156233ebbcAccepting request 159297 from mozilla:Factory
Stephan Kulow
2013-03-15 09:42:02 +0000
90bc4d30c6Accepting request 158795 from devel:ARM:Factory
Wolfgang Rosenauer
2013-03-14 09:58:43 +0000
3413fbf9d5Accepting request 158061 from mozilla:Factory
Stephan Kulow
2013-03-10 07:28:55 +0000
ebe37a4908* MFSA 2013-29/CVE-2013-0787 (bmo#848644)
Wolfgang Rosenauer
2013-03-08 20:25:24 +0000
f34b49371b- update to Firefox 19.0.2 (bnc#808243) * MFSA 2013-29/CVE-2013-0787 (bmo#555018) Use-after-free in HTML Editor
Wolfgang Rosenauer
2013-03-08 13:41:22 +0000
a7dcce03daAccepting request 155861 from mozilla:Factory
Stephan Kulow
2013-02-20 08:31:38 +0000
6a20f50d7f- update to Firefox 19.0 (bnc#804248) * MFSA 2013-21/CVE-2013-0783/2013-0784 Miscellaneous memory safety hazards * MFSA 2013-22/CVE-2013-0772 (bmo#801366) Out-of-bounds read in image rendering * MFSA 2013-23/CVE-2013-0765 (bmo#830614) Wrapped WebIDL objects can be wrapped again * MFSA 2013-24/CVE-2013-0773 (bmo#809652) Web content bypass of COW and SOW security wrappers * MFSA 2013-25/CVE-2013-0774 (bmo#827193) Privacy leak in JavaScript Workers * MFSA 2013-26/CVE-2013-0775 (bmo#831095) Use-after-free in nsImageLoadingContent * MFSA 2013-27/CVE-2013-0776 (bmo#796475) Phishing on HTTPS connection through malicious proxy * MFSA 2013-28/CVE-2013-0780/CVE-2013-0782/CVE-2013-0777/ CVE-2013-0778/CVE-2013-0779/CVE-2013-0781 Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer - removed obsolete patches * mozilla-webrtc.patch * mozilla-gstreamer-803287.patch - added patch to fix session restore window order (bmo#712763)
Wolfgang Rosenauer
2013-02-19 19:24:59 +0000
a1f794153cAccepting request 154952 from mozilla:Factory
Stephan Kulow
2013-02-09 09:13:36 +0000
71d293a758- update to Firefox 18.0.2 * blocklist and CTP updates * fixes in JS engine
Wolfgang Rosenauer
2013-02-08 07:03:05 +0000
f081046c6eAccepting request 149304 from mozilla:Factory
Stephan Kulow
2013-01-25 08:34:10 +0000
1ad53d1168- update to Firefox 18.0.1 * blocklist updates * backed out bmo#677092 (removed patch) * fixed problems involving HTTP proxy transactions
Wolfgang Rosenauer
2013-01-20 09:36:34 +0000
29bd40e39aAccepting request 148241 from home:AndreasSchwab:ff
Wolfgang Rosenauer
2013-01-13 13:11:48 +0000
ad166e3879add OBS hardware constraints
Wolfgang Rosenauer
2013-01-11 09:23:04 +0000
d0612a98d8Accepting request 147596 from mozilla:Factory
Stephan Kulow
2013-01-10 12:31:49 +0000
137de8fd48* MFSA 2013-01/CVE-2013-0749/CVE-2013-0769/CVE-2013-0770 Miscellaneous memory safety hazards * MFSA 2013-02/CVE-2013-0760/CVE-2013-0762/CVE-2013-0766/CVE-2013-0767 CVE-2013-0761/CVE-2013-0763/CVE-2013-0771/CVE-2012-5829 Use-after-free and buffer overflow issues found using Address Sanitizer * MFSA 2013-03/CVE-2013-0768 (bmo#815795) Buffer Overflow in Canvas * MFSA 2013-04/CVE-2012-0759 (bmo#802026) URL spoofing in addressbar during page loads * MFSA 2013-05/CVE-2013-0744 (bmo#814713) Use-after-free when displaying table with many columns and column groups * MFSA 2013-06/CVE-2013-0751 (bmo#790454) Touch events are shared across iframes * MFSA 2013-07/CVE-2013-0764 (bmo#804237) Crash due to handling of SSL on threads * MFSA 2013-08/CVE-2013-0745 (bmo#794158) AutoWrapperChanger fails to keep objects alive during garbage collection * MFSA 2013-09/CVE-2013-0746 (bmo#816842) Compartment mismatch with quickstubs returned values * MFSA 2013-10/CVE-2013-0747 (bmo#733305) Event manipulation in plugin handler to bypass same-origin policy * MFSA 2013-11/CVE-2013-0748 (bmo#806031) Address space layout leaked in XBL objects * MFSA 2013-12/CVE-2013-0750 (bmo#805121) Buffer overflow in Javascript string concatenation * MFSA 2013-13/CVE-2013-0752 (bmo#805024) Memory corruption in XBL with XML bindings containing SVG * MFSA 2013-14/CVE-2013-0757 (bmo#813901) Chrome Object Wrapper (COW) bypass through changing prototype * MFSA 2013-15/CVE-2013-0758 (bmo#813906)
Wolfgang Rosenauer
2013-01-08 18:14:01 +0000
18aea15755* MFSA 2013-01/CVE-2013-0749/CVE-2013-0769/CVE-2013-0770 Miscellaneous memory safety hazards * MFSA 2013-02/CVE-2013-0760/CVE-2013-0762/CVE-2013-0766/CVE-2013-0767 CVE-2013-0761/CVE-2013-0763/CVE-2013-0771/CVE-2012-5829 Use-after-free and buffer overflow issues found using Address Sanitizer * MFSA 2013-03/CVE-2013-0768 (bmo#815795) Buffer Overflow in Canvas * MFSA 2013-04/CVE-2012-0759 (bmo#802026) URL spoofing in addressbar during page loads * MFSA 2013-05/CVE-2013-0744 (bmo#814713) Use-after-free when displaying table with many columns and column groups * MFSA 2013-06/CVE-2013-0751 (bmo#790454) Touch events are shared across iframes * MFSA 2013-07/CVE-2013-0764 (bmo#804237) Crash due to handling of SSL on threads * MFSA 2013-08/CVE-2013-0745 (bmo#794158) AutoWrapperChanger fails to keep objects alive during garbage collection * MFSA 2013-09/CVE-2013-0746 (bmo#816842) Compartment mismatch with quickstubs returned values * MFSA 2013-10/CVE-2013-0747 (bmo#733305) Event manipulation in plugin handler to bypass same-origin policy * MFSA 2013-11/CVE-2013-0748 (bmo#806031) Address space layout leaked in XBL objects * MFSA 2013-12/CVE-2013-0750 (bmo#805121) Buffer overflow in Javascript string concatenation * MFSA 2013-13/CVE-2013-0752 (bmo#805024) Memory corruption in XBL with XML bindings containing SVG * MFSA 2013-14/CVE-2013-0757 (bmo#813901) Chrome Object Wrapper (COW) bypass through changing prototype * MFSA 2013-15/CVE-2013-0758 (bmo#813906)
Wolfgang Rosenauer
2013-01-08 18:10:29 +0000
7a99168951- added mozilla-libproxy-compat.patch for libproxy API compat on openSUSE 11.2 and earlier - backed out restartless language packs as it broke multi-locale setup (bmo#677092, bmo#818468)
Wolfgang Rosenauer
2013-01-08 15:14:02 +0000
e5938deab5Accepting request 143652 from mozilla:Factory
Stephan Kulow
2012-12-03 09:41:08 +0000
401b2f7bae- update to Firefox 17.0.1 * revert some useragent changes introduced in 17.0 * leaving private browsing with social enabled doesn't reset all social components (bmo#815042)
Wolfgang Rosenauer
2012-11-30 09:28:25 +0000
b4e0dbd99d- fix KDE integration for file dialogs
Wolfgang Rosenauer
2012-11-26 11:27:34 +0000
298279c46fAccepting request 142205 from mozilla:Factory
Stephan Kulow
2012-11-22 15:46:46 +0000
662e67c339- update to Firefox 17.0 (bnc#790140) * MFSA 2012-91/CVE-2012-5842/CVE-2012-5843 Miscellaneous memory safety hazards * MFSA 2012-92/CVE-2012-4202 (bmo#758200) Buffer overflow while rendering GIF images * MFSA 2012-93/CVE-2012-4201 (bmo#747607) evalInSanbox location context incorrectly applied * MFSA 2012-94/CVE-2012-5836 (bmo#792857) Crash when combining SVG text on path with CSS * MFSA 2012-95/CVE-2012-4203 (bmo#765628) Javascript: URLs run in privileged context on New Tab page * MFSA 2012-96/CVE-2012-4204 (bmo#778603) Memory corruption in str_unescape * MFSA 2012-97/CVE-2012-4205 (bmo#779821) XMLHttpRequest inherits incorrect principal within sandbox * MFSA 2012-99/CVE-2012-4208 (bmo#798264) XrayWrappers exposes chrome-only properties when not in chrome compartment * MFSA 2012-100/CVE-2012-5841 (bmo#805807) Improper security filtering for cross-origin wrappers * MFSA 2012-101/CVE-2012-4207 (bmo#801681) Improper character decoding in HZ-GB-2312 charset * MFSA 2012-102/CVE-2012-5837 (bmo#800363) Script entered into Developer Toolbar runs with chrome privileges * MFSA 2012-103/CVE-2012-4209 (bmo#792405) Frames can shadow top.location * MFSA 2012-104/CVE-2012-4210 (bmo#796866) CSS and HTML injection through Style Inspector * MFSA 2012-105/CVE-2012-4214/CVE-2012-4215/CVE-2012-4216/ CVE-2012-5829/CVE-2012-5839/CVE-2012-5840/CVE-2012-4212/
Wolfgang Rosenauer
2012-11-20 20:34:15 +0000
983f714c70Accepting request 139507 from mozilla:Factory
Stephan Kulow
2012-10-27 11:23:56 +0000
42ce70cbed- update to Firefox 16.0.2 (bnc#786522) * MFSA 2012-90/CVE-2012-4194/CVE-2012-4195/CVE-2012-4196 (bmo#800666, bmo#793121, bmo#802557) Fixes for Location object issues - bring back Obsoletes for libproxy's mozjs plugin for distributions before 12.2 to avoid crashes
Wolfgang Rosenauer
2012-10-26 21:49:26 +0000
626cf3199aAccepting request 137938 from mozilla:Factory
Stephan Kulow
2012-10-16 05:10:05 +0000
7513245175- update to Firefox 16.0.1 (bnc#783533) * MFSA 2012-88/CVE-2012-4191 (bmo#798045) Miscellaneous memory safety hazards * MFSA 2012-89/CVE-2012-4192/CVE-2012-4193 (bmo#799952, bmo#720619) defaultValue security checks not applied
Wolfgang Rosenauer
2012-10-12 06:40:31 +0000
c556a7e236Accepting request 137662 from mozilla:Factory
Stephan Kulow
2012-10-10 07:20:32 +0000
bdf969b733* MFSA 2012-87/CVE-2012-3990 (bmo#787704) Use-after-free in the IME State Manager
Wolfgang Rosenauer
2012-10-09 20:30:30 +0000
4aa15e2c44* MFSA 2012-74/CVE-2012-3982/CVE-2012-3983 Miscellaneous memory safety hazards * MFSA 2012-75/CVE-2012-3984 (bmo#575294) select element persistance allows for attacks * MFSA 2012-76/CVE-2012-3985 (bmo#655649) Continued access to initial origin after setting document.domain * MFSA 2012-77/CVE-2012-3986 (bmo#775868) Some DOMWindowUtils methods bypass security checks * MFSA 2012-79/CVE-2012-3988 (bmo#725770) DOS and crash with full screen and history navigation * MFSA 2012-80/CVE-2012-3989 (bmo#783867) Crash with invalid cast when using instanceof operator * MFSA 2012-81/CVE-2012-3991 (bmo#783260) GetProperty function can bypass security checks * MFSA 2012-82/CVE-2012-3994 (bmo#765527) top object and location property accessible by plugins * MFSA 2012-83/CVE-2012-3993/CVE-2012-4184 (bmo#768101, bmo#780370) Chrome Object Wrapper (COW) does not disallow acces to privileged functions or properties * MFSA 2012-84/CVE-2012-3992 (bmo#775009) Spoofing and script injection through location.hash * MFSA 2012-85/CVE-2012-3995/CVE-2012-4179/CVE-2012-4180/ CVE-2012-4181/CVE-2012-4182/CVE-2012-4183 Use-after-free, buffer overflow, and out of bounds read issues found using Address Sanitizer * MFSA 2012-86/CVE-2012-4185/CVE-2012-4186/CVE-2012-4187/ CVE-2012-4188 Heap memory corruption issues found using Address Sanitizer
Wolfgang Rosenauer
2012-10-09 20:06:07 +0000
6f2059ff99- update to Firefox 16.0 (bnc#783533) - requires NSPR 4.9.2 - improve GStreamer integration (bmo#760140) - removed upstreamed mozilla-crashreporter-restart-args.patch - webapprt now included - use kmozillahelper's new REVEAL command (bnc#777415) (requires mozilla-kde4-integration >= 0.6.4) - updated translations-other with new languages
Wolfgang Rosenauer
2012-10-09 11:14:08 +0000
6dbea3ab7dAccepting request 133769 from mozilla:Factory
Ismail Dönmez
2012-09-12 22:05:01 +0000
a1842748f3- update to Firefox 15.0.1 (bnc#779936) * Sites visited while in Private Browsing mode could be found through manual browser cache inspection (bmo#787743)
Wolfgang Rosenauer
2012-09-12 10:14:03 +0000
e574da8542Accepting request 131904 from mozilla:Factory
Stephan Kulow
2012-08-31 07:44:58 +0000
84ebf9d464- update to Firefox 15.0 (bnc#777588) * MFSA 2012-57/CVE-2012-1970 Miscellaneous memory safety hazards * MFSA 2012-58/CVE-2012-1972/CVE-2012-1973/CVE-2012-1974/CVE-2012-1975 CVE-2012-1976/CVE-2012-3956/CVE-2012-3957/CVE-2012-3958/CVE-2012-3959 CVE-2012-3960/CVE-2012-3961/CVE-2012-3962/CVE-2012-3963/CVE-2012-3964 Use-after-free issues found using Address Sanitizer * MFSA 2012-59/CVE-2012-1956 (bmo#756719) Location object can be shadowed using Object.defineProperty * MFSA 2012-60/CVE-2012-3965 (bmo#769108) Escalation of privilege through about:newtab * MFSA 2012-61/CVE-2012-3966 (bmo#775794, bmo#775793) Memory corruption with bitmap format images with negative height * MFSA 2012-62/CVE-2012-3967/CVE-2012-3968 WebGL use-after-free and memory corruption * MFSA 2012-63/CVE-2012-3969/CVE-2012-3970 SVG buffer overflow and use-after-free issues * MFSA 2012-64/CVE-2012-3971 Graphite 2 memory corruption * MFSA 2012-65/CVE-2012-3972 (bmo#746855) Out-of-bounds read in format-number in XSLT * MFSA 2012-66/CVE-2012-3973 (bmo#757128) HTTPMonitor extension allows for remote debugging without explicit activation * MFSA 2012-68/CVE-2012-3975 (bmo#770684) DOMParser loads linked resources in extensions when parsing text/html * MFSA 2012-69/CVE-2012-3976 (bmo#768568) Incorrect site SSL certificate data display * MFSA 2012-70/CVE-2012-3978 (bmo#770429)
Wolfgang Rosenauer
2012-08-28 18:40:50 +0000
0269b47b6eAccepting request 129207 from mozilla:Factory
Ismail Dönmez
2012-07-30 09:17:17 +0000
6f7c78c38eAccepting request 129204 from home:a_jaeger:FactoryFix
Wolfgang Rosenauer
2012-07-29 09:45:44 +0000
252274944cAccepting request 128272 from mozilla:Factory
Stephan Kulow
2012-07-20 08:18:06 +0000
6a7340e3e1- update to 14.0.1 (bnc#771583) * MFSA 2012-42/CVE-2012-1949/CVE-2012-1948 Miscellaneous memory safety hazards * MFSA 2012-43/CVE-2012-1950 Incorrect URL displayed in addressbar through drag and drop * MFSA 2012-44/CVE-2012-1951/CVE-2012-1954/CVE-2012-1953/CVE-2012-1952 Gecko memory corruption * MFSA 2012-45/CVE-2012-1955 (bmo#757376) Spoofing issue with location * MFSA 2012-46/CVE-2012-1966 (bmo#734076) XSS through data: URLs * MFSA 2012-47/CVE-2012-1957 (bmo#750096) Improper filtering of javascript in HTML feed-view * MFSA 2012-48/CVE-2012-1958 (bmo#750820) use-after-free in nsGlobalWindow::PageHidden * MFSA 2012-49/CVE-2012-1959 (bmo#754044, bmo#737559) Same-compartment Security Wrappers can be bypassed * MFSA 2012-50/CVE-2012-1960 (bmo#761014) Out of bounds read in QCMS * MFSA 2012-51/CVE-2012-1961 (bmo#761655) X-Frame-Options header ignored when duplicated * MFSA 2012-52/CVE-2012-1962 (bmo#764296) JSDependentString::undepend string conversion results in memory corruption * MFSA 2012-53/CVE-2012-1963 (bmo#767778) Content Security Policy 1.0 implementation errors cause data leakage * MFSA 2012-55/CVE-2012-1965 (bmo#758990) feed: URLs with an innerURI inherit security context of page * MFSA 2012-56/CVE-2012-1967 (bmo#758344)
Wolfgang Rosenauer
2012-07-18 05:21:02 +0000
e5beda73e6- PPC fixes: * reenabled mozilla-yarr-pcre.patch to fix build for PPC * add patches for bmo#750620 and bmo#746112 * fix xpcshell segfault on ppc
Wolfgang Rosenauer
2012-07-16 18:54:48 +0000
ec5d636a3c- update to 14.0.1 (bnc#) - license change from tri license to MPL-2.0 - fix crashreporter restart option (bmo#762780) - reenabled mozilla-yarr-pcre.patch to fix build for PPC - require NSS 3.13.5 - remove mozjs pacrunner obsoletes again for now - adopted mozilla-prefer_plugin_pref.patch
Wolfgang Rosenauer
2012-07-16 08:13:51 +0000
2f47f359b1Accepting request 125186 from mozilla:Factory
Stephan Kulow
2012-06-18 15:31:45 +0000
ad9947e5f3- update to Firefox 13.0.1 * bugfix release - obsolete libproxy's mozjs pacrunner (bnc#759123)
Wolfgang Rosenauer
2012-06-15 20:14:41 +0000
7f49ab608bAccepting request 123736 from mozilla:Factory
Stephan Kulow
2012-06-06 14:08:32 +0000
a7f369b4c2- update to Firefox 13.0 (bnc#765204) * MFSA 2012-34/CVE-2012-1938/CVE-2012-1937/CVE-2011-3101 Miscellaneous memory safety hazards * MFSA 2012-36/CVE-2012-1944 (bmo#751422) Content Security Policy inline-script bypass * MFSA 2012-37/CVE-2012-1945 (bmo#670514) Information disclosure though Windows file shares and shortcut files * MFSA 2012-38/CVE-2012-1946 (bmo#750109) Use-after-free while replacing/inserting a node in a document * MFSA 2012-40/CVE-2012-1947/CVE-2012-1940/CVE-2012-1941 Buffer overflow and use-after-free issues found using Address Sanitizer - require NSS 3.13.4 * MFSA 2012-39/CVE-2012-0441 (bmo#715073) - fix sound notifications when filename/path contains a whitespace (bmo#749739)
Wolfgang Rosenauer
2012-06-05 18:01:53 +0000
f05b764554Accepting request 122243 from mozilla:Factory
Stephan Kulow
2012-05-26 07:27:11 +0000
5cbfe5dc1aAccepting request 122016 from openSUSE:Factory:ARM
Wolfgang Rosenauer
2012-05-25 07:01:36 +0000
f1ea0660ffAccepting request 121179 from mozilla:Factory
Stephan Kulow
2012-05-16 19:08:25 +0000
03a2b96996- reenabled crashreporter for Factory/12.2 (fix in mozilla-gcc47.patch)
Wolfgang Rosenauer
2012-05-16 05:35:58 +0000
53335b664eAccepting request 116230 from mozilla:Factory
Stephan Kulow
2012-05-08 04:46:44 +0000
d3fc7a1a25* MFSA 2012-20/CVE-2012-0467/CVE-2012-0468 Miscellaneous memory safety hazards * MFSA 2012-22/CVE-2012-0469 (bmo#738985) use-after-free in IDBKeyRange * MFSA 2012-23/CVE-2012-0470 (bmo#734288) Invalid frees causes heap corruption in gfxImageSurface * MFSA 2012-24/CVE-2012-0471 (bmo#715319) Potential XSS via multibyte content processing errors * MFSA 2012-25/CVE-2012-0472 (bmo#744480) Potential memory corruption during font rendering using cairo-dwrite * MFSA 2012-26/CVE-2012-0473 (bmo#743475) WebGL.drawElements may read illegal video memory due to FindMaxUshortElement error * MFSA 2012-27/CVE-2012-0474 (bmo#687745, bmo#737307) Page load short-circuit can lead to XSS * MFSA 2012-28/CVE-2012-0475 (bmo#694576) Ambiguous IPv6 in Origin headers may bypass webserver access restrictions * MFSA 2012-29/CVE-2012-0477 (bmo#718573) Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues * MFSA 2012-30/CVE-2012-0478 (bmo#727547) Crash with WebGL content using textImage2D * MFSA 2012-31/CVE-2011-3062 (bmo#739925) Off-by-one error in OpenType Sanitizer * MFSA 2012-32/CVE-2011-1187 (bmo#624621) HTTP Redirections and remote content can be read by javascript errors * MFSA 2012-33/CVE-2012-0479 (bmo#714631) Potential site identity spoofing when loading RSS and Atom feeds
Wolfgang Rosenauer
2012-04-25 05:50:41 +0000
b44c6da2e0Accepting request 114913 from mozilla:Factory
Stephan Kulow
2012-04-23 14:11:40 +0000
3c4317c1ff- update to Firefox 12.0 (bnc#758408)
Wolfgang Rosenauer
2012-04-21 10:42:40 +0000
1d2bc7dc71- update to Firefox 12.0b6 * rebased patches - added mozilla-libnotify.patch to allow fallback from libnotify to xul based events if no notification-daemon is running - gcc 4.7 fixes * mozilla-gcc47.patch * disabled crashreporter temporarily for Factory - recommend libcanberra0 for proper sound notifications
Wolfgang Rosenauer
2012-04-20 19:18:58 +0000
88efdbb05eAccepting request 109208 from mozilla:Factory
Stephan Kulow
2012-03-16 12:18:14 +0000
9b8c7a10ed- update to Firefox 11.0 (bnc#750044) * MFSA 2012-13/CVE-2012-0455 (bmo#704354) XSS with Drag and Drop and Javascript: URL * MFSA 2012-14/CVE-2012-0456/CVE-2012-0457 (bmo#711653, #720103) SVG issues found with Address Sanitizer * MFSA 2012-15/CVE-2012-0451 (bmo#717511) XSS with multiple Content Security Policy headers * MFSA 2012-16/CVE-2012-0458 Escalation of privilege with Javascript: URL as home page * MFSA 2012-17/CVE-2012-0459 (bmo#723446) Crash when accessing keyframe cssText after dynamic modification * MFSA 2012-18/CVE-2012-0460 (bmo#727303) window.fullScreen writeable by untrusted content * MFSA 2012-19/CVE-2012-0461/CVE-2012-0462/CVE-2012-0464/ CVE-2012-0463 Miscellaneous memory safety hazards
Wolfgang Rosenauer
2012-03-14 07:27:10 +0000
2c4f5a31acAccepting request 108974 from mozilla:Factory
Stephan Kulow
2012-03-13 08:36:55 +0000
86129f9536Accepting request 107981 from home:vdziewiecki:branches:mozilla:Factory
Wolfgang Rosenauer
2012-03-05 13:38:22 +0000
3dcefa43db- update to version 11.0b5 - ported and reenabled KDE integration (bnc#746591) - explicitely build-require X libs
Wolfgang Rosenauer
2012-03-01 09:09:12 +0000
debdb7d238Accepting request 107062 from openSUSE:Factory:ARM
Wolfgang Rosenauer
2012-02-28 07:27:36 +0000
9c3ffed8a8Accepting request 105422 from mozilla:Factory
Stephan Kulow
2012-02-17 11:17:33 +0000
48942bb06f- update to Firefox 10.0.2 (bnc#747328) * CVE-2011-3026 (bmo#727401) libpng: integer overflow leading to heap-buffer overflow
Wolfgang Rosenauer
2012-02-16 13:41:23 +0000
d430c312c4Accepting request 104183 from mozilla:Factory
Stephan Kulow
2012-02-14 18:03:37 +0000
9dd1e5949c- update to Firefox 10.0.1 (bnc#746616) * MFSA 2012-10/CVE-2012-0452 (bmo#724284) use after free in nsXBLDocumentInfo::ReadPrototypeBindings
Wolfgang Rosenauer
2012-02-12 22:09:22 +0000
56abb2fdedAccepting request 103184 from mozilla:Factory
Stephan Kulow
2012-02-08 16:19:03 +0000
eee92765e6- Use YARR interpreter instead of PCRE on platforms where YARR JIT is not supported, since PCRE doesnt build (bmo#691898) - fix ppc64 build (bmo#703534)
Wolfgang Rosenauer
2012-02-07 18:15:47 +0000
e5281c0a89Accepting request 102411 from mozilla:Factory
Stephan Kulow
2012-02-02 16:58:06 +0000
54fa2b53dd- update to Firefox 10.0 (bnc#744275) * MFSA 2012-01/CVE-2012-0442/CVE-2012-0443 Miscellaneous memory safety hazards * MFSA 2012-03/CVE-2012-0445 (bmo#701071) <iframe> element exposed across domains via name attribute * MFSA 2012-04/CVE-2011-3659 (bmo#708198) Child nodes from nsDOMAttribute still accessible after removal of nodes * MFSA 2012-05/CVE-2012-0446 (bmo#705651) Frame scripts calling into untrusted objects bypass security checks * MFSA 2012-06/CVE-2012-0447 (bmo#710079) Uninitialized memory appended when encoding icon images may cause information disclosure * MFSA 2012-07/CVE-2012-0444 (bmo#719612) Potential Memory Corruption When Decoding Ogg Vorbis files * MFSA 2012-08/CVE-2012-0449 (bmo#701806, bmo#702466) Crash with malformed embedded XSLT stylesheets - KDE integration has been disabled since it needs refactoring - removed obsolete ppc64 patch
Wolfgang Rosenauer
2012-02-01 13:37:15 +0000
a3f56ad779Accepting request 98123 from mozilla:Factory
Stephan Kulow
2011-12-25 16:36:52 +0000
f33289d5ff- update to Firefox 9.0.1 * (strongparent) parentNode of element gets lost (bmo#335998)
Wolfgang Rosenauer
2011-12-23 20:44:10 +0000
27b2f4d442Accepting request 97351 from mozilla:Factory
Stephan Kulow
2011-12-21 09:01:28 +0000
3017ae6323- update to Firefox 9 (bnc#737533) * MFSA 2011-53/CVE-2011-3660 Miscellaneous memory safety hazards (rv:9.0) * MFSA 2011-54/CVE-2011-3661 (bmo#691299) Potentially exploitable crash in the YARR regular expression library * MFSA 2011-55/CVE-2011-3658 (bmo#708186) nsSVGValue out-of-bounds access * MFSA 2011-56/CVE-2011-3663 (bmo#704482) Key detection without JavaScript via SVG animation * MFSA 2011-58/VE-2011-3665 (bmo#701259) Crash scaling <video> to extreme sizes
Wolfgang Rosenauer
2011-12-20 20:07:17 +0000
a4c123508fAccepting request 96954 from openSUSE:Factory:ARM
Wolfgang Rosenauer
2011-12-19 13:17:53 +0000
3df3bcb178- update to Firefox 9
Wolfgang Rosenauer
2011-12-18 13:13:18 +0000
02a5839fe7- update to Firefox 9
Wolfgang Rosenauer
2011-12-18 13:10:54 +0000
bc2ec736b1replace license with spdx.org variant
Stephan Kulow
2011-12-06 17:29:44 +0000
8c4a34d482Updating link to change in openSUSE:Factory/MozillaFirefox revision 138.0
OBS User buildservice-autocommit
2011-12-06 17:29:44 +0000
3430ef9affAccepting request 91117 from mozilla:Factory
Stephan Kulow
2011-11-14 12:17:21 +0000
f645666476- fix ppc64 build
Wolfgang Rosenauer
2011-11-12 15:24:00 +0000
e2281b142bAccepting request 90807 from mozilla:Factory
Stephan Kulow
2011-11-10 14:54:26 +0000
8834f8ff8e- update to Firefox 8 (bnc#728520) * MFSA 2011-47/CVE-2011-3648 (bmo#690225) Potential XSS against sites using Shift-JIS * MFSA 2011-48/CVE-2011-3651/CVE-2011-3652/CVE-2011-3654 Miscellaneous memory safety hazards * MFSA 2011-49/CVE-2011-3650 (bmo#674776) Memory corruption while profiling using Firebug * MFSA 2011-52/CVE-2011-3655 (bmo#672182) Code execution via NoWaiverWrapper - rebased patches
Wolfgang Rosenauer
2011-11-09 12:04:11 +0000
956d35c86fAccepting request 85866 from mozilla:Factory
Lars Vogdt
2011-10-02 07:45:08 +0000
52ba560f1c- update to minor release 7.0.1 * fixed staged addon updates * MFSA 2011-36/CVE-2011-2995/CVE-2011-2996/CVE-2011-2997 Miscellaneous memory safety hazards * MFSA 2011-39/CVE-2011-3000 (bmo#655389) Defense against multiple Location headers due to CRLF Injection * MFSA 2011-40/CVE-2011-2372/CVE-2011-3001 Code installation through holding down Enter * MFSA 2011-41/CVE-2011-3002/CVE-2011-3003 (bmo#680840, bmo#682335) Potentially exploitable WebGL crashes * MFSA 2011-42/CVE-2011-3232 (bmo#653672) Potentially exploitable crash in the YARR regular expression library * MFSA 2011-43/CVE-2011-3004 (bmo#653926) loadSubScript unwraps XPCNativeWrapper scope parameter * MFSA 2011-44/CVE-2011-3005 (bmo#675747) Use after free reading OGG headers * MFSA 2011-45 Inferring keystrokes from motion data
Wolfgang Rosenauer
2011-09-30 12:17:54 +0000
a133c21e8bAccepting request 85281 from mozilla:Factory
Sascha Peilicke
2011-09-28 12:01:23 +0000
9933e45a18version 7
Wolfgang Rosenauer
2011-09-26 06:53:33 +0000
081a75e659- fixed loading of kde.js under KDE (bnc#718311)
Wolfgang Rosenauer
2011-09-16 12:57:01 +0000
831fc0d43fAutobuild autoformatter for 82116
Sascha Peilicke
2011-09-15 09:55:26 +0000
6e63619cbaUpdating link to change in openSUSE:Factory/MozillaFirefox revision 132.0
OBS User buildservice-autocommit
2011-09-15 09:55:26 +0000
b684d60617Accepting request 82116 from mozilla:Factory
Sascha Peilicke
2011-09-15 09:55:16 +0000
64d6854445fix build
Wolfgang Rosenauer
2011-09-14 07:03:00 +0000
79806e72fbAutobuild autoformatter for 81758
Sascha Peilicke
2011-09-11 17:02:07 +0000
470e628180Updating link to change in openSUSE:Factory/MozillaFirefox revision 130.0
OBS User buildservice-autocommit
2011-09-11 17:02:07 +0000
7652364e06Accepting request 81758 from mozilla:Factory
Sascha Peilicke
2011-09-11 17:01:54 +0000
dbe00f868fsource-stamp
Wolfgang Rosenauer
2011-09-09 21:09:54 +0000
abfcc9c248Accepting request 81394 from mozilla:Factory
Sascha Peilicke
2011-09-09 09:03:58 +0000
f864313e08- security update to 6.0.2 (bnc#714931) * Complete blocking of certificates issued by DigiNotar (bmo#683449)
Petr Cerny
2011-09-07 16:09:13 +0000