Subject: CVS commit: pkgsrc/www/firefox115
From: Benny Siegert
Date: 2024-11-26 20:11:54
Message id: 20241126191154.81A49FC7D@cvs.NetBSD.org

Log Message:
firefox115: update to 115.18.0

Security Vulnerabilities fixed in Firefox ESR 115.18

#CVE-2024-11691: Out-of-bounds write in Apple GPU drivers via WebGL

Impact: high

Certain WebGL operations on Apple silicon M series devices could have lead to
an out-of-bounds write and memory corruption due to a flaw in Apple's GPU
driver.
This bug only affected the application on Apple M series hardware. Other
platforms were unaffected.

#CVE-2024-11694: CSP Bypass and XSS Exposure via Web Compatibility Shims

Impact: moderate

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP
frame-src bypass and DOM-based XSS through the Google SafeFrame shim in the Web
Compatibility extension. This issue could have exposed users to malicious
frames masquerading as legitimate content.

Files:
RevisionActionfile
1.38modifypkgsrc/www/firefox115/Makefile
1.20modifypkgsrc/www/firefox115/distinfo