- Add MozillaFirefox.changes.txt as a hard link to firefox-esr.changes

- Rename firefox-esr.changes into firefox-esr.changes.txt in order
  to trick source_validator because of the two possible package
  names "firefox-esr" vs. "MozillaFirefox" (in Leap).

- Firefox Extended Support Release 128.5.1 ESR
  * Fixed: Fixed an issue that prevented some websites from
    loading when using SSL Inspection. (bmo#1933747)

- Firefox Extended Support Release 128.5.0 ESR
  * Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.5.0
  https://www.mozilla.org/security/advisories/mfsa2024-64
  MFSA 2024-64 (boo#1233695)
  * CVE-2024-11691 (bmo#1914707, bmo#1924184)
    Memory corruption in Apple GPU drivers
  * CVE-2024-11692 (bmo#1909535)
    Select list elements could be shown over another site
  * CVE-2024-11693 (bmo#1921458)
    Download Protections were bypassed by .library-ms files on
    Windows
  * CVE-2024-11694 (bmo#1924167)
    CSP Bypass and XSS Exposure via Web Compatibility Shims
  * CVE-2024-11695 (bmo#1925496)
    URL Bar Spoofing via Manipulated Punycode and Whitespace
    Characters
  * CVE-2024-11696 (bmo#1929600)
    Unhandled Exception in Add-on Signature Verification
  * CVE-2024-11697 (bmo#1842187)
    Improper Keypress Handling in Executable File Confirmation

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=24
This commit is contained in:
Manfred Hollstein 2024-12-11 17:12:36 +00:00 committed by Git OBS Bridge
parent 73b9e38bcb
commit 4324e796ef