Subject: CVS commit: [pkgsrc-2020Q2] pkgsrc/www/firefox68
From: Benny Siegert
Date: 2020-07-09 10:07:52
Message id: 20200709080752.1D403FB28@cvs.NetBSD.org

Log Message:
Pullup ticket #6266 - requested by nia
www/firefox68: security fix

Revisions pulled up:
- www/firefox68/Makefile                                        1.29
- www/firefox68/distinfo                                        1.19

---
   Module Name:	pkgsrc
   Committed By:	nia
   Date:		Tue Jul  7 16:44:11 UTC 2020

   Modified Files:
   	pkgsrc/www/firefox68: Makefile distinfo

   Log Message:
   firefox68: Update to 68.10.0

   For anyone curious about the delay: apparently, my ccache cache
   was corrupted so the build was failing. *sigh* that won't be a problem
   soon...

   Security Vulnerabilities fixed in Firefox ESR 68.10

       #CVE-2020-12417: Memory corruption due to missing sign-extension for
       ValueTags on ARM64

       #CVE-2020-12418: Information disclosure due to manipulated URL object

       #CVE-2020-12419: Use-after-free in nsGlobalWindowInner

       #CVE-2020-12420: Use-After-Free when trying to connect to a STUN server

       #CVE-2020-12421: Add-On updates did not respect the same certificate trust
       rules as software updates

Files:
RevisionActionfile
1.26.2.1modifypkgsrc/www/firefox68/Makefile
1.18.2.1modifypkgsrc/www/firefox68/distinfo