Subject: CVS commit: pkgsrc/www/firefox60
From: Ryo ONODERA
Date: 2019-03-24 13:36:42
Message id: 20190324123642.567D0FB16@cvs.NetBSD.org

Log Message:
Update to 60.6.1

Changelog:
60.6.1
#CVE-2019-9810: IonMonkey MArraySlice has incorrect alias information
#CVE-2019-9813: Ionmonkey type confusion with __proto__ mutations

60.6.0
#CVE-2019-9790: Use-after-free when removing in-use DOM elements
#CVE-2019-9791: Type inference is incorrect for constructors entered through \ 
on-stack replacement with IonMonkey
#CVE-2019-9792: IonMonkey leaks JS_OPTIMIZED_OUT magic value to script
#CVE-2019-9793: Improper bounds checks when Spectre mitigations are disabled
#CVE-2019-9794: Command line arguments not discarded during execution
#CVE-2019-9795: Type-confusion in IonMonkey JIT compiler
#CVE-2019-9801: Windows programs that are not 'URL Handlers' are exposed to web \ 
content
#CVE-2018-18506: Proxy Auto-Configuration file can define localhost access to be \ 
proxied
#CVE-2019-9788: Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6

Enterprise
    In the network connections settings, sites added to the "No proxy \ 
for" list will now honor that setting regardless of any other specified \ 
proxy settings

Files:
RevisionActionfile
1.17modifypkgsrc/www/firefox60/Makefile
1.3modifypkgsrc/www/firefox60/PLIST
1.9modifypkgsrc/www/firefox60/distinfo