Path to this page:
Subject: CVS commit: [pkgsrc-2020Q2] pkgsrc/www/firefox68
From: Benny Siegert
Date: 2020-07-09 10:07:52
Message id: 20200709080752.1D403FB28@cvs.NetBSD.org
Log Message:
Pullup ticket #6266 - requested by nia
www/firefox68: security fix
Revisions pulled up:
- www/firefox68/Makefile 1.29
- www/firefox68/distinfo 1.19
---
Module Name: pkgsrc
Committed By: nia
Date: Tue Jul 7 16:44:11 UTC 2020
Modified Files:
pkgsrc/www/firefox68: Makefile distinfo
Log Message:
firefox68: Update to 68.10.0
For anyone curious about the delay: apparently, my ccache cache
was corrupted so the build was failing. *sigh* that won't be a problem
soon...
Security Vulnerabilities fixed in Firefox ESR 68.10
#CVE-2020-12417: Memory corruption due to missing sign-extension for
ValueTags on ARM64
#CVE-2020-12418: Information disclosure due to manipulated URL object
#CVE-2020-12419: Use-after-free in nsGlobalWindowInner
#CVE-2020-12420: Use-After-Free when trying to connect to a STUN server
#CVE-2020-12421: Add-On updates did not respect the same certificate trust
rules as software updates
Files: