Commit Graph

31 Commits

Author SHA256 Message Date
9b62e72a5a - Firefox Extended Support Release 128.6.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.6.0
  https://www.mozilla.org/security/advisories/mfsa2025-02
  MFSA 2025-02 (boo#1234991)
  * CVE-2025-0237 (bmo#1915257)
    WebChannel APIs susceptible to confused deputy attack
  * CVE-2025-0238 (bmo#1915535)
    Use-after-free when breaking lines in text
  * CVE-2025-0239 (bmo#1929156)
    Alt-Svc ALPN validation failure when redirected
  * CVE-2025-0240 (bmo#1929623)
    Compartment mismatch when parsing JavaScript JSON module
  * CVE-2025-0241 (bmo#1933023)
    Memory corruption when using JavaScript Text Segmentation
  * CVE-2025-0242 (bmo#1874523, bmo#1926454, bmo#1931873,
    bmo#1932169)
    Memory safety bugs fixed in Firefox 134, Thunderbird 134,
    Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19,
    and Thunderbird 128.6
  * CVE-2025-0243 (bmo#1827142, bmo#1932783)
    Memory safety bugs fixed in Firefox 134, Thunderbird 134,
    Firefox ESR 128.6, and Thunderbird 128.6

- Firefox Extended Support Release 128.5.2 ESR
  * Fixed: Fixed a crash experienced by Windows users with Qihoo
    360 Total Security Antivirus software installed (bmo#1934258)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=32
2025-01-07 16:21:28 +00:00
Ana Guerrero
a58ec43e06 Accepting request 1230315 from mozilla:Factory
Introduce Mozilla Firefox ESR as a new package "firefox-esr" to Factory; this package happily co-exists with the real "MozillaFirefox".

OBS-URL: https://build.opensuse.org/request/show/1230315
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firefox-esr?expand=0&rev=1
2024-12-12 20:18:05 +00:00
4d682f771e OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=29 2024-12-12 10:33:01 +00:00
782a783eb7 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=28 2024-12-12 09:26:48 +00:00
0d4d17772f - Don't install the gnome-shell search-provider, it conflicts with
MozillaFirefox

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=27
2024-12-12 09:25:33 +00:00
da5a48ebc2 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=26 2024-12-11 19:24:10 +00:00
9a18f9bfb1 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=25 2024-12-11 17:23:12 +00:00
4324e796ef - Add MozillaFirefox.changes.txt as a hard link to firefox-esr.changes
- Rename firefox-esr.changes into firefox-esr.changes.txt in order
  to trick source_validator because of the two possible package
  names "firefox-esr" vs. "MozillaFirefox" (in Leap).

- Firefox Extended Support Release 128.5.1 ESR
  * Fixed: Fixed an issue that prevented some websites from
    loading when using SSL Inspection. (bmo#1933747)

- Firefox Extended Support Release 128.5.0 ESR
  * Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.5.0
  https://www.mozilla.org/security/advisories/mfsa2024-64
  MFSA 2024-64 (boo#1233695)
  * CVE-2024-11691 (bmo#1914707, bmo#1924184)
    Memory corruption in Apple GPU drivers
  * CVE-2024-11692 (bmo#1909535)
    Select list elements could be shown over another site
  * CVE-2024-11693 (bmo#1921458)
    Download Protections were bypassed by .library-ms files on
    Windows
  * CVE-2024-11694 (bmo#1924167)
    CSP Bypass and XSS Exposure via Web Compatibility Shims
  * CVE-2024-11695 (bmo#1925496)
    URL Bar Spoofing via Manipulated Punycode and Whitespace
    Characters
  * CVE-2024-11696 (bmo#1929600)
    Unhandled Exception in Add-on Signature Verification
  * CVE-2024-11697 (bmo#1842187)
    Improper Keypress Handling in Executable File Confirmation

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=24
2024-12-11 17:12:36 +00:00
73b9e38bcb - Add MozillaFirefox.changes.txt as a hard link to firefox-esr.changes
- Rename firefox-esr.changes into firefox-esr.changes.txt in order
  to trick source_validator because of the two possible package
  names "firefox-esr" vs. "MozillaFirefox" (in Leap).

- Firefox Extended Support Release 128.5.1 ESR
  * Fixed: Fixed an issue that prevented some websites from
    loading when using SSL Inspection. (bmo#1933747)

- Firefox Extended Support Release 128.5.0 ESR
  * Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.5.0
  https://www.mozilla.org/security/advisories/mfsa2024-64
  MFSA 2024-64 (boo#1233695)
  * CVE-2024-11691 (bmo#1914707, bmo#1924184)
    Memory corruption in Apple GPU drivers
  * CVE-2024-11692 (bmo#1909535)
    Select list elements could be shown over another site
  * CVE-2024-11693 (bmo#1921458)
    Download Protections were bypassed by .library-ms files on
    Windows
  * CVE-2024-11694 (bmo#1924167)
    CSP Bypass and XSS Exposure via Web Compatibility Shims
  * CVE-2024-11695 (bmo#1925496)
    URL Bar Spoofing via Manipulated Punycode and Whitespace
    Characters
  * CVE-2024-11696 (bmo#1929600)
    Unhandled Exception in Add-on Signature Verification
  * CVE-2024-11697 (bmo#1842187)
    Improper Keypress Handling in Executable File Confirmation

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=23
2024-12-11 17:05:12 +00:00
3b2f571f9a osc copypac from project:mozilla package:firefox128esr revision:24
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=22
2024-12-11 16:58:52 +00:00
Wolfgang Rosenauer
a226d95b0d New development package for openSUSE:Factory
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=21
2024-12-11 12:38:50 +00:00
Wolfgang Rosenauer
d8a78670a6 - Disable/remove patches no longer needed:
mozilla-bmo1511604.patch
    mozilla-bmo1583471.patch
- Added mozilla-bmo1602730.patch to fix another LE<->BE issue (bmo#1602730)

- Mozilla Firefox 68.4.1esr
  MFSA 2020-03 (bsc#1160498)
  * CVE-2019-17026 (bmo#1607443)
    IonMonkey type confusion with StoreElementHole and FallibleStoreElement

- Mozilla Firefox 68.4.0esr
  MFSA 2020-02 (bsc#1160305)
  * CVE-2019-17015 (bmo#1599005)
    Memory corruption in parent process during new content process
    initialization on Windows
  * CVE-2019-17016 (bmo#1599181)
    Bypass of @namespace CSS sanitization during pasting
  * CVE-2019-17017 (bmo#1603055)
    Type Confusion in XPCVariant.cpp
  * CVE-2019-17021 (bmo#1599008)
    Heap address disclosure in parent process during content process
    initialization on Windows
  * CVE-2019-17022 (bmo#1602843)
    CSS sanitization does not escape HTML tags
  * CVE-2019-17024 (bmo#1507180, bmo#1595470, bmo#1598605, bmo#1601826)
    Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4
------------------------------------------------------------------

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=20
2020-01-09 21:31:21 +00:00
Wolfgang Rosenauer
25ef0f15a6 - add mozilla-bmo1583471.patch to allow building with rust 1.39
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=19
2019-12-29 19:02:56 +00:00
Wolfgang Rosenauer
8f8a49159e OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=18 2019-12-06 23:33:30 +00:00
Wolfgang Rosenauer
9895d20c5d - Mozilla Firefox 68.3.0esr
MFSA 2019-37
  * CVE-2019-17008 (bmo#1546331)
    Use-after-free in worker destruction
  * CVE-2019-13722 (bmo#1580156)
    Stack corruption due to incorrect number of arguments in WebRTC code
  * CVE-2019-11745 (bmo#1586176)
    Out of bounds write in NSS when encrypting with a block cipher
  * CVE-2019-17009 (bmo#1510494)
    Updater temporary files accessible to unprivileged processes
  * CVE-2019-17010 (bmo#1581084)
    Use-after-free when performing device orientation checks
  * CVE-2019-17005 (bmo#1584170)
    Buffer overflow in plain text serializer
  * CVE-2019-17011 (bmo#1591334)
    Use-after-free when retrieving a document in antitracking
  * CVE-2019-17012 (bmo#1449736, bmo#1533957, bmo#1560667, bmo#1567209,
    bmo#1580288, bmo#1585760, bmo#1592502)
    Memory safety bugs fixed in Firefox 71 and Firefox ESR 68.3
  * Various updates to improve performance and stability
- updated create-tar.sh to cover buildid and origin repo information
  -> removed obsolete source-stamp.txt
- changed locale building procedure
  * removed obsolete compare-locales.tar.xz

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=17
2019-12-06 23:06:28 +00:00
Wolfgang Rosenauer
9c9885ff77 - added
mozilla-bmo1504834-part4.patch
    mozilla-bmo849632.patch
  to fix broken tab-titles on big endian machines
- reactivate webRTC for all architectures

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=16
2019-11-19 09:21:36 +00:00
Wolfgang Rosenauer
3617f1c97f - Ensure %{ff_esr_name} get tested as a string; also, don't compare
against an empty string.

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=15
2019-11-17 06:21:11 +00:00
Wolfgang Rosenauer
688c3dcd33 - Use more portable syntax to check if macro ff_esr_name is defined.
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=14
2019-11-15 07:54:34 +00:00
Wolfgang Rosenauer
167d6d48ad - Increase disk size in _constraints file from 24 to 25 Gb since the
build log is showing a "No space left on device" error when checking
  for unpackaged files in x86_64.

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=13
2019-11-15 07:52:45 +00:00
Wolfgang Rosenauer
16a01b7dfd OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=12 2019-10-22 20:25:15 +00:00
Wolfgang Rosenauer
237b9259bd OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=11 2019-10-22 20:14:20 +00:00
Wolfgang Rosenauer
abc587e76f MFSA 2019-33 (bsc#1154738)
* CVE-2019-15903 (bmo#1584907)
    Heap overflow in expat library in XML_GetCurrentLineNumber
  * CVE-2019-11757 (bmo#1577107)
    Use-after-free when creating index updates in IndexedDB
  * CVE-2019-11758 (bmo#1536227)
    Potentially exploitable crash due to 360 Total Security
  * CVE-2019-11759 (bmo#1577953)
    Stack buffer overflow in HKDF output
  * CVE-2019-11760 (bmo#1577719)
    Stack buffer overflow in WebRTC networking
  * CVE-2019-11761 (bmo#1561502)
    Unintended access to a privileged JSONView object
  * CVE-2019-11762 (bmo#1582857)
    document.domain-based origin isolation has same-origin-property violation
  * CVE-2019-11763 (bmo#1584216)
    Incorrect HTML parsing results in XSS bypass technique
  * CVE-2019-11764 (bmo#1558522, bmo#1577061, bmo#1548044, bmo#1571223,
    bmo#1573048, bmo#1578933, bmo#1575217, bmo#1583684, bmo#1586845,
    bmo#1581950, bmo#1583463, bmo#1586599)
    Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=10
2019-10-22 19:46:06 +00:00
Wolfgang Rosenauer
9ed7dfc5da OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=9 2019-10-21 20:54:55 +00:00
Wolfgang Rosenauer
d0d63be38a OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=8 2019-10-21 20:51:13 +00:00
Wolfgang Rosenauer
91ee4ba1c3 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=7 2019-10-21 20:46:46 +00:00
Wolfgang Rosenauer
9bf9623ece - added mozilla-sle12-lower-python-requirement.patch to support
SLE12 still

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=6
2019-10-21 20:41:32 +00:00
Wolfgang Rosenauer
69085a7729 - Mozilla Firefox 68.2.0esr
- removed obsolete patches
    mozilla-bmo1573381.patch
    mozilla-bmo1512162.patch
    mozilla-bmo1585099.patch

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=5
2019-10-21 13:36:41 +00:00
Wolfgang Rosenauer
1c69eeca85 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=4 2019-10-11 12:41:04 +00:00
Wolfgang Rosenauer
67b87408b1 - do not build devel subpackage for this variant (not required and
creating file conflicts)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=3
2019-10-10 14:11:19 +00:00
Wolfgang Rosenauer
9f5300c225 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=2 2019-10-05 07:06:41 +00:00
Wolfgang Rosenauer
4ac53cb2cd osc copypac from project:mozilla package:firefox68 revision:8
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=1
2019-10-03 20:50:15 +00:00