From fbf027988aa167a40c2c6810788bb99e1c7371dc1f8a4c0f7fe6083414f19467 Mon Sep 17 00:00:00 2001 From: Wolfgang Rosenauer Date: Thu, 7 Jan 2021 20:33:44 +0000 Subject: [PATCH] Accepting request 861463 from home:AndreasStieger:branches:mozilla:Factory - Mozilla Firefox 84.0.2 MFSA 2021-01 (bsc#1180623) * CVE-2020-16044 (bmo#1683964) Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk OBS-URL: https://build.opensuse.org/request/show/861463 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=884 --- MozillaFirefox.changes | 9 +++++++++ MozillaFirefox.spec | 4 ++-- firefox-84.0.1.source.tar.xz | 3 --- firefox-84.0.1.source.tar.xz.asc | 16 ---------------- firefox-84.0.2.source.tar.xz | 3 +++ firefox-84.0.2.source.tar.xz.asc | 16 ++++++++++++++++ l10n-84.0.1.tar.xz => l10n-84.0.2.tar.xz | 0 tar_stamps | 8 ++++---- 8 files changed, 34 insertions(+), 25 deletions(-) delete mode 100644 firefox-84.0.1.source.tar.xz delete mode 100644 firefox-84.0.1.source.tar.xz.asc create mode 100644 firefox-84.0.2.source.tar.xz create mode 100644 firefox-84.0.2.source.tar.xz.asc rename l10n-84.0.1.tar.xz => l10n-84.0.2.tar.xz (100%) diff --git a/MozillaFirefox.changes b/MozillaFirefox.changes index d71e87b9..71cefa3d 100644 --- a/MozillaFirefox.changes +++ b/MozillaFirefox.changes @@ -1,3 +1,12 @@ +------------------------------------------------------------------- +Thu Jan 7 17:11:43 UTC 2021 - Andreas Stieger + +- Mozilla Firefox 84.0.2 + MFSA 2021-01 (bsc#1180623) + * CVE-2020-16044 (bmo#1683964) + Use-after-free write when handling a malicious COOKIE-ECHO + SCTP chunk + ------------------------------------------------------------------- Sun Dec 27 09:52:50 UTC 2020 - Wolfgang Rosenauer diff --git a/MozillaFirefox.spec b/MozillaFirefox.spec index 8f02be1e..327bca9d 100644 --- a/MozillaFirefox.spec +++ b/MozillaFirefox.spec @@ -30,8 +30,8 @@ # major 69 # mainver %major.99 %define major 84 -%define mainver %major.0.1 -%define orig_version 84.0.1 +%define mainver %major.0.2 +%define orig_version 84.0.2 %define orig_suffix %{nil} %define update_channel release %define branding 1 diff --git a/firefox-84.0.1.source.tar.xz b/firefox-84.0.1.source.tar.xz deleted file mode 100644 index 51ab7b0f..00000000 --- a/firefox-84.0.1.source.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:ae5500d270a199f9a10674fbd4ba7a6beac1f260a4c009bbca8ea39967592243 -size 369981420 diff --git a/firefox-84.0.1.source.tar.xz.asc b/firefox-84.0.1.source.tar.xz.asc deleted file mode 100644 index 77f03106..00000000 --- a/firefox-84.0.1.source.tar.xz.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCgAdFiEECXsxMHeuYqAvhNpN8aZmj7t9Vy4FAl/g9BEACgkQ8aZmj7t9 -Vy5POBAApcPIj7YPe6i8UfJQKEZ2XK0mRWdEQ4v78Ws7Zgck/TsmgRLzZLQvIhNc -YPlQGN9pn6EtD59vuWkUXYPXAZJR9sCeVDEicI3xYFIRwBVPuLK6ueS4CZ8XYaxx -WRYi4NybQ1IugXQhGi60pNC37r5VGCnppzJNFem/Q5yiCCVJrPi6dweUDAbUOkDW -NPP/X3LGQSrQn8P17rxfje6+ZHILy7kgl/31elA654QR+M6q5qVTrU9CZrOWZi0D -bizITY2Z2U+BSZ8zoi/y7xctnrKpnGDe/QyhGGqrxzWOvEiYu7T4EmHChGGVcnUk -gbNs77IhY01X43y4xa6xpflgZ5j7nUK40KIB3cCsEg8RqqHHQUWXr+sq2ozeG6iT -9PQZLGRWCrP1TVsehSo1RDi7ab9fowp5a6U9M4b1V5nlMqGbGR+Eun9csM1fLEdL -gsE3k97S3AYHrCw33QVA6uFMzfpl+omi5CvhfAY4w9sM+IayQwmCMZpOnmg3Dvw4 -sBDxuh/hsCT5bXGnfhP8y3hU5RnDwl2SinMvOUMgJorxEBAZ6zxKeLBWup5SL7i1 -3XZmDKeIiaDEYou+v3a9SmFoasyzAzvrhXYCkqGm3w9yhsMtXvNt7JRMwYL/P1VG -FGDU+2lGjp2RKgFfQkEBpWrPs/fnFIFAXRl9cu/HITVVom6cH/g= -=SwIm ------END PGP SIGNATURE----- diff --git a/firefox-84.0.2.source.tar.xz b/firefox-84.0.2.source.tar.xz new file mode 100644 index 00000000..a2824eec --- /dev/null +++ b/firefox-84.0.2.source.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:92bfd518d4f9760c897388a8e06130b171c1c43524d8af181add9daac2be7b37 +size 363415420 diff --git a/firefox-84.0.2.source.tar.xz.asc b/firefox-84.0.2.source.tar.xz.asc new file mode 100644 index 00000000..ae3950de --- /dev/null +++ b/firefox-84.0.2.source.tar.xz.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCgAdFiEECXsxMHeuYqAvhNpN8aZmj7t9Vy4FAl/0zh8ACgkQ8aZmj7t9 +Vy6krg//cvXq4sARmctPX8CkDMmbj9P734RCwOsSacu2hCmLMaefK+uq6yKt/c+L +i77S9sY1WnbDtHAGGLd2LTXvSEuwbpIvNlBmXSAWlATMDpMzMD08BGCOILYyOCMz +OFh590JQhjASfvpUeE/4kB+f/YEXLBnyV2vq1vcqWflsfWuvcGy+YIO3/WI+SVk4 +NknJ/KqWui1Pgl8rI6UrlmDY7e/vA0bee4MqGKwfcdRjM01XuSHMzt5rJP2mvF7S +r58SBpY8ZJz++axJihos7A9jo3d6reF3CRR9aiH26bXyaqKnRfnZIZYPhdW6gfhM +mkIKAc/kVDjzBF4Xg/QWMONynrh288fEinCH7v3VHDWhes50uq33Ki5rgb+zXX9T +WjGVBZmC48mTpXAbroyn8Y3skVHJY+nhg/4akybsx9rz1pgIJh1P6aDmbSHFmoc5 +5xDCHNVgm80FySV84CaXCG0Lq7Gdo317B8xReIAaMrXw3N+RKtiAdy/hswL0j70Y +rU77kXbo80ALVfXp/JEa697XOqxs0d6a0ekacsKo3pq6aWowRsdmNFdUTBxK8zDO +QiISgm3+xgO8sQgYCC3KyhKa+gMsa6Axw2PqsXNFgoC0rKQGbGzTVyqfcXUx9BR2 +gpTpx1b8fKzf8PQZz9MSYHpv7QOW/agVQ3rmlgVr7lk/RyoOWmY= +=XVjq +-----END PGP SIGNATURE----- diff --git a/l10n-84.0.1.tar.xz b/l10n-84.0.2.tar.xz similarity index 100% rename from l10n-84.0.1.tar.xz rename to l10n-84.0.2.tar.xz diff --git a/tar_stamps b/tar_stamps index 0e8c94ef..2936c9c2 100644 --- a/tar_stamps +++ b/tar_stamps @@ -1,11 +1,11 @@ PRODUCT="firefox" CHANNEL="release" -VERSION="84.0.1" +VERSION="84.0.2" VERSION_SUFFIX="" -PREV_VERSION="84.0" +PREV_VERSION="84.0.1" PREV_VERSION_SUFFIX="" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/mozilla-release" -RELEASE_TAG="88e4de109bfa59db244d1fd590d64edfdd872b54" -RELEASE_TIMESTAMP="20201221152838" +RELEASE_TAG="7e22d68e1ebfc0839092237feeefad46cfbd8651" +RELEASE_TIMESTAMP="20210105180113"