Subject: CVS commit: [pkgsrc-2021Q4] pkgsrc/www/firefox91
From: Benny Siegert
Date: 2022-03-13 19:34:40
Message id: 20220313183440.ACF9EFB24@cvs.NetBSD.org

Log Message:
Pullup ticket #6598 - requested by nia
www/firefox91: security fix

Revisions pulled up:
- www/firefox91/Makefile                                        1.14
- www/firefox91/distinfo                                        1.11

---
   Module Name:	pkgsrc
   Committed By:	nia
   Date:		Thu Mar 10 16:22:47 UTC 2022

   Modified Files:
   	pkgsrc/www/firefox91: Makefile distinfo

   Log Message:
   firefox91: update to 91.7.0

   Security Vulnerabilities fixed in Firefox ESR 91.7

       #CVE-2022-26383: Browser window spoof using fullscreen mode

       #CVE-2022-26384: iframe allow-scripts sandbox bypass

       #CVE-2022-26387: Time-of-check time-of-use bug when verifying add-on
       signatures

       #CVE-2022-26381: Use-after-free in text reflows

       #CVE-2022-26386: Temporary files downloaded to /tmp and accessible by other
       local users

Files:
RevisionActionfile
1.11.2.3modifypkgsrc/www/firefox91/Makefile
1.8.2.3modifypkgsrc/www/firefox91/distinfo