1
0
Go to file
Wolfgang Rosenauer cb96a9588a Accepting request 489077 from home:AndreasStieger:branches:mozilla:Factory
Adding changelog entries for 52:

- security fixes (bsc#1028391, MFSA 2017-09):
  In general, these flaws cannot be exploited through email because
  scripting is disabled when reading mail, but are potentially
  risks in browser or browser-like contexts.
  * CVE-2017-5400: asm.js JIT-spray bypass of ASLR and DEP (bmo#1334933)
  * CVE-2017-5401: Memory Corruption when handling ErrorResult (bmo#1328861)
  * CVE-2017-5402: Use-after-free working with events in FontFace objects (bmo#1334876)
  * CVE-2017-5403: Use-after-free using addRange to add range to an incorrect root object (bmo#1340186)
  * CVE-2017-5404: Use-after-free working with ranges in selections (bmo#1340138)
  * CVE-2017-5406: Segmentation fault in Skia with canvas operations (bmo#1306890)
  * CVE-2017-5407: Pixel and history stealing via floating-point timing side channel with SVG filters (bmo#1336622)
  * CVE-2017-5410: Memory corruption during JavaScript garbage collection incremental sweeping (bmo#1330687)
  * CVE-2017-5408: Cross-origin reading of video captions in violation of CORS (bmo#1313711)
  * CVE-2017-5412: Buffer overflow read in SVG filters (bmo#1328323)
  * CVE-2017-5413: Segmentation fault during bidirectional operations (bmo#1337504)
  * CVE-2017-5414: File picker can choose incorrect default directory (bmo#1319370)
  * CVE-2017-5416: Null dereference crash in HttpChannel (bmo#1328121)
  * CVE-2017-5426: Gecko Media Plugin sandbox is not started if seccomp-bpf filter is running (bmo#1257361)
  * CVE-2017-5418: Out of bounds read when parsing HTTP digest authorization responses (bmo#1338876)
  * CVE-2017-5419: Repeated authentication prompts lead to DOS attack (bmo#1312243)
  * CVE-2017-5405: FTP response codes can cause use of uninitialized values for ports (bmo#1336699)
  * CVE-2017-5421: Print preview spoofing (bmo#1301876)
  * CVE-2017-5422: DOS attack by using view-source: protocol repeatedly in one hyperlink (bmo#1295002)
  * CVE-2017-5399: Memory safety bugs fixed in Thunderbird 52
  * CVE-2017-5398: Memory safety bugs fixed in Thunderbird 52 and Thunderbird 45.8

OBS-URL: https://build.opensuse.org/request/show/489077
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=363
2017-04-18 12:03:08 +00:00
_constraints - For openSUSE > 13.2, the build fails for i586 as it goes out of 2016-04-30 13:53:52 +00:00
.gitattributes OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=34 2009-07-21 10:08:52 +00:00
.gitignore OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=1 2007-01-15 22:49:32 +00:00
compare-locales.tar.xz - update to Thunderbird 52.0.1 2017-04-17 12:52:44 +00:00
create-tar.sh - update to Thunderbird 52.0.1 2017-04-17 12:52:44 +00:00
find-external-requires.sh fix build 2011-06-20 09:37:54 +00:00
kde.js - update to Thunderbird 11.0 (bnc#750044) 2012-03-14 07:47:37 +00:00
l10n-52.0.1.tar.xz - update to Thunderbird 52.0.1 2017-04-17 12:52:44 +00:00
mozilla-aarch64-startup-crash.patch - update to Thunderbird 52.0 2017-03-18 21:27:55 +00:00
mozilla-develdirs.patch - update to Thunderbird 52.0 2017-03-18 21:27:55 +00:00
mozilla-kde.patch Accepting request 483796 from home:AndreasStieger:branches:mozilla:Factory 2017-04-02 21:22:13 +00:00
mozilla-language.patch - update to Thunderbird 52.0 2017-03-18 21:27:55 +00:00
mozilla-no-stdcxx-check.patch - For openSUSE > 13.2, the build fails for i586 as it goes out of 2016-04-30 13:53:52 +00:00
mozilla-nongnome-proxies.patch - update to Thunderbird 31.0 2014-07-28 13:29:31 +00:00
mozilla.sh.in Accepting request 262389 from home:Ledest:bashisms 2014-11-19 22:02:44 +00:00
MozillaThunderbird.changes Accepting request 489077 from home:AndreasStieger:branches:mozilla:Factory 2017-04-18 12:03:08 +00:00
MozillaThunderbird.spec - update to Thunderbird 52.0.1 2017-04-17 12:52:44 +00:00
suse-default-prefs.js OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=263 2014-10-25 18:42:54 +00:00
tb-ssldap.patch - For openSUSE > 13.2, the build fails for i586 as it goes out of 2016-04-30 13:53:52 +00:00
thunderbird-52.0.1-source.tar.xz - update to Thunderbird 52.0.1 2017-04-17 12:52:44 +00:00
thunderbird-rpmlintrc - update to Thunderbird 11.0 (bnc#750044) 2012-03-14 07:47:37 +00:00
thunderbird.appdata.xml Accepting request 412542 from home:Mailaender:branches:mozilla:Factory 2016-07-21 20:54:18 +00:00
thunderbird.desktop - update to Thunderbird 11.0 (bnc#750044) 2012-03-14 07:47:37 +00:00