Path to this page:
Subject: CVS commit: pkgsrc/www/firefox60
From: Ryo ONODERA
Date: 2019-03-24 13:36:42
Message id: 20190324123642.567D0FB16@cvs.NetBSD.org
Log Message:
Update to 60.6.1
Changelog:
60.6.1
#CVE-2019-9810: IonMonkey MArraySlice has incorrect alias information
#CVE-2019-9813: Ionmonkey type confusion with __proto__ mutations
60.6.0
#CVE-2019-9790: Use-after-free when removing in-use DOM elements
#CVE-2019-9791: Type inference is incorrect for constructors entered through \
on-stack replacement with IonMonkey
#CVE-2019-9792: IonMonkey leaks JS_OPTIMIZED_OUT magic value to script
#CVE-2019-9793: Improper bounds checks when Spectre mitigations are disabled
#CVE-2019-9794: Command line arguments not discarded during execution
#CVE-2019-9795: Type-confusion in IonMonkey JIT compiler
#CVE-2019-9801: Windows programs that are not 'URL Handlers' are exposed to web \
content
#CVE-2018-18506: Proxy Auto-Configuration file can define localhost access to be \
proxied
#CVE-2019-9788: Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6
Enterprise
In the network connections settings, sites added to the "No proxy \
for" list will now honor that setting regardless of any other specified \
proxy settings
Files: