Сопровождающий Pavel Vasenkov в ветке sisyphus: Информация
Имя сопровождающего: Pavel Vasenkov (pav)
Собрано source пакетов в данной ветке: 13
-
- @ruby
Последние изменения
30 сентября 2023 г. 8:09
#330520 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
29 сентября 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-5168 Out-of-bounds write in FilterNodeD2D1 + CVE-2023-5169 Out-of-bounds write in PathOps + CVE-2023-5171 Use-after-free in Ion Compiler + CVE-2023-5174 Double-free in process spawning on Windows + CVE-2023-5176 Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 + CVE-2023-5217 Heap buffer overflow in libvpx
25 сентября 2023 г. 12:11
#328494 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
14 сентября 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-3600 Use-after-free in workers + CVE-2023-3417 File Extension Spoofing using the Text Direction Override Character + CVE-2023-4045 Offscreen Canvas could have bypassed cross-origin restrictions + CVE-2023-4046 Incorrect value used during WASM compilation + CVE-2023-4047 Potential permissions request bypass via clickjacking + CVE-2023-4048 Crash in DOMParser due to out-of-memory conditions + CVE-2023-4049 Fix potential race conditions when releasing platform objects + CVE-2023-4050 Stack buffer overflow in StorageManager + CVE-2023-4052 File deletion and privilege escalation through Firefox uninstaller + CVE-2023-4054 Lack of warning when opening appref-ms files + CVE-2023-4055 Cookie jar overflow caused unexpected cookie jar state + CVE-2023-4056 Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 + CVE-2023-4057 Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1 + CVE-2023-4573 Memory corruption in IPC CanvasTranslator + CVE-2023-4574 Memory corruption in IPC ColorPickerShownCallback + CVE-2023-4575 Memory corruption in IPC FilePickerShownCallback + CVE-2023-4576 Integer Overflow in RecordedSourceSurfaceCreation + CVE-2023-4577 Memory corruption in JIT UpdateRegExpStatics + CVE-2023-4051 Full screen notification obscured by file open dialog + CVE-2023-4578 Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception + CVE-2023-4053 Full screen notification obscured by external program + CVE-2023-4580 Push notifications saved to disk unencrypted + CVE-2023-4581 XLL file extensions were downloadable without warnings + CVE-2023-4582 Buffer Overflow in WebGL glGetProgramiv + CVE-2023-4583 Browsing Context potentially not cleared when closing Private Window + CVE-2023-4584 Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 + CVE-2023-4585 Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 + CVE-2023-4863 Heap buffer overflow in libwebp
21 сентября 2023 г. 13:16
#329982 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
20 сентября 2023 г. Pavel Vasenkov:
- Restored build for 32bit archs
20 сентября 2023 г. 8:36
#329883 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
8 сентября 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-3600 Use-after-free in workers + CVE-2023-4045 Offscreen Canvas could have bypassed cross-origin restrictions + CVE-2023-4046 Incorrect value used during WASM compilation + CVE-2023-4047 Potential permissions request bypass via clickjacking + CVE-2023-4048 Crash in DOMParser due to out-of-memory conditions + CVE-2023-4049 Fix potential race conditions when releasing platform objects + CVE-2023-4050 Stack buffer overflow in StorageManager + CVE-2023-4052 File deletion and privilege escalation through Firefox uninstaller + CVE-2023-4054 Lack of warning when opening appref-ms files + CVE-2023-4055 Cookie jar overflow caused unexpected cookie jar state + CVE-2023-4056 Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 + CVE-2023-4057 Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1 + CVE-2023-4573 Memory corruption in IPC CanvasTranslator + CVE-2023-4574 Memory corruption in IPC ColorPickerShownCallback + CVE-2023-4575 Memory corruption in IPC FilePickerShownCallback + CVE-2023-4576 Integer Overflow in RecordedSourceSurfaceCreation + CVE-2023-4577 Memory corruption in JIT UpdateRegExpStatics + CVE-2023-4051 Full screen notification obscured by file open dialog + CVE-2023-4578 Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception + CVE-2023-4053 Full screen notification obscured by external program + CVE-2023-4580 Push notifications saved to disk unencrypted + CVE-2023-4581 XLL file extensions were downloadable without warnings + CVE-2023-4582 Buffer Overflow in WebGL glGetProgramiv + CVE-2023-4583 Browsing Context potentially not cleared when closing Private Window + CVE-2023-4584 Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 + CVE-2023-4585 Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 + CVE-2023-4863 Heap buffer overflow in libwebp
20 сентября 2023 г. 1:36
#329882 отправлено Pavel Vasenkov
E-book reader application
18 сентября 2023 г. Pavel Vasenkov:
- ExcludeArch: i386 i486 i586 i686 i786 i886 i986 pentium2 pentium3 pentium4 k6 athlon athlon_xp ppc64le
GUI prototyping tool
18 сентября 2023 г. Pavel Vasenkov:
- ExcludeArch: i386 i486 i586 i686 i786 i886 i986 pentium2 pentium3 pentium4 k6 athlon athlon_xp ppc64le
configure firefox for a livecd environment
18 сентября 2023 г. Pavel Vasenkov:
- ExcludeArch: i386 i486 i586 i686 i786 i886 i986 pentium2 pentium3 pentium4 k6 athlon athlon_xp ppc64le
start the browser for a suitable webkiosk environment
19 сентября 2023 г. Pavel Vasenkov:
- ExcludeArch: i386 i486 i586 i686 i786 i886 i986 pentium2 pentium3 pentium4 k6 athlon athlon_xp ppc64le
30 июня 2023 г. 22:42
#323806 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
27 июня 2023 г. Pavel Vasenkov:
- Fixes: Unstable name collisions Build failure with GCC 13
30 июня 2023 г. 22:02
#323808 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
27 июня 2023 г. Pavel Vasenkov:
- Fixes: Unstable name collisions Build failure with GCC 13
14 июня 2023 г. 17:05
#322997 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
14 июня 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-34414 Click-jacking certificate exceptions through rendering lag + CVE-2023-34416 Memory safety bugs fixed in Thunderbird 102.12
8 июня 2023 г. 5:55
#322571 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
7 июня 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-34414 Click-jacking certificate exceptions through rendering lag + CVE-2023-34416 Memory safety bugs fixed in Firefox 114 and Firefox ESR 102.12
19 мая 2023 г. 15:07
#321197 отправлено Pavel Vasenkov
System call fuzz tester
19 мая 2023 г. Pavel Vasenkov:
- Fix removing depricated i810 definations
17 мая 2023 г. 23:51
#321097 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
17 мая 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-32205 Browser prompts could have been obscured by popups + CVE-2023-32206 Crash in RLBox Expat driver + CVE-2023-32207 Potential permissions request bypass via clickjacking + CVE-2023-32211 Content process crash due to invalid wasm code + CVE-2023-32212 Potential spoof due to obscured address bar + CVE-2023-32213 Potential memory corruption in FileReader::DoReadData() + CVE-2023-32214 Potential DoS via exposed protocol handlers + CVE-2023-32215 Memory safety bugs fixed in Thunderbird 102.11
17 мая 2023 г. 9:47
#320575 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
15 мая 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-32205 Browser prompts could have been obscured by popups + CVE-2023-32206 Crash in RLBox Expat driver + CVE-2023-32207 Potential permissions request bypass via clickjacking + CVE-2023-32211 Content process crash due to invalid wasm code + CVE-2023-32212 Potential spoof due to obscured address bar + CVE-2023-32213 Potential memory corruption in FileReader::DoReadData() + CVE-2023-32214 Potential DoS via exposed protocol handlers + CVE-2023-32215 Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
20 апреля 2023 г. 11:25
#318816 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
19 апреля 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-29531 Out-of-bound memory access in WebGL on macOS + CVE-2023-29532 Mozilla Maintenance Service Write-lock bypass + CVE-2023-29533 Fullscreen notification obscured + CVE-2023-1999 Double-free in libwebp + CVE-2023-29535 Potential Memory Corruption following Garbage Collector compaction + CVE-2023-29536 Invalid free from JavaScript code + CVE-2023-29539 Content-Disposition filename truncation leads to Reflected File Download + CVE-2023-29541 Files with malicious extensions could have been downloaded unsafely on Linux + CVE-2023-29542 Bypass of file download extension restrictions + CVE-2023-29545 Windows Save As dialog resolved environment variables + CVE-2023-1945 Memory Corruption in Safe Browsing Code + CVE-2023-29548 Incorrect optimization result on ARM64 + CVE-2023-29550 Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10
20 апреля 2023 г. 10:45
#318817 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
19 апреля 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-29531 Out-of-bound memory access in WebGL on macOS + CVE-2023-29532 Mozilla Maintenance Service Write-lock bypass + CVE-2023-29533 Fullscreen notification obscured + CVE-2023-1999 Double-free in libwebp + CVE-2023-29535 Potential Memory Corruption following Garbage Collector compaction + CVE-2023-29536 Invalid free from JavaScript code + CVE-2023-0547 Revocation status of S/Mime recipient certificates was not checked + CVE-2023-29479 Hang when processing certain OpenPGP messages + CVE-2023-29539 Content-Disposition filename truncation leads to Reflected File Download + CVE-2023-29541 Files with malicious extensions could have been downloaded unsafely on Linux + CVE-2023-29542 Bypass of file download extension restrictions + CVE-2023-29545 Windows Save As dialog resolved environment variables + CVE-2023-1945 Memory Corruption in Safe Browsing Code + CVE-2023-29548 Incorrect optimization result on ARM64 + CVE-2023-29550 Memory safety bugs fixed in Thunderbird 102.10
22 марта 2023 г. 19:14
#317199 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
22 марта 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-25751 Incorrect code generation during JIT compilation + CVE-2023-28164 URL being dragged from a removed cross-origin iframe into the same tab triggered navigation + CVE-2023-28162 Invalid downcast in Worklets + CVE-2023-25752 Potential out-of-bounds when accessing throttled streams + CVE-2023-28163 Windows Save As dialog resolved environment variables + CVE-2023-28176 Memory safety bugs fixed in Thunderbird 102.9
22 марта 2023 г. 19:01
#317198 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
22 марта 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-25751 Incorrect code generation during JIT compilation + CVE-2023-28164 URL being dragged from a removed cross-origin iframe into the same tab triggered navigation + CVE-2023-28162 Invalid downcast in Worklets + CVE-2023-25752 Potential out-of-bounds when accessing throttled streams + CVE-2023-28163 Windows Save As dialog resolved environment variables + CVE-2023-28176 Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9
5 марта 2023 г. 2:58
#316235 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
3 марта 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2023-25728 Content security policy leak in violation reports using iframes + CVE-2023-25730 Screen hijack via browser fullscreen mode + CVE-2023-0767 Arbitrary memory write via PKCS 12 in NSS + CVE-2023-25735 Potential use-after-free from compartment mismatch in SpiderMonkey + CVE-2023-25737 Invalid downcast in SVGUtils::SetupStrokeGeometry + CVE-2023-25738 Printing on Windows could potentially crash Firefox with some device drivers + CVE-2023-25739 Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext + CVE-2023-25729 Extensions could have opened external schemes without user knowledge + CVE-2023-25732 Out of bounds memory write from EncodeInputStream + CVE-2023-25734 Opening local .url files could cause unexpected network loads + CVE-2023-25742 Web Crypto ImportKey crashes tab + CVE-2023-25744 Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 + CVE-2023-25746 Memory safety bugs fixed in Firefox ESR 102.8
2 марта 2023 г. 8:23
#316076 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
28 февраля 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-0616 User Interface lockup with messages combining S/MIME and OpenPGP + CVE-2023-25728 Content security policy leak in violation reports using iframes + CVE-2023-25730 Screen hijack via browser fullscreen mode + CVE-2023-0767 Arbitrary memory write via PKCS 12 in NSS + CVE-2023-25735 Potential use-after-free from compartment mismatch in SpiderMonkey + CVE-2023-25737 Invalid downcast in SVGUtils::SetupStrokeGeometry + CVE-2023-25738 Printing on Windows could potentially crash Thunderbird with some device drivers + CVE-2023-25739 Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext + CVE-2023-25729 Extensions could have opened external schemes without user knowledge + CVE-2023-25732 Out of bounds memory write from EncodeInputStream + CVE-2023-25734 Opening local .url files could cause unexpected network loads + CVE-2023-25742 Web Crypto ImportKey crashes tab + CVE-2023-25746 Memory safety bugs fixed in Thunderbird 102.8
14 февраля 2023 г. 19:08
#313517 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
18 января 2023 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2022-46871 libusrsctp library out of date + CVE-2023-23598 Arbitrary file read from GTK drag and drop on Linux + CVE-2023-23599 Malicious command could be hidden in devtools output on Windows + CVE-2023-23601 URL being dragged from cross-origin iframe into same tab triggers navigation + CVE-2023-23602 Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers + CVE-2022-46877 Fullscreen notification bypass + CVE-2023-23603 Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive + CVE-2023-23605 Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
3 февраля 2023 г. 14:03
#314597 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
3 февраля 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2023-0430 Revocation status of S/Mime signature certificates was not checked
24 января 2023 г. 11:45
#314030 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
24 января 2023 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-46871 libusrsctp library out of date + CVE-2023-23598 Arbitrary file read from GTK drag and drop on Linux + CVE-2023-23599 Malicious command could be hidden in devtools output on Windows + CVE-2023-23601 URL being dragged from cross-origin iframe into same tab triggers navigation + CVE-2023-23602 Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers + CVE-2022-46877 Fullscreen notification bypass + CVE-2023-23603 Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive + CVE-2023-23605 Memory safety bugs fixed in Thunderbird 102.7
24 декабря 2022 г. 23:01
#312284 отправлено Pavel Vasenkov
System call fuzz tester
24 декабря 2022 г. Pavel Vasenkov:
- Update from upstream - Fix missed header file - Update source url(Closes: #40516)
23 декабря 2022 г. 21:44
#312280 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
23 декабря 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions
16 декабря 2022 г. 18:12
#311856 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
16 декабря 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-46880 Use-after-free in WebGL + CVE-2022-46872 Arbitrary file read from a compromised content process + CVE-2022-46881 Memory corruption in WebGL + CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions + CVE-2022-46875 Download Protections were bypassed by .atloc and .ftploc files on Mac OS + CVE-2022-46882 Use-after-free in WebGL + CVE-2022-46878 Memory safety bugs fixed in Thunderbird 102.6
15 декабря 2022 г. 1:02
#311756 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
14 декабря 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes + CVE-2022-46880 Use-after-free in WebGL + CVE-2022-46872 Arbitrary file read from a compromised content process + CVE-2022-46881 Memory corruption in WebGL + CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions + CVE-2022-46875 Download Protections were bypassed by .atloc and .ftploc files on Mac OS + CVE-2022-46882 Use-after-free in WebGL + CVE-2022-46878 Memory safety bugs fixed in Firefox 108 and Firefox ESR 102.6
9 декабря 2022 г. 18:54
#311455 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
9 декабря 2022 г. Pavel Vasenkov:
- Build with llvm-version 12 instead llvm-version 13 (Closes: #44436)
5 декабря 2022 г. 20:42
#311223 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
5 декабря 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-45414 Quoting from an HTML email with certain tags will trigger network requests and load remote content, regardless of a configuration
22 ноября 2022 г. 10:31
#310431 отправлено Pavel Vasenkov
17 ноября 2022 г. 15:01
#310102 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
16 ноября 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-45403 Service Workers might have learned size of cross-origin media files + CVE-2022-45404 Fullscreen notification bypass + CVE-2022-45405 Use-after-free in InputStream implementation + CVE-2022-45406 Use-after-free of a JavaScript Realm + CVE-2022-45408 Fullscreen notification bypass via windowName + CVE-2022-45409 Use-after-free in Garbage Collection + CVE-2022-45410 ServiceWorker-intercepted requests bypassed SameSite cookie policy + CVE-2022-45411 Cross-Site Tracing was possible via non-standard override headers + CVE-2022-45412 Symlinks may resolve to partially uninitialized buffers + CVE-2022-45416 Keystroke Side-Channel Leakage + CVE-2022-45418 Custom mouse cursor could have been drawn over browser UI + CVE-2022-45420 Iframe contents could be rendered outside the iframe + CVE-2022-45421 Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5
17 ноября 2022 г. 12:26
#310101 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
16 ноября 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-45403 Service Workers might have learned size of cross-origin media files + CVE-2022-45404 Fullscreen notification bypass + CVE-2022-45405 Use-after-free in InputStream implementation + CVE-2022-45406 Use-after-free of a JavaScript Realm + CVE-2022-45408 Fullscreen notification bypass via windowName + CVE-2022-45409 Use-after-free in Garbage Collection + CVE-2022-45410 ServiceWorker-intercepted requests bypassed SameSite cookie policy + CVE-2022-45411 Cross-Site Tracing was possible via non-standard override headers + CVE-2022-45412 Symlinks may resolve to partially uninitialized buffers + CVE-2022-45416 Keystroke Side-Channel Leakage + CVE-2022-45418 Custom mouse cursor could have been drawn over browser UI + CVE-2022-45420 Iframe contents could be rendered outside the iframe + CVE-2022-45421 Memory safety bugs fixed in Thunderbird 102.5
15 ноября 2022 г. 21:33
#310018 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
11 ноября 2022 г. Pavel Vasenkov:
- New version.
24 октября 2022 г. 14:27
#308901 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
24 октября 2022 г. Pavel Vasenkov:
- New version.
24 октября 2022 г. 12:41
#308900 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
24 октября 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-42927 Same-origin policy violation could have leaked cross-origin URLs + CVE-2022-42928 Memory Corruption in JS Engine + CVE-2022-42929 Denial of Service via window.print + CVE-2022-42932 Memory safety bugs fixed in Firefox 106 and Firefox ESR 102.4
11 октября 2022 г. 10:01
#308169 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
10 октября 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-3266 Out of bounds read when decoding H264 + CVE-2022-40959 Bypassing FeaturePolicy restrictions on transient pages + CVE-2022-40960 Data-race when parsing non-UTF-8 URLs in threads + CVE-2022-40958 Bypassing Secure Context restriction for cookies with __Host and __Secure prefix + CVE-2022-40956 Content-Security-Policy base-uri bypass + CVE-2022-40957 Incoherent instruction cache when building WASM on ARM64 + CVE-2022-40962 Memory safety bugs fixed in Firefox 105 and Firefox ESR 102.3
10 октября 2022 г. 9:10
#308145 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
10 октября 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-39249 Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators + CVE-2022-39250 Matrix SDK bundled with Thunderbird vulnerable to a device verification attack + CVE-2022-39251 Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack + CVE-2022-39236 Matrix SDK bundled with Thunderbird vulnerable to a data corruption issue
16 сентября 2022 г. 0:57
#306846 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
15 сентября 2022 г. Pavel Vasenkov:
- Update language support
6 сентября 2022 г. 11:54
#306343 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
6 сентября 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-3033 Leaking of sensitive information when composing a response to an HTML email with a META refresh tag + CVE-2022-3032 Remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute was not blocked + CVE-2022-3034 An iframe element in an HTML email could trigger a network request + CVE-2022-36059 Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack
29 августа 2022 г. 9:04
#304701 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
24 августа 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-38472 Address bar spoofing via XSLT error handling + CVE-2022-38473 Cross-origin XSLT Documents would have inherited the parent's permissions + CVE-2022-38476 Data race and potential use-after-free in PK11_ChangePW + CVE-2022-38477 Memory safety bugs fixed in Thunderbird 102.2 + CVE-2022-38478 Memory safety bugs fixed in Thunderbird 102.2, and Thunderbird 91.13
25 августа 2022 г. 15:42
#305733 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
25 августа 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-38472 Address bar spoofing via XSLT error handling + CVE-2022-38473 Cross-origin XSLT Documents would have inherited the parent's permissions + CVE-2022-38476 Data race and potential use-after-free in PK11_ChangePW + CVE-2022-38477 Memory safety bugs fixed in Firefox 104 and Firefox ESR 102.2 + CVE-2022-38478 Memory safety bugs fixed in Firefox 104, Firefox ESR 102.2, and Firefox ESR 91.13
18 августа 2022 г. 18:48
#304700 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
22 июля 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-36319 Mouse Position spoofing with CSS transforms + CVE-2022-36318 Directory indexes for bundled resources reflected URL parameters + CVE-2022-36314 Opening local <code>.lnk</code> files could cause unexpected network loads + CVE-2022-2505 Memory safety bugs fixed in Firefox 103 and 102.1
29 июня 2022 г. 20:04
#302834 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
29 июня 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-34479 A popup window could be resized in a way to overlay the address bar with web content + CVE-2022-34470 Use-after-free in nsSHistory + CVE-2022-34468 CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI + CVE-2022-34481 Potential integer overflow in ReplaceElementsAt + CVE-2022-31744 CSP bypass enabling stylesheet injection + CVE-2022-34472 Unavailable PAC file resulted in OCSP requests being blocked + CVE-2022-34478 Microsoft protocols can be attacked if a user accepts a prompt + CVE-2022-2200 Undesired attributes could be set as part of prototype pollution + CVE-2022-34484 Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11
4 июня 2022 г. 1:29
#301216 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
3 июня 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-31736 Cross-Origin resource's length leaked + CVE-2022-31737 Heap buffer overflow in WebGL + CVE-2022-31738 Browser window spoof using fullscreen mode + CVE-2022-31739 Attacker-influenced path traversal when saving downloaded files + CVE-2022-31740 Register allocation problem in WASM on arm64 + CVE-2022-31741 Uninitialized variable leads to invalid memory read + CVE-2022-1834 Braille space character caused incorrect sender email to be shown for a digitally signed email + CVE-2022-31742 Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information + CVE-2022-31747 Memory safety bugs fixed in Thunderbird 91.10
4 июня 2022 г. 1:23
#301215 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
3 июня 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-31736 Cross-Origin resource's length leaked + CVE-2022-31737 Heap buffer overflow in WebGL + CVE-2022-31738 Browser window spoof using fullscreen mode + CVE-2022-31739 Attacker-influenced path traversal when saving downloaded files + CVE-2022-31740 Register allocation problem in WASM on arm64 + CVE-2022-31741 Uninitialized variable leads to invalid memory read + CVE-2022-31742 Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information + CVE-2022-31747 Memory safety bugs fixed in Firefox 101 and Firefox ESR 91.10
25 мая 2022 г. 1:13
#297983 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
21 мая 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-1802 Prototype pollution in Top-Level Await implementation + CVE-2022-1529 Untrusted input used in JavaScript object indexing, leading to prototype pollution
24 мая 2022 г. 15:12
#300522 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
22 мая 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-1802 Prototype pollution in Top-Level Await implementation + CVE-2022-1529 Untrusted input used in JavaScript object indexing, leading to prototype pollution
5 мая 2022 г. 6:17
#299477 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
4 мая 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-29914 Fullscreen notification bypass using popups + CVE-2022-29909 Bypassing permission prompt in nested browsing contexts + CVE-2022-29916 Leaking browser history with CSS variables + CVE-2022-29911 iframe Sandbox bypass + CVE-2022-29912 Reader mode bypassed SameSite cookies + CVE-2022-29917 Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9
3 мая 2022 г. 23:44
#297984 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
6 апреля 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-1097 Use-after-free in NSSToken objects + CVE-2022-28281 Out of bounds write due to unexpected WebAuthN Extensions + CVE-2022-1196 Use-after-free after VR Process destruction + CVE-2022-28282 Use-after-free in DocumentL10n::TranslateDocument + CVE-2022-28285 Incorrect AliasSet used in JIT Codegen + CVE-2022-28286 iframe contents could be rendered outside the border + CVE-2022-24713 Denial of Service via complex regular expressions + CVE-2022-28289 Memory safety bugs fixed in Firefox 99 and Firefox ESR 91.8
24 марта 2022 г. 20:08
#297130 отправлено Pavel Vasenkov
The orginal well curated collection of extension methods for Ruby
23 марта 2022 г. Pavel Vasenkov:
- + disable provides cgi-exception
14 марта 2022 г. 1:06
#296596 отправлено Pavel Vasenkov
Thunderbird is Mozilla's e-mail client
13 марта 2022 г. Pavel Vasenkov:
- New version. - Security fixes: + CVE-2022-26383 Browser window spoof using fullscreen mode + CVE-2022-26384 iframe allow-scripts sandbox bypass + CVE-2022-26387 Time-of-check time-of-use bug when verifying add-on signatures + CVE-2022-26381 Use-after-free in text reflows + CVE-2022-26386 Temporary files downloaded to /tmp and accessible by other local users
14 марта 2022 г. 0:59
#296595 отправлено Pavel Vasenkov
The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
13 марта 2022 г. Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2022-26383 Browser window spoof using fullscreen mode + CVE-2022-26384 iframe allow-scripts sandbox bypass + CVE-2022-26387 Time-of-check time-of-use bug when verifying add-on signatures + CVE-2022-26381 Use-after-free in text reflows + CVE-2022-26386 Temporary files downloaded to /tmp and accessible by other local users