Path to this page:
Subject: CVS commit: [pkgsrc-2009Q1] pkgsrc/www/firefox3
From: S.P.Zeidler
Date: 2009-06-14 12:59:44
Message id: 20090614105944.CF518175D0@cvs.netbsd.org
Log Message:
Pullup ticket 2796 - requested by tron
Security update
Revisions pulled up:
- pkgsrc/www/firefox3/Makefile 1.33
- pkgsrc/www/firefox3/PLIST 1.9
- pkgsrc/www/firefox3/distinfo 1.25
Module Name: pkgsrc
Committed By: tron
Date: Fri Jun 12 10:08:28 UTC 2009
Modified Files:
pkgsrc/www/firefox3: Makefile PLIST distinfo
Log Message:
Update "firefox3" package to version 3.0.11. Changes since version \
3.0.10:
- Fixed several security issues:
MFSA 2009-32 JavaScript chrome privilege escalation
MFSA 2009-31 XUL scripts bypass content-policy checks
MFSA 2009-30 Incorrect principal set for file: resources loaded via
location bar
MFSA 2009-29 Arbitrary code execution using event listeners attached
to an element whose owner document is null
MFSA 2009-28 Race condition while accessing the private data of a
NPObject JS wrapper class object
MFSA 2009-27 SSL tampering via non-200 responses to proxy
CONNECT requests
MFSA 2009-26 Arbitrary domain cookie access by local file: resources
MFSA 2009-25 URL spoofing with invalid unicode characters
MFSA 2009-24 Crashes with evidence of memory corruption (rv:1.9.0.11)
- Fixed several stability issues.
- Several issues were reported with the internal database, SQLite, which
have now been fixed by upgrading to a newer version.
- Fixed an issue where, in some specific cases, the bookmarks database
would become corrupt. (bug 464486)
To generate a diff of this commit:
cvs rdiff -u -r1.32 -r1.33 pkgsrc/www/firefox3/Makefile
cvs rdiff -u -r1.8 -r1.9 pkgsrc/www/firefox3/PLIST
cvs rdiff -u -r1.24 -r1.25 pkgsrc/www/firefox3/distinfo
Files: