-devel
    62. libXcursor-devel
    63. libpulseaudio-devel
    64. libXi-devel
    65. libXScrnSaver-devel
    66. libXdamage-devel
    67. libX11-devel
    68. libXext-devel
    69. libXt-devel

Последнее изменение


20 декабря 2018 г. Alexey Gladkov 64.0-alt1
- New release (64.0).
- Fixed:
  + CVE-2018-12407: Buffer overflow with ANGLE library when using VertexBuffer11 module
  + CVE-2018-17466: Buffer overflow and out-of-bounds read in ANGLE library with TextureStorage11
  + CVE-2018-18492: Use-after-free with select element
  + CVE-2018-18493: Buffer overflow in accelerated 2D canvas with Skia
  + CVE-2018-18494: Same-origin policy violation using location attribute and performance.getEntries to steal cross-origin URLs
  + CVE-2018-18495: WebExtension content scripts can be loaded in about: pages
  + CVE-2018-18496: Embedded feed preview page can be abused for clickjacking
  + CVE-2018-18497: WebExtensions can load arbitrary URLs through pipe separators
  + CVE-2018-18498: Integer overflow when calculating buffer sizes for images
  + CVE-2018-12406: Memory safety bugs fixed in Firefox 64
  + CVE-2018-12405: Memory safety bugs fixed in Firefox 64 and Firefox ESR 60.4
23 ноября 2018 г. Alexey Gladkov 63.0.3-alt1
- New release (63.0.3).
13 ноября 2018 г. Alexey Gladkov 63.0.1-alt1
- New release (63.0.1).
- Fixed:
  + CVE-2018-12391: HTTP Live Stream audio data is accessible cross-origin
  + CVE-2018-12392: Crash with nested event loops
  + CVE-2018-12393: Integer overflow during Unicode conversion while loading JavaScript
  + CVE-2018-12395: WebExtension bypass of domain restrictions through header rewriting
  + CVE-2018-12396: WebExtension content scripts can execute in disallowed contexts
  + CVE-2018-12397: Missing warning prompt when WebExtension requests local file access
  + CVE-2018-12398: CSP bypass through stylesheet injection in resource URIs
  + CVE-2018-12399: Spoofing of protocol registration notification bar
  + CVE-2018-12400: Favicons are cached in private browsing mode on Firefox for Android
  + CVE-2018-12401: DOS attack through special resource URI parsing
  + CVE-2018-12402: SameSite cookies leak when pages are explicitly saved
  + CVE-2018-12403: Mixed content warning is not displayed when HTTPS page loads a favicon over HTTP
  + CVE-2018-12388: Memory safety bugs fixed in Firefox 63
  + CVE-2018-12390: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3