Path to this page:
Subject: CVS commit: [pkgsrc-2017Q4] pkgsrc/www
From: Benny Siegert
Date: 2018-01-28 13:36:22
Message id: 20180128123622.4B731FBDE@cvs.NetBSD.org
Log Message:
Pullup ticket #5692 - requested by he
www/firefox52: security fix
www/firefox52-l10n: dependent update
Revisions pulled up:
- www/firefox52-l10n/Makefile 1.8
- www/firefox52-l10n/PLIST 1.2
- www/firefox52-l10n/distinfo 1.8
- www/firefox52/Makefile 1.14
- www/firefox52/PLIST 1.4
- www/firefox52/distinfo 1.10
---
Module Name: pkgsrc
Committed By: ryoon
Date: Wed Jan 24 16:31:23 UTC 2018
Modified Files:
pkgsrc/www/firefox52: Makefile PLIST distinfo
Log Message:
Update to 52.6.0
Changelog:
CVE-2018-5091: Use-after-free with DTMF timers
CVE-2018-5095: Integer overflow in Skia library during edge builder allocation
CVE-2018-5096: Use-after-free while editing form elements
CVE-2018-5097: Use-after-free when source document is manipulated during XSLT
CVE-2018-5098: Use-after-free while manipulating form input elements
CVE-2018-5099: Use-after-free with widget listener
CVE-2018-5102: Use-after-free in HTML media elements
CVE-2018-5103: Use-after-free during mouse event handling
CVE-2018-5104: Use-after-free during font face manipulation
CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right
CVE-2018-5089: Memory safety bugs fixed in Firefox 58 and Firefox ESR 52.6
Fix for Speculative execution side-channel attack ("Spectre")
---
Module Name: pkgsrc
Committed By: ryoon
Date: Wed Jan 24 16:35:28 UTC 2018
Modified Files:
pkgsrc/www/firefox52-l10n: Makefile PLIST distinfo
Log Message:
Update to 52.6.0
* Sync with www/firefox52-52.6.0
Files: