Subject: CVS commit: pkgsrc/www/firefox68
From: Nia Alarie
Date: 2020-01-09 21:51:59
Message id: 20200109205159.A7678FBF4@cvs.NetBSD.org

Log Message:
firefox68: Update to 68.4.1

This release fixes one zero-day vulnerability:

CVE-2019-17026: IonMonkey type confusion with StoreElementHole and \ 
FallibleStoreElement

Incorrect alias information in IonMonkey JIT compiler for setting array elements \ 
could lead to a type confusion.
We are aware of targeted attacks in the wild abusing this flaw

Files:
RevisionActionfile
1.8modifypkgsrc/www/firefox68/Makefile
1.7modifypkgsrc/www/firefox68/distinfo