Subject: CVS commit: pkgsrc/www/firefox128
From: David H. Gutteridge
Date: 2024-10-30 17:29:43
Message id: 20241030162943.29E1BFC7E@cvs.NetBSD.org

Log Message:
firefox128: update to 128.4.0

Fixes for Mozilla Foundation Security Advisory 2024-56

CVE-2024-10458: Permission leak via embed or object elements
CVE-2024-10459: Use-after-free in layout with accessibility
CVE-2024-10460: Confusing display of origin for external protocol handler prompt
CVE-2024-10461: XSS due to Content-Disposition being ignored in \ 
multipart/x-mixed-replace response
CVE-2024-10462: Origin of permission prompt could be spoofed by long URL
CVE-2024-10463: Cross origin video frame leak
CVE-2024-10464: History interface could have been used to cause a Denial of \ 
Service condition in the browser
CVE-2024-10465: Clipboard "paste" button persisted across tabs
CVE-2024-10466: DOM push subscription message could hang Firefox
CVE-2024-10467: Memory safety bugs fixed in Firefox 132, Thunderbird 132, \ 
Firefox ESR 128.4, and Thunderbird 128.4

Files:
RevisionActionfile
1.6modifypkgsrc/www/firefox128/Makefile
1.6modifypkgsrc/www/firefox128/distinfo