Subject: CVS commit: pkgsrc/www/firefox52
From: Ryo ONODERA
Date: 2018-01-24 17:31:23
Message id: 20180124163123.F1406FBDE@cvs.NetBSD.org

Log Message:
Update to 52.6.0

Changelog:
CVE-2018-5091: Use-after-free with DTMF timers
CVE-2018-5095: Integer overflow in Skia library during edge builder allocation
CVE-2018-5096: Use-after-free while editing form elements
CVE-2018-5097: Use-after-free when source document is manipulated during XSLT
CVE-2018-5098: Use-after-free while manipulating form input elements
CVE-2018-5099: Use-after-free with widget listener
CVE-2018-5102: Use-after-free in HTML media elements
CVE-2018-5103: Use-after-free during mouse event handling
CVE-2018-5104: Use-after-free during font face manipulation
CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right
CVE-2018-5089: Memory safety bugs fixed in Firefox 58 and Firefox ESR 52.6

Fix for Speculative execution side-channel attack ("Spectre")

Files:
RevisionActionfile
1.14modifypkgsrc/www/firefox52/Makefile
1.4modifypkgsrc/www/firefox52/PLIST
1.10modifypkgsrc/www/firefox52/distinfo