Subject: CVS commit: pkgsrc/www
From: Nia Alarie
Date: 2023-01-24 18:59:28
Message id: 20230124175928.41725FA90@cvs.NetBSD.org

Log Message:
firefox102: Update to 102.7.0

Security Vulnerabilities fixed in Firefox ESR 102.7

    #CVE-2022-46871: libusrsctp library out of date

    #CVE-2023-23598: Arbitrary file read from GTK drag and drop on Linux

    #CVE-2023-23599: Malicious command could be hidden in devtools output on
    Windows

    #CVE-2023-23601: URL being dragged from cross-origin iframe into same tab
    triggers navigation

    #CVE-2023-23602: Content Security Policy wasn't being correctly applied to
    WebSockets in WebWorkers

    #CVE-2022-46877: Fullscreen notification bypass

    #CVE-2023-23603: Calls to <code>console.log</code> allowed \ 
bypasing Content
    Security Policy via format directive

    #CVE-2023-23605: Memory safety bugs fixed in Firefox 109 and Firefox ESR
    102.7

Files:
RevisionActionfile
1.15modifypkgsrc/www/firefox102/Makefile
1.10modifypkgsrc/www/firefox102/distinfo
1.9modifypkgsrc/www/firefox102-l10n/Makefile
1.8modifypkgsrc/www/firefox102-l10n/distinfo