Commit Graph

1 Commits

Author SHA256 Message Date
Wolfgang Rosenauer
d8a78670a6 - Disable/remove patches no longer needed:
mozilla-bmo1511604.patch
    mozilla-bmo1583471.patch
- Added mozilla-bmo1602730.patch to fix another LE<->BE issue (bmo#1602730)

- Mozilla Firefox 68.4.1esr
  MFSA 2020-03 (bsc#1160498)
  * CVE-2019-17026 (bmo#1607443)
    IonMonkey type confusion with StoreElementHole and FallibleStoreElement

- Mozilla Firefox 68.4.0esr
  MFSA 2020-02 (bsc#1160305)
  * CVE-2019-17015 (bmo#1599005)
    Memory corruption in parent process during new content process
    initialization on Windows
  * CVE-2019-17016 (bmo#1599181)
    Bypass of @namespace CSS sanitization during pasting
  * CVE-2019-17017 (bmo#1603055)
    Type Confusion in XPCVariant.cpp
  * CVE-2019-17021 (bmo#1599008)
    Heap address disclosure in parent process during content process
    initialization on Windows
  * CVE-2019-17022 (bmo#1602843)
    CSS sanitization does not escape HTML tags
  * CVE-2019-17024 (bmo#1507180, bmo#1595470, bmo#1598605, bmo#1601826)
    Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4
------------------------------------------------------------------

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/firefox-esr?expand=0&rev=20
2020-01-09 21:31:21 +00:00