2023-04-19 10:12:01 by Adam Ciarcinski | Files touched by this commit (2359) | |
Log message:
revbump after textproc/icu update
|
2023-04-14 10:53:12 by Nia Alarie | Files touched by this commit (4) |
Log message:
firefox102: Update to 102.10.0
Security Vulnerabilities fixed in Firefox ESR 102.10
#CVE-2023-29531: Out-of-bound memory access in WebGL on macOS
#CVE-2023-29533: Fullscreen notification obscured
#CVE-2023-29535: Potential Memory Corruption following Garbage Collector
compaction
#CVE-2023-29536: Invalid free from JavaScript code
#CVE-2023-29539: Content-Disposition filename truncation leads to Reflected
File Download
#CVE-2023-29541: Files with malicious extensions could have been downloaded
unsafely on Linux
#CVE-2023-29542: Bypass of file download extension restrictions
#CVE-2023-1945: Memory Corruption in Safe Browsing Code
#CVE-2023-29548: Incorrect optimization result on ARM64
#CVE-2023-29550: Memory safety bugs fixed in Firefox 112 and Firefox ESR
102.10
|
2023-01-29 22:18:34 by Ryo ONODERA | Files touched by this commit (2527) |
Log message:
*: Recursive revbup from graphics/freetype2
|
2023-01-24 18:59:28 by Nia Alarie | Files touched by this commit (4) |
Log message:
firefox102: Update to 102.7.0
Security Vulnerabilities fixed in Firefox ESR 102.7
#CVE-2022-46871: libusrsctp library out of date
#CVE-2023-23598: Arbitrary file read from GTK drag and drop on Linux
#CVE-2023-23599: Malicious command could be hidden in devtools output on
Windows
#CVE-2023-23601: URL being dragged from cross-origin iframe into same tab
triggers navigation
#CVE-2023-23602: Content Security Policy wasn't being correctly applied to
WebSockets in WebWorkers
#CVE-2022-46877: Fullscreen notification bypass
#CVE-2023-23603: Calls to <code>console.log</code> allowed \
bypasing Content
Security Policy via format directive
#CVE-2023-23605: Memory safety bugs fixed in Firefox 109 and Firefox ESR
102.7
|
2023-01-03 18:38:37 by Thomas Klausner | Files touched by this commit (1416) |
Log message:
*: recursive bump for tiff shlib major bump
|
2022-12-24 16:47:54 by Nia Alarie | Files touched by this commit (5) | |
Log message:
firefox102: update to 102.6.0
Security Vulnerabilities fixed in Firefox ESR 102.6
#CVE-2022-46880: Use-after-free in WebGL
#CVE-2022-46872: Arbitrary file read from a compromised content process
#CVE-2022-46881: Memory corruption in WebGL
#CVE-2022-46874: Drag and Dropped Filenames could have been truncated to
malicious extensions
#CVE-2022-46875: Download Protections were bypassed by .atloc and .ftploc
files on Mac OS
#CVE-2022-46882: Use-after-free in WebGL
#CVE-2022-46878: Memory safety bugs fixed in Firefox 108 and Firefox ESR
102.6
|
2022-12-21 11:10:37 by Nia Alarie | Files touched by this commit (4) |
Log message:
firefox102: Disable service worker support until the root cause of the
crashes is investigated.
|
2022-12-04 10:50:00 by Nia Alarie | Files touched by this commit (4) |
Log message:
firefox102: Update to 102.5.0
Security Vulnerabilities fixed in Firefox ESR 102.5
#CVE-2022-45403: Service Workers might have learned size of cross-origin
media files
#CVE-2022-45404: Fullscreen notification bypass
#CVE-2022-45405: Use-after-free in InputStream implementation
#CVE-2022-45406: Use-after-free of a JavaScript Realm
#CVE-2022-45408: Fullscreen notification bypass via windowName
#CVE-2022-45409: Use-after-free in Garbage Collection
#CVE-2022-45410: ServiceWorker-intercepted requests bypassed SameSite cookie
policy
#CVE-2022-45411: Cross-Site Tracing was possible via non-standard override
headers
#CVE-2022-45412: Symlinks may resolve to partially uninitialized buffers
#CVE-2022-45416: Keystroke Side-Channel Leakage
#CVE-2022-45418: Custom mouse cursor could have been drawn over browser UI
#CVE-2022-45420: Iframe contents could be rendered outside the iframe
#CVE-2022-45421: Memory safety bugs fixed in Firefox 107 and Firefox ESR
102.5
|
2022-11-23 17:21:30 by Adam Ciarcinski | Files touched by this commit (1878) | |
Log message:
massive revision bump after textproc/icu update
|
2022-11-02 21:36:33 by David H. Gutteridge | Files touched by this commit (1) |
Log message:
firefox102: reflect new minimum dependency of cbindgen >= 0.24
We're carrying a patch that will only build with recent cbindgen.
Issue noted by Todd Gruhn on pkgsrc-users@.
|