forked from pool/MozillaThunderbird
c90bbb3be9
* fix crash in nsImapProtocol::CreateNewLineFromSocket (bmo#1667120) - Mozilla Thunderbird 78.3.0 MFSA 2020-44 (bsc#1176756) * CVE-2020-15677 (bmo#1641487) Download origin spoofing via redirect * CVE-2020-15676 (bmo#1646140) XSS when pasting attacker-controlled data into a contenteditable element * CVE-2020-15678 (bmo#1660211) When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after- free scenario * CVE-2020-15673 (bmo#1648493, bmo#1660800) Memory safety bugs fixed in Thunderbird 78.3 - requires NSPR >= 4.25.1 - removed obsolete thunderbird-bmo1664607.patch - Mozilla Thunderbird 78.2.2 https://www.thunderbird.net/en-US/thunderbird/78.2.2/releasenotes - added thunderbird-bmo1664607.patch required for builds w/o updater (boo#1176384) - Mozilla Thunderbird 78.2.1 * based on Mozilla's 78 ESR codebase * many new and changed features https://www.thunderbird.net/en-US/thunderbird/78.0/releasenotes/#whatsnew * built-in OpenPGP support (enigmail neither required nor supported) OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=549
86 lines
3.2 KiB
Diff
86 lines
3.2 KiB
Diff
# HG changeset patch
|
|
# User msirringhaus@suse.de
|
|
# Date 1582805876 -3600
|
|
# Thu Feb 27 13:17:56 2020 +0100
|
|
# Node ID cc3d09abea31068e57f1ab918782f9f86fc6a158
|
|
# Parent 9cd90914846f667f18babc491a74c164ae5d6e9f
|
|
imported patch decoder_workaround.patch
|
|
|
|
diff -r 9cd90914846f image/decoders/nsGIFDecoder2.cpp
|
|
--- a/image/decoders/nsGIFDecoder2.cpp Thu Feb 27 12:57:14 2020 +0100
|
|
+++ b/image/decoders/nsGIFDecoder2.cpp Fri Mar 27 13:06:18 2020 +0100
|
|
@@ -422,6 +422,9 @@
|
|
MOZ_ASSERT(mSwizzleFn);
|
|
uint8_t* data = reinterpret_cast<uint8_t*>(aColormap);
|
|
mSwizzleFn(data, data, aColors);
|
|
+#if MOZ_BIG_ENDIAN()
|
|
+ SwizzleRow(SurfaceFormat::A8R8G8B8, SurfaceFormat::B8G8R8A8)(data, data, aColors);
|
|
+#endif
|
|
}
|
|
|
|
LexerResult nsGIFDecoder2::DoDecode(SourceBufferIterator& aIterator,
|
|
diff -r 9cd90914846f image/decoders/nsJPEGDecoder.cpp
|
|
--- a/image/decoders/nsJPEGDecoder.cpp Thu Feb 27 12:57:14 2020 +0100
|
|
+++ b/image/decoders/nsJPEGDecoder.cpp Fri Mar 27 13:06:18 2020 +0100
|
|
@@ -263,6 +263,9 @@
|
|
case JCS_YCbCr:
|
|
// By default, we will output directly to BGRA. If we need to apply
|
|
// special color transforms, this may change.
|
|
+#if MOZ_BIG_ENDIAN()
|
|
+ mInfo.out_color_space = MOZ_JCS_EXT_NATIVE_ENDIAN_XRGB;
|
|
+#else
|
|
switch (SurfaceFormat::OS_RGBX) {
|
|
case SurfaceFormat::B8G8R8X8:
|
|
mInfo.out_color_space = JCS_EXT_BGRX;
|
|
@@ -277,6 +280,7 @@
|
|
mState = JPEG_ERROR;
|
|
return Transition::TerminateFailure();
|
|
}
|
|
+#endif
|
|
break;
|
|
case JCS_CMYK:
|
|
case JCS_YCCK:
|
|
diff -r 9cd90914846f image/decoders/nsPNGDecoder.cpp
|
|
--- a/image/decoders/nsPNGDecoder.cpp Thu Feb 27 12:57:14 2020 +0100
|
|
+++ b/image/decoders/nsPNGDecoder.cpp Fri Mar 27 13:06:18 2020 +0100
|
|
@@ -361,7 +361,7 @@
|
|
IResumable* aOnResume) {
|
|
MOZ_ASSERT(!HasError(), "Shouldn't call DoDecode after error!");
|
|
|
|
- return mLexer.Lex(aIterator, aOnResume,
|
|
+ LexerResult res = mLexer.Lex(aIterator, aOnResume,
|
|
[=](State aState, const char* aData, size_t aLength) {
|
|
switch (aState) {
|
|
case State::PNG_DATA:
|
|
@@ -371,6 +371,14 @@
|
|
}
|
|
MOZ_CRASH("Unknown State");
|
|
});
|
|
+
|
|
+#if MOZ_BIG_ENDIAN()
|
|
+ if(res.is<TerminalState>() && res.as<TerminalState>() == TerminalState::SUCCESS) {
|
|
+ NativeEndian::swapToLittleEndianInPlace<uint32_t>((uint32_t*)(mImageData), mImageDataLength / 4);
|
|
+ }
|
|
+#endif
|
|
+
|
|
+ return res;
|
|
}
|
|
|
|
LexerTransition<nsPNGDecoder::State> nsPNGDecoder::ReadPNGData(
|
|
diff -r 9cd90914846f image/decoders/nsWebPDecoder.cpp
|
|
--- a/image/decoders/nsWebPDecoder.cpp Thu Feb 27 12:57:14 2020 +0100
|
|
+++ b/image/decoders/nsWebPDecoder.cpp Fri Mar 27 13:06:18 2020 +0100
|
|
@@ -237,7 +237,12 @@
|
|
// WebP doesn't guarantee that the alpha generated matches the hint in the
|
|
// header, so we always need to claim the input is BGRA. If the output is
|
|
// BGRX, swizzling will mask off the alpha channel.
|
|
+#if MOZ_BIG_ENDIAN()
|
|
+ mBuffer.colorspace = MODE_ARGB;
|
|
+ SurfaceFormat inFormat = mFormat;
|
|
+#else
|
|
SurfaceFormat inFormat = SurfaceFormat::OS_RGBA;
|
|
+#endif
|
|
|
|
SurfacePipeFlags pipeFlags = SurfacePipeFlags();
|
|
if (mFormat == SurfaceFormat::OS_RGBA &&
|