1
0
Commit Graph

1207 Commits

Author SHA256 Message Date
Dominique Leuenberger
bbf30e466b Accepting request 1092022 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1092022
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=400
2023-06-12 13:25:06 +00:00
Wolfgang Rosenauer
24a9e3ddcb Accepting request 1092018 from home:AndreasStieger:branches:mozilla:Factory
Mozilla Firefox 114.0.1

OBS-URL: https://build.opensuse.org/request/show/1092018
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1066
2023-06-10 15:11:56 +00:00
Dominique Leuenberger
55dff7d4a5 Accepting request 1089039 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1089039
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=399
2023-05-26 18:15:11 +00:00
Wolfgang Rosenauer
6caaefa8ca Accepting request 1088911 from home:AndreasStieger:branches:mozilla:Factory
Mozilla Firefox 113.0.2 (boo#1211696)

OBS-URL: https://build.opensuse.org/request/show/1088911
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1064
2023-05-25 13:45:47 +00:00
Dominique Leuenberger
e1cc4cc48a Accepting request 1087124 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1087124
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=398
2023-05-15 14:54:03 +00:00
Wolfgang Rosenauer
d4b52ebc4a Accepting request 1087021 from home:AndreasStieger:branches:mozilla:Factory
113.0.1

OBS-URL: https://build.opensuse.org/request/show/1087021
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1062
2023-05-14 18:44:10 +00:00
Dominique Leuenberger
3a7d9558a7 Accepting request 1085989 from mozilla:Factory
- Mozilla Firefox 113.0
  * https://www.mozilla.org/en-US/firefox/113.0/releasenotes
  MFSA 2023-16 (bsc#1211175)
  * CVE-2023-32205 (bmo#1753339, bmo#1753341)
    Browser prompts could have been obscured by popups
  * CVE-2023-32206 (bmo#1824892)
    Crash in RLBox Expat driver
  * CVE-2023-32207 (bmo#1826116)
    Potential permissions request bypass via clickjacking
  * CVE-2023-32208 (bmo#1646034)
    Leak of script base URL in service workers via import()
  * CVE-2023-32209 (bmo#1767194)
    Persistent DoS via favicon image
  * CVE-2023-32210 (bmo#1776755)
    Incorrect principal object ordering
  * CVE-2023-32211 (bmo#1823379)
    Content process crash due to invalid wasm code
  * CVE-2023-32212 (bmo#1826622)
    Potential spoof due to obscured address bar
  * CVE-2023-32213 (bmo#1826666)
    Potential memory corruption in FileReader::DoReadData()
  * MFSA-TMP-2023-0002 (bmo#1814560, bmo#1814790, bmo#1819796)
    Race condition in dav1d decoding
  * CVE-2023-32214 (bmo#1828716)
    Potential DoS via exposed protocol handlers
  * CVE-2023-32215 (bmo#1540883, bmo#1751943, bmo#1814856, bmo#1820210,
    bmo#1821480, bmo#1827019, bmo#1827024, bmo#1827144, bmo#1827359,
    bmo#1830186)
    Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
  * CVE-2023-32216 (bmo#1746479, bmo#1806852, bmo#1815987,

OBS-URL: https://build.opensuse.org/request/show/1085989
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=397
2023-05-11 10:31:37 +00:00
Wolfgang Rosenauer
c51a7ff93a OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1060 2023-05-10 06:34:41 +00:00
Wolfgang Rosenauer
9ce57073ae - Mozilla Firefox 113.0
* https://www.mozilla.org/en-US/firefox/113.0/releasenotes
  MFSA 2023-16 (bsc#1211175)
  * CVE-2023-32205 (bmo#1753339, bmo#1753341)
    Browser prompts could have been obscured by popups
  * CVE-2023-32206 (bmo#1824892)
    Crash in RLBox Expat driver
  * CVE-2023-32207 (bmo#1826116)
    Potential permissions request bypass via clickjacking
  * CVE-2023-32208 (bmo#1646034)
    Leak of script base URL in service workers via import()
  * CVE-2023-32209 (bmo#1767194)
    Persistent DoS via favicon image
  * CVE-2023-32210 (bmo#1776755)
    Incorrect principal object ordering
  * CVE-2023-32211 (bmo#1823379)
    Content process crash due to invalid wasm code
  * CVE-2023-32212 (bmo#1826622)
    Potential spoof due to obscured address bar
  * CVE-2023-32213 (bmo#1826666)
    Potential memory corruption in FileReader::DoReadData()
  * MFSA-TMP-2023-0002 (bmo#1814560, bmo#1814790, bmo#1819796)
    Race condition in dav1d decoding
  * CVE-2023-32214 (bmo#1828716)
    Potential DoS via exposed protocol handlers
  * CVE-2023-32215 (bmo#1540883, bmo#1751943, bmo#1814856, bmo#1820210,
    bmo#1821480, bmo#1827019, bmo#1827024, bmo#1827144, bmo#1827359,
    bmo#1830186)
    Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
  * CVE-2023-32216 (bmo#1746479, bmo#1806852, bmo#1815987,

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1059
2023-05-10 06:26:50 +00:00
Dominique Leuenberger
932f9acd0c Accepting request 1085402 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1085402
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=396
2023-05-09 11:07:21 +00:00
Wolfgang Rosenauer
c1a18b007d Accepting request 1085361 from home:aaronpuchert:branches:mozilla:Factory
- Fix i586 build by reducing debug info to -g1. (boo#1210168)

OBS-URL: https://build.opensuse.org/request/show/1085361
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1057
2023-05-08 05:59:59 +00:00
Dominique Leuenberger
5fb3b3490a Accepting request 1082809 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1082809
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=395
2023-04-27 17:56:49 +00:00
Wolfgang Rosenauer
a2aae95ca7 Accepting request 1082806 from home:AndreasStieger:branches:mozilla:Factory
112.0.2

OBS-URL: https://build.opensuse.org/request/show/1082806
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1055
2023-04-25 17:09:11 +00:00
Dominique Leuenberger
9de11f7822 Accepting request 1080954 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1080954
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=394
2023-04-22 19:56:24 +00:00
Wolfgang Rosenauer
10e1ac0514 Accepting request 1080895 from home:AndreasStieger:branches:mozilla:Factory
112.0.1

OBS-URL: https://build.opensuse.org/request/show/1080895
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1053
2023-04-20 19:38:57 +00:00
Dominique Leuenberger
258ef68e59 Accepting request 1078521 from mozilla:Factory
- Mozilla Firefox 112.0
  * https://www.mozilla.org/en-US/firefox/112.0/releasenotes/
  MFSA 2023-13 (bsc#1210212)
  * CVE-2023-29531 (bmo#1794292)
    Out-of-bound memory access in WebGL on macOS
  * CVE-2023-29532 (bmo#1806394)
    Mozilla Maintenance Service Write-lock bypass
  * CVE-2023-29533 (bmo#1798219, bmo#1814597)
    Fullscreen notification obscured
  * CVE-2023-29534 (bmo#1816007, bmo#1816059, bmo#1821155, bmo#1821576,
    bmo#1821906, bmo#1822298, bmo#1822305)
    Fullscreen notification could have been obscured on Firefox
    for Android
  * MFSA-TMP-2023-0001 (bmo#1819244)
    Double-free in libwebp
  * CVE-2023-29535 (bmo#1820543)
    Potential Memory Corruption following Garbage Collector compaction
  * CVE-2023-29536 (bmo#1821959)
    Invalid free from JavaScript code
  * CVE-2023-29537 (bmo#1823365, bmo#1824200, bmo#1825569)
    Data Races in font initialization code
  * CVE-2023-29538 (bmo#1685403)
    Directory information could have been leaked to WebExtensions
  * CVE-2023-29539 (bmo#1784348)
    Content-Disposition filename truncation leads to Reflected
    File Download
  * CVE-2023-29540 (bmo#1790542)
    Iframe sandbox bypass using redirects and sourceMappingUrls
  * CVE-2023-29541 (bmo#1810191)
    Files with malicious extensions could have been downloaded

OBS-URL: https://build.opensuse.org/request/show/1078521
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=393
2023-04-13 12:09:31 +00:00
Wolfgang Rosenauer
df4a0a1c4b - Mozilla Firefox 112.0
* https://www.mozilla.org/en-US/firefox/112.0/releasenotes/
  MFSA 2023-13 (bsc#1210212)
  * CVE-2023-29531 (bmo#1794292)
    Out-of-bound memory access in WebGL on macOS
  * CVE-2023-29532 (bmo#1806394)
    Mozilla Maintenance Service Write-lock bypass
  * CVE-2023-29533 (bmo#1798219, bmo#1814597)
    Fullscreen notification obscured
  * CVE-2023-29534 (bmo#1816007, bmo#1816059, bmo#1821155, bmo#1821576,
    bmo#1821906, bmo#1822298, bmo#1822305)
    Fullscreen notification could have been obscured on Firefox
    for Android
  * MFSA-TMP-2023-0001 (bmo#1819244)
    Double-free in libwebp
  * CVE-2023-29535 (bmo#1820543)
    Potential Memory Corruption following Garbage Collector compaction
  * CVE-2023-29536 (bmo#1821959)
    Invalid free from JavaScript code
  * CVE-2023-29537 (bmo#1823365, bmo#1824200, bmo#1825569)
    Data Races in font initialization code
  * CVE-2023-29538 (bmo#1685403)
    Directory information could have been leaked to WebExtensions
  * CVE-2023-29539 (bmo#1784348)
    Content-Disposition filename truncation leads to Reflected
    File Download
  * CVE-2023-29540 (bmo#1790542)
    Iframe sandbox bypass using redirects and sourceMappingUrls
  * CVE-2023-29541 (bmo#1810191)
    Files with malicious extensions could have been downloaded

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1051
2023-04-11 21:09:55 +00:00
Dominique Leuenberger
808948fb2b Accepting request 1077029 from mozilla:Factory
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1077029
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=392
2023-04-04 19:17:24 +00:00
Wolfgang Rosenauer
01aefd0ce5 - exclude i586/i686 once again because it fails to link libxul due
to its size

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1049
2023-03-27 15:18:05 +00:00
Wolfgang Rosenauer
28f1396420 - Mozilla Firefox 111.0.1 (boo#1209688)
* Fixed a crash on macOS while pinch-zooming under some circumstances
    (bmo#1658986)
  * Fixed a bug causing Firefox to freeze on startup for some
    Windows users (bmo#1823159)
- fix build on Tumbleweed (mozilla-bmo1807652.patch)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1048
2023-03-26 17:00:08 +00:00
Wolfgang Rosenauer
708d958a66 Accepting request 1072979 from home:Thaodan:branches:mozilla:Factory
Packaging cleanup
- Reomve obsolote checks that unused now
- Escape macros inside comments from dead code or plain comments
- Make -devel package noarch, it doesn't contain any architecture specific files

OBS-URL: https://build.opensuse.org/request/show/1072979
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1047
2023-03-20 07:47:31 +00:00
Wolfgang Rosenauer
38ab2454d8 - Mozilla Firefox 111.0
* https://www.mozilla.org/en-US/firefox/111.0/releasenotes
  MFSA 2023-09 (bsc#1209173)
  * CVE-2023-28159 (bmo#1783561)
    Fullscreen Notification could have been hidden by download
    popups on Android
  * CVE-2023-25748 (bmo#1798798)
    Fullscreen Notification could have been hidden by window
    prompts on Android
  * CVE-2023-25749 (bmo#1810705)
    Firefox for Android may have opened third-party apps without
    a prompt
  * CVE-2023-25750 (bmo#1814733)
    Potential ServiceWorker cache leak during private browsing mode
  * CVE-2023-25751 (bmo#1814899)
    Incorrect code generation during JIT compilation
  * CVE-2023-28160 (bmo#1802385)
    Redirect to Web Extension files may have leaked local path
  * CVE-2023-28164 (bmo#1809122)
    URL being dragged from a removed cross-origin iframe into the
    same tab triggered navigation
  * CVE-2023-28161 (bmo#1811181)
    One-time permissions granted to a local file were extended to
    other local files loaded in the same tab
  * CVE-2023-28162 (bmo#1811327)
    Invalid downcast in Worklets
  * CVE-2023-25752 (bmo#1811627)
    Potential out-of-bounds when accessing throttled streams
  * CVE-2023-28163 (bmo#1817768)
    Windows Save As dialog resolved environment variables

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1046
2023-03-15 08:38:02 +00:00
Dominique Leuenberger
348a85f8c0 Accepting request 1070344 from mozilla:Factory
- Cherry-pick upstream changes for GCC 13 in gcc13-fix.patch.

- Fix 32 bit build bmo#1810584 (add mozilla-bmo1810584.patch)
- Mozilla Firefox 110.0.1 (boo#1208886)
    Digital ID in Denmark (bmo#1819096)

OBS-URL: https://build.opensuse.org/request/show/1070344
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=391
2023-03-11 17:22:13 +00:00
Dominique Leuenberger
0cc95b3368 Accepting request 1069866 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1069866
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=390
2023-03-08 13:51:33 +00:00
Wolfgang Rosenauer
7506067808 - Fix 32 bit build bmo#1810584 (add mozilla-bmo1810584.patch)
- Mozilla Firefox 110.0.1 (boo#1208886)
    Digital ID in Denmark (bmo#1819096)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1043
2023-03-07 10:04:24 +00:00
Wolfgang Rosenauer
1886b3b7c9 Accepting request 1069880 from home:marxin:branches:mozilla:Factory
- Cherry-pick upstream changes for GCC 13 in gcc13-fix.patch.

OBS-URL: https://build.opensuse.org/request/show/1069880
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1042
2023-03-07 10:01:14 +00:00
Wolfgang Rosenauer
5e3b24dd6a Accepting request 1069865 from openSUSE:Factory:RISCV
- Limit memory use on riscv64

OBS-URL: https://build.opensuse.org/request/show/1069865
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1041
2023-03-07 08:46:06 +00:00
Dominique Leuenberger
abe3bb20b2 Accepting request 1069444 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1069444
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=389
2023-03-06 17:54:05 +00:00
Wolfgang Rosenauer
4161893523 Accepting request 1069419 from home:AndreasStieger:branches:mozilla:Factory
Fix 32 bit build

OBS-URL: https://build.opensuse.org/request/show/1069419
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1039
2023-03-05 06:01:08 +00:00
Wolfgang Rosenauer
a0299253b8 Accepting request 1069272 from home:AndreasStieger:branches:mozilla:Factory
110.0.1

OBS-URL: https://build.opensuse.org/request/show/1069272
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1038
2023-03-03 22:24:28 +00:00
Wolfgang Rosenauer
8c7db35439 - Mozilla Firefox 110.0
* https://www.mozilla.org/en-US/firefox/110.0/releasenotes
  MFSA 2023-05 (bsc#1208144)
  * CVE-2023-25728 (bmo#1790345)
    Content security policy leak in violation reports using iframes
  * CVE-2023-25730 (bmo#1794622)
    Screen hijack via browser fullscreen mode
  * CVE-2023-25743 (bmo#1800203)
    Fullscreen notification not shown in Firefox Focus
  * CVE-2023-0767 (bmo#1804640)
    Arbitrary memory write via PKCS 12 in NSS
  * CVE-2023-25735 (bmo#1810711)
    Potential use-after-free from compartment mismatch in SpiderMonkey
  * CVE-2023-25737 (bmo#1811464)
    Invalid downcast in SVGUtils::SetupStrokeGeometry
  * CVE-2023-25738 (bmo#1811852)
    Printing on Windows could potentially crash Firefox with some
    device drivers
  * CVE-2023-25739 (bmo#1811939)
    Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext
  * CVE-2023-25729 (bmo#1792138)
    Extensions could have opened external schemes without user knowledge
  * CVE-2023-25732 (bmo#1804564)
    Out of bounds memory write from EncodeInputStream
  * CVE-2023-25734 (bmo#1784451, bmo#1809923, bmo#1810143, bmo#1812338)
    Opening local .url files could cause unexpected network loads
  * CVE-2023-25740 (bmo#1812354)
    Opening local .scf files could cause unexpected network loads
  * CVE-2023-25731 (bmo#1801542)
    Prototype pollution when rendering URLPreview

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1037
2023-02-15 21:11:31 +00:00
Dominique Leuenberger
32850f782e Accepting request 1062544 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1062544
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=388
2023-02-02 17:07:47 +00:00
Wolfgang Rosenauer
7938696dc2 Accepting request 1062535 from home:AndreasStieger:branches:mozilla:Factory
Mozilla Firefox 109.0.1

OBS-URL: https://build.opensuse.org/request/show/1062535
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1035
2023-02-01 20:43:46 +00:00
Dominique Leuenberger
953b85891d Accepting request 1059273 from mozilla:Factory
- Mozilla Firefox 109.0
  MFSA 2023-01 (bsc#1207119)
  * CVE-2023-23597 (bmo#1538028)
    Logic bug in process allocation allowed to read arbitrary
    files
  * CVE-2023-23598 (bmo#1800425)
    Arbitrary file read from GTK drag and drop on Linux
  * CVE-2023-23599 (bmo#1777800)
    Malicious command could be hidden in devtools output on
    Windows
  * CVE-2023-23600 (bmo#1787034)
    Notification permissions persisted between Normal and Private
    Browsing on Android
  * CVE-2023-23601 (bmo#1794268)
    URL being dragged from cross-origin iframe into same tab
    triggers navigation
  * CVE-2023-23602 (bmo#1800890)
    Content Security Policy wasn't being correctly applied to
    WebSockets in WebWorkers
  * CVE-2023-23603 (bmo#1800832)
    Calls to <code>console.log</code> allowed bypasing Content
    Security Policy via format directive
  * CVE-2023-23604 (bmo#1802346)
    Creation of duplicate <code>SystemPrincipal</code> from less
    secure contexts
  * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)
    Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
  * CVE-2023-23606 (bmo#1764974, bmo#1798591, bmo#1799201,
    bmo#1800446, bmo#1801248, bmo#1802100, bmo#1803393,
    bmo#1804626, bmo#1804971, bmo#1807004)

OBS-URL: https://build.opensuse.org/request/show/1059273
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=387
2023-01-20 16:36:31 +00:00
Wolfgang Rosenauer
b45fd771cd - Mozilla Firefox 109.0
MFSA 2023-01 (bsc#1207119)
  * CVE-2023-23597 (bmo#1538028)
    Logic bug in process allocation allowed to read arbitrary
    files
  * CVE-2023-23598 (bmo#1800425)
    Arbitrary file read from GTK drag and drop on Linux
  * CVE-2023-23599 (bmo#1777800)
    Malicious command could be hidden in devtools output on
    Windows
  * CVE-2023-23600 (bmo#1787034)
    Notification permissions persisted between Normal and Private
    Browsing on Android
  * CVE-2023-23601 (bmo#1794268)
    URL being dragged from cross-origin iframe into same tab
    triggers navigation
  * CVE-2023-23602 (bmo#1800890)
    Content Security Policy wasn't being correctly applied to
    WebSockets in WebWorkers
  * CVE-2023-23603 (bmo#1800832)
    Calls to <code>console.log</code> allowed bypasing Content
    Security Policy via format directive
  * CVE-2023-23604 (bmo#1802346)
    Creation of duplicate <code>SystemPrincipal</code> from less
    secure contexts
  * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)
    Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
  * CVE-2023-23606 (bmo#1764974, bmo#1798591, bmo#1799201,
    bmo#1800446, bmo#1801248, bmo#1802100, bmo#1803393,
    bmo#1804626, bmo#1804971, bmo#1807004)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1033
2023-01-18 07:21:07 +00:00
Dominique Leuenberger
30792c4d34 Accepting request 1056394 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1056394
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=386
2023-01-07 16:16:07 +00:00
Wolfgang Rosenauer
6767b9f284 Accepting request 1056391 from home:luc14n0:branches:mozilla:Factory
Update to version 108.0.2.

OBS-URL: https://build.opensuse.org/request/show/1056391
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1031
2023-01-06 12:39:34 +00:00
Dominique Leuenberger
47e33a892c Accepting request 1044163 from mozilla:Factory
- add mozilla-bmo1805809.patch to fix build for x86-32 (boo#1206600)

OBS-URL: https://build.opensuse.org/request/show/1044163
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=385
2022-12-23 09:20:48 +00:00
Wolfgang Rosenauer
58f0d1e270 - add mozilla-bmo1805809.patch to fix build for x86-32 (boo#1206600)
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1029
2022-12-21 16:08:13 +00:00
Dominique Leuenberger
7d1196d8c6 Accepting request 1043934 from mozilla:Factory
- Mozilla Firefox 108.0.1 (boo#1206507)
  * Fixes the default search engine being reset on upgrade for
    profiles which were previously copied from a different location

- Mozilla Firefox 108.0
  https://www.mozilla.org/en-US/firefox/108.0/releasenotes/
  MFSA 2022-51 (bsc#1206242)
  * CVE-2022-46871 (bmo#1795697)
    libusrsctp library out of date
  * CVE-2022-46872 (bmo#1799156)
    Arbitrary file read from a compromised content process
  * CVE-2022-46873 (bmo#1644790)
    Firefox did not implement the CSP directive unsafe-hashes
  * CVE-2022-46874 (bmo#1746139)
    Drag and Dropped Filenames could have been truncated to
    malicious extensions
  * CVE-2022-46875 (bmo#1786188)
    Download Protections were bypassed by .atloc and .ftploc
    files on Mac OS
  * CVE-2022-46877 (bmo#1795139)
    Fullscreen notification bypass
  * CVE-2022-46878 (bmo#1782219, bmo#1797370, bmo#1797685,
    bmo#1801102, bmo#1801315, bmo#1802395)
    Memory safety bugs fixed in Firefox 108 and Firefox ESR 102.6
  * CVE-2022-46879 (bmo#1736224, bmo#1793407, bmo#1794249, bmo#1795845,
    bmo#1797682, bmo#1797720, bmo#1798494, bmo#1799479)
    Memory safety bugs fixed in Firefox 108
- requires
  NSS >= 3.85
  rustc/cargo 1.65

OBS-URL: https://build.opensuse.org/request/show/1043934
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=384
2022-12-21 15:05:48 +00:00
Wolfgang Rosenauer
1045a27659 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1027 2022-12-20 15:28:29 +00:00
Wolfgang Rosenauer
1498efd183 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1026 2022-12-20 15:27:14 +00:00
Wolfgang Rosenauer
ec5a29f477 - Mozilla Firefox 108.0.1 (boo#1206507)
* Fixes the default search engine being reset on upgrade for
    profiles which were previously copied from a different location

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1025
2022-12-20 08:04:12 +00:00
Wolfgang Rosenauer
1c9c2f3dd5 - Mozilla Firefox 108.0
https://www.mozilla.org/en-US/firefox/108.0/releasenotes/
  MFSA 2022-51 (bsc#1206242)
  * CVE-2022-46871 (bmo#1795697)
    libusrsctp library out of date
  * CVE-2022-46872 (bmo#1799156)
    Arbitrary file read from a compromised content process
  * CVE-2022-46873 (bmo#1644790)
    Firefox did not implement the CSP directive unsafe-hashes
  * CVE-2022-46874 (bmo#1746139)
    Drag and Dropped Filenames could have been truncated to
    malicious extensions
  * CVE-2022-46875 (bmo#1786188)
    Download Protections were bypassed by .atloc and .ftploc
    files on Mac OS
  * CVE-2022-46877 (bmo#1795139)
    Fullscreen notification bypass
  * CVE-2022-46878 (bmo#1782219, bmo#1797370, bmo#1797685,
    bmo#1801102, bmo#1801315, bmo#1802395)
    Memory safety bugs fixed in Firefox 108 and Firefox ESR 102.6
  * CVE-2022-46879 (bmo#1736224, bmo#1793407, bmo#1794249, bmo#1795845,
    bmo#1797682, bmo#1797720, bmo#1798494, bmo#1799479)
    Memory safety bugs fixed in Firefox 108
- requires
  NSS >= 3.85
  rustc/cargo 1.65

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1024
2022-12-13 21:48:56 +00:00
Wolfgang Rosenauer
948218484d Accepting request 1041338 from home:milachew:branches:mozilla:Factory
- added translations to .desktop file.

OBS-URL: https://build.opensuse.org/request/show/1041338
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1023
2022-12-09 09:40:12 +00:00
Dominique Leuenberger
fc347e1056 Accepting request 1039406 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1039406
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=383
2022-12-02 12:12:25 +00:00
Wolfgang Rosenauer
8200399c53 Accepting request 1039401 from home:AndreasStieger:branches:mozilla:Factory
Mozilla Firefox 107.0.1

OBS-URL: https://build.opensuse.org/request/show/1039401
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1021
2022-12-01 21:39:40 +00:00
Dominique Leuenberger
9488c60e72 Accepting request 1036230 from mozilla:Factory
- Mozilla Firefox 107.0
  MFSA 2022-47 (bsc#1205270)
 * CVE-2022-45403 (bmo#1762078)
    Service Workers might have learned size of cross-origin media files
  * CVE-2022-45404 (bmo#1790815)
    Fullscreen notification bypass
  * CVE-2022-45405 (bmo#1791314)
    Use-after-free in InputStream implementation
  * CVE-2022-45406 (bmo#1791975)
    Use-after-free of a JavaScript Realm
  * CVE-2022-45407 (bmo#1793314)
    Loading fonts on workers was not thread-safe
  * CVE-2022-45408 (bmo#1793829)
    Fullscreen notification bypass via windowName
  * CVE-2022-45409 (bmo#1796901)
    Use-after-free in Garbage Collection
  * CVE-2022-45410 (bmo#1658869)
    ServiceWorker-intercepted requests bypassed SameSite cookie policy
  * CVE-2022-45411 (bmo#1790311)
    Cross-Site Tracing was possible via non-standard override headers
  * CVE-2022-45412 (bmo#1791029)
    Symlinks may resolve to partially uninitialized buffers
  * CVE-2022-45413 (bmo#1791201)
    SameSite=Strict cookies could have been sent cross-site via
    intent URLs
  * CVE-2022-40674 (bmo#1791598)
    Use-after-free vulnerability in expat
  * CVE-2022-45415 (bmo#1793551)
    Downloaded file may have been saved with malicious extension
  * CVE-2022-45416 (bmo#1793676)

OBS-URL: https://build.opensuse.org/request/show/1036230
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=382
2022-11-17 16:23:52 +00:00
Wolfgang Rosenauer
c9ea1238e9 - Mozilla Firefox 107.0
MFSA 2022-47 (bsc#1205270)
 * CVE-2022-45403 (bmo#1762078)
    Service Workers might have learned size of cross-origin media files
  * CVE-2022-45404 (bmo#1790815)
    Fullscreen notification bypass
  * CVE-2022-45405 (bmo#1791314)
    Use-after-free in InputStream implementation
  * CVE-2022-45406 (bmo#1791975)
    Use-after-free of a JavaScript Realm
  * CVE-2022-45407 (bmo#1793314)
    Loading fonts on workers was not thread-safe
  * CVE-2022-45408 (bmo#1793829)
    Fullscreen notification bypass via windowName
  * CVE-2022-45409 (bmo#1796901)
    Use-after-free in Garbage Collection
  * CVE-2022-45410 (bmo#1658869)
    ServiceWorker-intercepted requests bypassed SameSite cookie policy
  * CVE-2022-45411 (bmo#1790311)
    Cross-Site Tracing was possible via non-standard override headers
  * CVE-2022-45412 (bmo#1791029)
    Symlinks may resolve to partially uninitialized buffers
  * CVE-2022-45413 (bmo#1791201)
    SameSite=Strict cookies could have been sent cross-site via
    intent URLs
  * CVE-2022-40674 (bmo#1791598)
    Use-after-free vulnerability in expat
  * CVE-2022-45415 (bmo#1793551)
    Downloaded file may have been saved with malicious extension
  * CVE-2022-45416 (bmo#1793676)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=1019
2022-11-16 13:36:59 +00:00
Dominique Leuenberger
091a155ca4 Accepting request 1033697 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1033697
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaFirefox?expand=0&rev=381
2022-11-06 11:41:37 +00:00