| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: firefox-esr-translations-common | Distribution: openSUSE Tumbleweed |
| Version: 140.9.1 | Vendor: openSUSE |
| Release: 1.1 | Build date: Tue Apr 7 14:13:24 2026 |
| Group: System/Localization | Build host: reproducible |
| Size: 9938724 | Source RPM: firefox-esr-140.9.1-1.1.src.rpm |
| Packager: http://bugs.opensuse.org | |
| Url: http://www.mozilla.org/ | |
| Summary: Common translations for Firefox ESR | |
This package contains several common languages for the user interface of Firefox ESR.
MPL-2.0
* Tue Apr 07 2026 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.9.1 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.9.1
https://www.mozilla.org/security/advisories/mfsa2026-27
MFSA 2026-27 (boo#1261663)
* CVE-2026-5732 (bmo#2017867)
Incorrect boundary conditions, integer overflow in the
Graphics: Text component
* CVE-2026-5731 (bmo#2021894, bmo#2022225, bmo#2022252,
bmo#2022294, bmo#2023007, bmo#2023130, bmo#2023191,
bmo#2023364, bmo#2023829, bmo#2024074, bmo#2024417,
bmo#2024433, bmo#2024436, bmo#2024437, bmo#2024453,
bmo#2024461, bmo#2024462, bmo#2024472, bmo#2024474,
bmo#2024477, bmo#2025364, bmo#2025401, bmo#2025402,
bmo#2025472, bmo#2026287, bmo#2026299, bmo#2026305,
bmo#2026426)
Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR
140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and
Thunderbird 149.0.2
* CVE-2026-5734 (bmo#2022369, bmo#2023026, bmo#2023545,
bmo#2023555, bmo#2023958, bmo#2025422, bmo#2025468,
bmo#2025492, bmo#2025505)
Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird
ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
* Tue Mar 24 2026 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.9.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.9
https://www.mozilla.org/security/advisories/mfsa2026-22
MFSA 2026-22 (boo#1260083)
* CVE-2026-4684 (bmo#2011129)
Race condition, use-after-free in the Graphics: WebRender
component
* CVE-2026-4685 (bmo#2016349)
Incorrect boundary conditions in the Graphics: Canvas2D
component
* CVE-2026-4686 (bmo#2016351)
Incorrect boundary conditions in the Graphics: Canvas2D
component
* CVE-2026-4687 (bmo#2016368)
Sandbox escape due to incorrect boundary conditions in the
Telemetry component
* CVE-2026-4688 (bmo#2016373)
Sandbox escape due to use-after-free in the Disability Access
APIs component
* CVE-2026-4689 (bmo#2016374)
Sandbox escape due to incorrect boundary conditions, integer
overflow in the XPCOM component
* CVE-2026-4690 (bmo#2016375)
Sandbox escape due to incorrect boundary conditions, integer
overflow in the XPCOM component
* CVE-2026-4691 (bmo#2017512)
Use-after-free in the CSS Parsing and Computation component
* CVE-2026-4692 (bmo#2017643)
Sandbox escape in the Responsive Design Mode component
* CVE-2026-4693 (bmo#2018102)
Incorrect boundary conditions in the Audio/Video: Playback
component
* CVE-2026-4694 (bmo#2018430)
Incorrect boundary conditions, integer overflow in the
Graphics component
* CVE-2026-4695 (bmo#2020030)
Incorrect boundary conditions in the Audio/Video: Web Codecs
component
* CVE-2026-4696 (bmo#2020190)
Use-after-free in the Layout: Text and Fonts component
* CVE-2026-4697 (bmo#2020422)
Incorrect boundary conditions in the Audio/Video: Web Codecs
component
* CVE-2026-4698 (bmo#2020906)
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-4699 (bmo#2021863)
Incorrect boundary conditions in the Layout: Text and Fonts
component
* CVE-2026-4700 (bmo#2003766)
Mitigation bypass in the Networking: HTTP component
* CVE-2026-4701 (bmo#2009303)
Use-after-free in the JavaScript Engine component
* CVE-2026-4702 (bmo#2013560)
JIT miscompilation in the JavaScript Engine component
* CVE-2026-4704 (bmo#2014868)
Denial-of-service in the WebRTC: Signaling component
* CVE-2026-4705 (bmo#2014873)
Undefined behavior in the WebRTC: Signaling component
* CVE-2026-4706 (bmo#2015091)
Incorrect boundary conditions in the Graphics: Canvas2D
component
* CVE-2026-4707 (bmo#2015267)
Incorrect boundary conditions in the Graphics: Canvas2D
component
* CVE-2026-4708 (bmo#2015268)
Incorrect boundary conditions in the Graphics component
* CVE-2026-4709 (bmo#2016329)
Incorrect boundary conditions in the Audio/Video: GMP
component
* CVE-2026-4710 (bmo#2016370)
Incorrect boundary conditions in the Audio/Video component
* CVE-2026-4711 (bmo#2017002)
Use-after-free in the Widget: Cocoa component
* CVE-2026-4712 (bmo#2017666)
Information disclosure in the Widget: Cocoa component
* CVE-2026-4713 (bmo#2018113)
Incorrect boundary conditions in the Graphics component
* CVE-2026-4714 (bmo#2018126)
Incorrect boundary conditions in the Audio/Video component
* CVE-2026-4715 (bmo#2018405)
Uninitialized memory in the Graphics: Canvas2D component
* CVE-2026-4716 (bmo#2018592)
Incorrect boundary conditions, uninitialized memory in the
JavaScript Engine component
* CVE-2026-4717 (bmo#2021695)
Privilege escalation in the Netmonitor component
* CVE-2025-59375 (bmo#1988467)
Denial-of-service in the XML component
* CVE-2026-4718 (bmo#2014864)
Undefined behavior in the WebRTC: Signaling component
* CVE-2026-4719 (bmo#2016367)
Incorrect boundary conditions in the Graphics: Text component
* CVE-2026-4720 (bmo#2004652, bmo#2019372, bmo#2021922,
bmo#2022567, bmo#2022733)
Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird
ESR 140.9, Firefox 149 and Thunderbird 149
* CVE-2026-4721 (bmo#2013762, bmo#2015291, bmo#2016591,
bmo#2016661, bmo#2016664, bmo#2017303, bmo#2017894,
bmo#2018090, bmo#2018196, bmo#2018379, bmo#2019112,
bmo#2022090, bmo#2022243, bmo#2022351, bmo#2022478,
bmo#2022676)
Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR
140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
* Tue Feb 24 2026 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.8.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.8
https://www.mozilla.org/security/advisories/mfsa2026-15
MFSA 2026-15 (boo#1258568)
* CVE-2026-2757 (bmo#2001637)
Incorrect boundary conditions in the WebRTC: Audio/Video
component
* CVE-2026-2758 (bmo#2009608)
Use-after-free in the JavaScript: GC component
* CVE-2026-2759 (bmo#2010933)
Incorrect boundary conditions in the Graphics: ImageLib
component
* CVE-2026-2760 (bmo#2011062)
Sandbox escape due to incorrect boundary conditions in the
Graphics: WebRender component
* CVE-2026-2761 (bmo#2011063)
Sandbox escape in the Graphics: WebRender component
* CVE-2026-2762 (bmo#2011649)
Integer overflow in the JavaScript: Standard Library
component
* CVE-2026-2763 (bmo#2012018)
Use-after-free in the JavaScript Engine component
* CVE-2026-2764 (bmo#2012608)
JIT miscompilation, use-after-free in the JavaScript Engine:
JIT component
* CVE-2026-2765 (bmo#2013562)
Use-after-free in the JavaScript Engine component
* CVE-2026-2766 (bmo#2013583)
Use-after-free in the JavaScript Engine: JIT component
* CVE-2026-2767 (bmo#2013741)
Use-after-free in the JavaScript: WebAssembly component
* CVE-2026-2768 (bmo#2014101)
Sandbox escape in the Storage: IndexedDB component
* CVE-2026-2769 (bmo#2014550)
Use-after-free in the Storage: IndexedDB component
* CVE-2026-2770 (bmo#2014585)
Use-after-free in the DOM: Bindings (WebIDL) component
* CVE-2026-2771 (bmo#2014593)
Undefined behavior in the DOM: Core & HTML component
* CVE-2026-2772 (bmo#2014827)
Use-after-free in the Audio/Video: Playback component
* CVE-2026-2773 (bmo#2014832)
Incorrect boundary conditions in the Web Audio component
* CVE-2026-2774 (bmo#2014883)
Integer overflow in the Audio/Video component
* CVE-2026-2775 (bmo#2015199)
Mitigation bypass in the DOM: HTML Parser component
* CVE-2026-2776 (bmo#2015266)
Sandbox escape due to incorrect boundary conditions in the
Telemetry component in External Software
* CVE-2026-2777 (bmo#2015305)
Privilege escalation in the Messaging System component
* CVE-2026-2778 (bmo#2016358)
Sandbox escape due to incorrect boundary conditions in the
DOM: Core & HTML component
* CVE-2026-2779 (bmo#1164141)
Incorrect boundary conditions in the Networking: JAR
component
* CVE-2026-2780 (bmo#2007829)
Privilege escalation in the Netmonitor component
* CVE-2026-2781 (bmo#2009552)
Integer overflow in the Libraries component in NSS
* CVE-2026-2782 (bmo#2010743)
Privilege escalation in the Netmonitor component
* CVE-2026-2783 (bmo#2010943)
Information disclosure due to JIT miscompilation in the
JavaScript Engine: JIT component
* CVE-2026-2784 (bmo#2012984)
Mitigation bypass in the DOM: Security component
* CVE-2026-2785 (bmo#2013549)
Invalid pointer in the JavaScript Engine component
* CVE-2026-2786 (bmo#2013612)
Use-after-free in the JavaScript Engine component
* CVE-2026-2787 (bmo#2014560)
Use-after-free in the DOM: Window and Location component
* CVE-2026-2788 (bmo#2014824)
Incorrect boundary conditions in the Audio/Video: GMP
component
* CVE-2026-2789 (bmo#2015179)
Use-after-free in the Graphics: ImageLib component
* CVE-2026-2790 (bmo#2008426)
Same-origin policy bypass in the Networking: JAR component
* CVE-2026-2791 (bmo#2015220)
Mitigation bypass in the Networking: Cache component
* CVE-2026-2792 (bmo#2008912, bmo#2010050, bmo#2010275,
bmo#2012331)
Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird
ESR 140.8, Firefox 148 and Thunderbird 148
* CVE-2026-2793 (bmo#2015196, bmo#2016423, bmo#2016498)
Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR
140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
* Mon Feb 16 2026 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.7.1 ESR
* Fixed: Security fix.
- Mozilla Firefox ESR 140.7.1
https://www.mozilla.org/security/advisories/mfsa2026-10
MFSA 2026-10 (boo#???????)
* CVE-2026-2447 (bmo#2014390)
Heap buffer overflow in libvpx
* Sun Feb 08 2026 Manfred Hollstein <manfred.h@gmx.net>
- Update MozillaFirefox.desktop from a fresh Factory/Tumbleweed
build.
* Tue Jan 13 2026 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.7.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.7
https://www.mozilla.org/security/advisories/mfsa2026-03
MFSA 2026-03 (boo#1256340)
* CVE-2026-0877 (bmo#1999257)
Mitigation bypass in the DOM: Security component
* CVE-2026-0878 (bmo#2003989)
Sandbox escape due to incorrect boundary conditions in the
Graphics: CanvasWebGL component
* CVE-2026-0879 (bmo#2004602)
Sandbox escape due to incorrect boundary conditions in the
Graphics component
* CVE-2026-0880 (bmo#2005014)
Sandbox escape due to integer overflow in the Graphics
component
* CVE-2026-0882 (bmo#1924125)
Use-after-free in the IPC component
* CVE-2025-14327 (bmo#1970743)
Spoofing issue in the Downloads Panel component
* CVE-2026-0883 (bmo#1989340)
Information disclosure in the Networking component
* CVE-2026-0884 (bmo#2003588)
Use-after-free in the JavaScript Engine component
* CVE-2026-0885 (bmo#2003607)
Use-after-free in the JavaScript: GC component
* CVE-2026-0886 (bmo#2005658)
Incorrect boundary conditions in the Graphics component
* CVE-2026-0887 (bmo#2006500)
Clickjacking issue, information disclosure in the PDF Viewer
component
* CVE-2026-0890 (bmo#2005081)
Spoofing issue in the DOM: Copy & Paste and Drag & Drop
component
* CVE-2026-0891 (bmo#1964722, bmo#2000981, bmo#2003100,
bmo#2003278)
Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird
ESR 140.7, Firefox 147 and Thunderbird 147
* Thu Dec 11 2025 Manfred Hollstein <manfred.h@gmx.net>
* Remove the Build1 tag from the last changes entry; no other change *
- Firefox Extended Support Release 140.6.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.6
https://www.mozilla.org/security/advisories/mfsa2025-94
MFSA 2025-94 (boo#1254551)
* CVE-2025-14321 (bmo#1992760)
Use-after-free in the WebRTC: Signaling component
* CVE-2025-14322 (bmo#1996473)
Sandbox escape due to incorrect boundary conditions in the
Graphics: CanvasWebGL component
* CVE-2025-14323 (bmo#1996555)
Privilege escalation in the DOM: Notifications component
* CVE-2025-14324 (bmo#1996840)
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2025-14325 (bmo#1998050)
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2025-14328 (bmo#1996761)
Privilege escalation in the Netmonitor component
* CVE-2025-14329 (bmo#1997018)
Privilege escalation in the Netmonitor component
* CVE-2025-14330 (bmo#1997503)
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2025-14331 (bmo#2000218)
Same-origin policy bypass in the Request Handling component
* CVE-2025-14333 (bmo#1966501, bmo#1997639)
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird
ESR 140.6, Firefox 146 and Thunderbird 146
- BuildRequires: cargo1.86 and rust1.86
- BuildRequires: clang19-devel on Leap 15.6
* Tue Dec 09 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.6.0 ESR Build1
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.6
https://www.mozilla.org/security/advisories/mfsa2025-94
MFSA 2025-94 (boo#1254551)
* CVE-2025-14321 (bmo#1992760)
Use-after-free in the WebRTC: Signaling component
* CVE-2025-14322 (bmo#1996473)
Sandbox escape due to incorrect boundary conditions in the
Graphics: CanvasWebGL component
* CVE-2025-14323 (bmo#1996555)
Privilege escalation in the DOM: Notifications component
* CVE-2025-14324 (bmo#1996840)
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2025-14325 (bmo#1998050)
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2025-14328 (bmo#1996761)
Privilege escalation in the Netmonitor component
* CVE-2025-14329 (bmo#1997018)
Privilege escalation in the Netmonitor component
* CVE-2025-14330 (bmo#1997503)
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2025-14331 (bmo#2000218)
Same-origin policy bypass in the Request Handling component
* CVE-2025-14333 (bmo#1966501, bmo#1997639)
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird
ESR 140.6, Firefox 146 and Thunderbird 146
- BuildRequires: cargo1.86 and rust1.86
- BuildRequires: clang19-devel on Leap 15.6
* Thu Nov 13 2025 Manfred Hollstein <manfred.h@gmx.net>
- Update MozillaFirefox.desktop from a fresh Factory/Tumbleweed
build.
* Tue Nov 11 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.5.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.5
https://www.mozilla.org/security/advisories/mfsa2025-88
MFSA 2025-88 (boo#1253188)
* MFSA-RESERVE-2025-1991458 (bmo#1991458)
Race condition in the Graphics component
* MFSA-RESERVE-2025-1992130 (bmo#1992130)
Incorrect boundary conditions in the JavaScript: WebAssembly
component
* MFSA-RESERVE-2025-1980904 (bmo#1980904)
Same-origin policy bypass in the DOM: Notifications component
* MFSA-RESERVE-2025-1984940 (bmo#1984940)
Mitigation bypass in the DOM: Security component
* MFSA-RESERVE-2025-1988412 (bmo#1988412)
Same-origin policy bypass in the DOM: Workers component
* MFSA-RESERVE-2025-1991945 (bmo#1991945)
Mitigation bypass in the DOM: Core & HTML component
* MFSA-RESERVE-2025-1995686 (bmo#1995686)
Use-after-free in the WebRTC: Audio/Video component
* MFSA-RESERVE-2025-1994241 (bmo#1994241)
Use-after-free in the Audio/Video component
* MFSA-RESERVE-2025-1994164 (bmo#1994164)
Spoofing issue in Firefox
* Wed Oct 15 2025 Manfred Hollstein <manfred.h@gmx.net>
- Run the "desktop file" actions only on non Leap/SLE distributions.
* Tue Oct 14 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.4.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.4
https://www.mozilla.org/security/advisories/mfsa2025-83
MFSA 2025-83 (boo#1251263)
* CVE-2025-11708 (bmo#1988931)
Use-after-free in MediaTrackGraphImpl::GetInstance()
* CVE-2025-11709 (bmo#1989127)
Out of bounds read/write in a privileged process triggered by
WebGL textures
* CVE-2025-11710 (bmo#1989899)
Cross-process information leaked due to malicious IPC
messages
* CVE-2025-11711 (bmo#1989978)
Some non-writable Object properties could be modified
* CVE-2025-11712 (bmo#1979536)
An OBJECT tag type attribute overrode browser behavior on web
resources without a content-type
* CVE-2025-11713 (bmo#1986142)
Potential user-assisted code execution in “Copy as cURL”
command
* CVE-2025-11714 (bmo#1973699, bmo#1989945, bmo#1990970,
bmo#1991040, bmo#1992113)
Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR
140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
* CVE-2025-11715 (bmo#1983838, bmo#1987624, bmo#1988244,
bmo#1988912, bmo#1989734, bmo#1990085, bmo#1991899)
Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird
ESR 140.4, Firefox 144 and Thunderbird 144
* Tue Sep 23 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.3.1 ESR
* Fixed: Improved reliability when HTTP/3 connections fail:
Firefox no longer forces HTTP/2 during fallback, allowing the
server to choose the protocol and preventing stalls on some
sites. (bmo#1980812)
* Tue Sep 16 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.3.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.3.0
https://www.mozilla.org/security/advisories/mfsa2025-75
MFSA 2025-75 (boo#1249391)
* CVE-2025-10527 (bmo#1984825)
Sandbox escape due to use-after-free in the Graphics:
Canvas2D component
* CVE-2025-10528 (bmo#1986185)
Sandbox escape due to undefined behavior, invalid pointer in
the Graphics: Canvas2D component
* CVE-2025-10529 (bmo#1970490)
Same-origin policy bypass in the Layout component
* CVE-2025-10532 (bmo#1979502)
Incorrect boundary conditions in the JavaScript: GC component
* CVE-2025-10533 (bmo#1980788)
Integer overflow in the SVG component
* CVE-2025-10536 (bmo#1981502)
Information disclosure in the Networking: Cache component
* CVE-2025-10537 (bmo#1938220, bmo#1980730, bmo#1981280,
bmo#1981283, bmo#1984505, bmo#1985067)
Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird
ESR 140.3, Firefox 143 and Thunderbird 143
* Fri Sep 05 2025 Manfred Hollstein <manfred.h@gmx.net>
- Update MozillaFirefox.desktop from a fresh Factory/Tumbleweed
build.
* Sun Aug 17 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.2.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.2.0
https://www.mozilla.org/security/advisories/mfsa2025-67
MFSA 2025-67 (boo#1248162)
* CVE-2025-9179 (bmo#1979527)
Sandbox escape due to invalid pointer in the Audio/Video: GMP
component
* CVE-2025-9180 (bmo#1979782)
Same-origin policy bypass in the Graphics: Canvas2D component
* CVE-2025-9181 (bmo#1977130)
Uninitialized memory in the JavaScript Engine component
* CVE-2025-9182 (bmo#1975837)
Denial-of-service due to out-of-memory in the Graphics:
WebRender component
* CVE-2025-9183 (bmo#1976102)
Spoofing issue in the Address Bar component
* CVE-2025-9184 (bmo#1929482, bmo#1976376, bmo#1979163,
bmo#1979955)
Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird
ESR 140.2, Firefox 142 and Thunderbird 142
* CVE-2025-9185 (bmo#1970154, bmo#1976782, bmo#1977166)
Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR
128.14, Thunderbird ESR 128.14, Firefox ESR 140.2,
Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
* Tue Jul 22 2025 Manfred Hollstein <manfred.h@gmx.net>
- Avoid file conflict with MozillaFirefox regarding
firefox-search-provider.ini; assume MozillaFirefox gets installed
anyway, so omit traces here. Add Recommends: MozillaFirefox for
this.
* Sat Jul 19 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.1.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.1.0
https://www.mozilla.org/security/advisories/mfsa2025-59
MFSA 2025-59 (boo#1246664)
* CVE-2025-8027 (bmo#1968423)
JavaScript engine only wrote partial return value to stack
* CVE-2025-8028 (bmo#1971581)
Large branch table could lead to truncated instruction
* CVE-2025-8029 (bmo#1928021)
javascript: URLs executed on object and embed tags
* CVE-2025-8036 (bmo#1960834)
DNS rebinding circumvents CORS
* CVE-2025-8037 (bmo#1964767)
Nameless cookies shadow secure cookies
* CVE-2025-8030 (bmo#1968414)
Potential user-assisted code execution in “Copy as cURL”
command
* CVE-2025-8031 (bmo#1971719)
Incorrect URL stripping in CSP reports
* CVE-2025-8032 (bmo#1974407)
XSLT documents could bypass CSP
* CVE-2025-8038 (bmo#1808979)
CSP frame-src was not correctly enforced for paths
* CVE-2025-8039 (bmo#1970997)
Search terms persisted in URL bar
* CVE-2025-8033 (bmo#1973990)
Incorrect JavaScript state machine for generators
* CVE-2025-8034 (bmo#1970422, bmo#1970422, bmo#1970422,
bmo#1970422)
Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR
128.13, Thunderbird ESR 128.13, Firefox ESR 140.1,
Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
* CVE-2025-8040 (bmo#1975058, bmo#1975058, bmo#1975998,
bmo#1975998)
Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird
ESR 140.1, Firefox 141 and Thunderbird 141
* CVE-2025-8035 (bmo#1975961, bmo#1975961, bmo#1975961)
Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird
ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox
141 and Thunderbird 141
* Mon Jun 23 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 140.0esr ESR
* New: ###General
- Reader View now has an enhanced Text and Layout menu with
new options for character spacing, word spacing, and text
alignment. These changes offer a more accessible reading
experience.
- Reader View now has a Theme menu with additional Contrast
and Gray options. You can also select custom colors for text,
background, and links from the Custom tab.
- Firefox will now offer to temporarily remember when users
grant permissions to sites (e.g. geolocation). Temporary
permissions will be removed either after one hour or when the
tab is closed.
- Firefox now includes safeguards to prevent sites from
abusing the history API by generating excessive history
entries, which can make navigating with the back and forward
buttons difficult by cluttering the history. This
intervention ensures that such entries, unless interacted
with by the user, are skipped when using the back and forward
buttons.
- Firefox now identifies all links in PDFs and turns them
into hyperlinks.
- You can now copy links from background tabs using the
tabstrip context menu on macOS and Linux.
- Users on macOS and Linux are now given the option to close
only the current tab if the Quit keyboard shortcut is used
while multiple tabs are open in the window.
* New: ###Sidebar and Tabs
- You can now enable the updated Firefox sidebar in Settings
> General > Browser Layout to quickly access multiple tools
in one click, without leaving your main view. Sidebar tools
include an AI chatbot of your choice, bookmarks, history, and
tabs from devices you sync with your Mozilla account.
- Keep a lot of tabs open? Try our new vertical tabs layout
to quickly scan your list of tabs. With vertical tabs, your
open and pinned tabs appear in the sidebar instead of along
the top of the browser. To turn on vertical tabs, right-click
on the toolbar near the top of the browser and select Turn on
Vertical Tabs. If you’ve enabled the updated sidebar, you can
also go to Customize sidebar and check Vertical tabs. Early
testers report feeling more organized after using vertical
tabs for a few days.
- Stay productive and organized with less effort by grouping
related tabs together. One simple way to create a group is to
drag a tab onto another, pause until you see a highlight,
then drop to create the group. Tab groups can be named,
color-coded, and are always saved. You can close a group and
reopen it later.
- A tab preview is now displayed when hovering the mouse over
background tabs, making it easier to locate the desired tab
without needing to switch tabs.
- The sidebar to view tabs from other devices can now be
opened via the Tab overview menu.
* New: ###Security & Privacy
- HTTPS is replacing HTTP as the default protocol in the
address bar on non-local sites. If a site is not available
via HTTPS, Firefox will fall back to HTTP.
- Firefox now blocks third-party cookie access when Enhanced
Tracking Protection's Strict mode is enabled.
- Firefox now has a new anti-tracking feature, Bounce
Tracking Protection, which is now available in Enhanced
Tracking Protection's "Strict" mode. This feature detects
bounce trackers based on their redirect behavior and
periodically purges their cookies and site data to block
tracking.
- Firefox now enforces certificate transparency, requiring
web servers to provide sufficient proof that their
certificates were publicly disclosed before they will be
trusted. This only affects servers using certificates issued
by a certificate authority in Mozilla's Root CA Program.
- Smartblock Embeds allows users to selectively unblock
certain social media embeds that are blocked in ETP Strict
and Private Browsing modes. Currently, support is limited to
a few embed types, with more to be added in future updates.
- Firefox now upgrades page loads to HTTPS by default and
gracefully falls back to HTTP if the secure connection fails.
This behavior is known as HTTPS-First.
- The "Copy Without Site Tracking" menu item was renamed to
"Copy Clean Link" to help clarify expectations around what
the feature does. "Copy Clean Link" is a list based approach
to remove - known tracking parameters from links. This option
can also now be used on plain text links.
- The Clear browsing data and cookies dialog now allows
clearing saved form info separately from browsing history.
* New: ###Translations
- Firefox now allows translating selected text portions to
different languages after a full-page translation.
- Full-Page Translations are now available within Firefox
extension pages that start with the moz-extension:// URL
scheme.
- When suggesting a default translation language, Firefox
will now take into consideration languages you have
previously used for translations.
- Added support for many new languages in Firefox
translation.
* New: ###Windows
- Canvas2D switched from Direct2D to a platform independent
acceleration backend on Windows.
- Hardware-accelerated playback of HEVC video content is now
supported on Windows.
- Firefox on Windows 11 now uses acrylic-style menus for
popup windows, which better match the operating system’s
aesthetic.
* New: ###macOS
- Added support for multiple languages in the same document
spoken in macOS VoiceOver.
- The macOS session resume feature has been enhanced. Firefox
will now automatically relaunch if it was open before a
system restart, like after an OS update.
- The macOS DMG installer packages now use LZMA for
compression, reducing download size and installation time.
- Due to recent changes in macOS Sequoia, the shortcut for
completing search strings to .com addresses has been changed
from Ctrl+Enter to Cmd+Enter.
* New: ###Linux
- Firefox now supports touchpad hold gestures on Linux. This
means that kinetic (momentum) scrolling can now be
interrupted by placing two fingers on the touchpad.
* Developer: - Firefox now supports text fragments, which
allows users to link directly to a specific portion of text
in a web document via a special URL fragment.
- Debugger log-point values are now automatically converted
into profiler markers, making it easy to add information to
the marker timeline directly from the Debugger.
- The Debugger's directory root is now scoped to the specific
domain where it was set, which aligns with typical usage and
avoids applying it across unrelated domains. This builds on
previous improvements such as a redesigned UI and easier
removal of the root setting. Setting a directory root updates
the Source List to show only the selected directory and its
children. (Learn more)
- The Network Blocking feature in the Network panel now
blocks HTTP requests in addition to blocking responses.
- The Network panel displays information about Early Hints,
including a dedicated indicator for the 103 HTTP status code
in the user interface.
- The Network panel now allows overriding network request
responses with local files.
- The filter setting in the Network panel is now preserved
across DevTools Toolbox sessions.
- A new column has been added to the Network panel to display
the full path of the request URL. This enhancement makes
helps developers quickly view and analyze complete request
paths.
- Introduced a new console command `$$$` that allows
searching the page, including within shadow roots.
- Improved support for debugging web extensions, such as
automatically reloading the web extension's source code in
the Debugger when the extension is reloaded. Workers are now
available in the Console panel’s context selector and
breakpoints function correctly in content scripts.
- In the Inspector Fonts panel, we now display fonts
metadata, like the font version, designer, vendor, license,
etc.
- Added support for the import map integrity field, allowing
you to ensure the integrity of dynamically or statically
imported modules.
- Implemented support for `Error.isError`, enabling brand
checks to determine whether an object is an instance of
Error. (Learn more)
- Added support for the `error.captureStackTrace` extension
to improve compatibility with other browsers. (Learn more)
[5]: http://github.com/tc39/proposal-error-
capturestacktrace
* Enterprise: - The UserMessaging policy has been updated with
a new option to allow disabling Firefox Labs in preferences.
- The Preferences policy has been updated to allow setting
the preference security.pki.certificate_transparency.mode.
- HTTPS-First is now on by default. You can manage this
behavior using the HttpsOnlyMode and HttpAllowlist policies.
- An internal change has been made to Firefox that removes
`XPCOMUtils.defineLazyGetter`. For most people, this
shouldn't matter, but if you encounter problems with
AutoConfig or third party software like PolicyPak, this might
be the cause. You'll need to reach out to your provider.
- Firefox now supports the Content Analysis SDK for
integrating DLP software. For more information, see this
post.
- The SearchEngines policy is now available on all versions
of Firefox (not just the ESR).
* Fixed: Various security fixes.
- Mozilla Firefox ESR 140.0
https://www.mozilla.org/security/advisories/mfsa2025-51
MFSA 2025-51 (boo#1244670)
* CVE-2025-6424 (bmo#1966423)
Use-after-free in FontFaceSet
* CVE-2025-6425 (bmo#1717672)
The WebCompat WebExtension shipped with Firefox exposed a
persistent UUID
* CVE-2025-6426 (bmo#1964385)
No warning when opening executable terminal files on macOS
* CVE-2025-6427 (bmo#1966927)
connect-src Content Security Policy restriction could be
bypassed
* CVE-2025-6428 (bmo#1970151)
Firefox for Android opened URLs specified in a link
querystring parameter
* CVE-2025-6429 (bmo#1970658)
Incorrect parsing of URLs could have allowed embedding of
youtube.com
* CVE-2025-6430 (bmo#1971140)
Content-Disposition header ignored when a file is included in
an embed or object tag
* CVE-2025-6431 (bmo#1942716)
The prompt in Firefox for Android that asks before opening a
link in an external application could be bypassed
* CVE-2025-6432 (bmo#1943804)
DNS Requests leaked outside of a configured SOCKS proxy
* CVE-2025-6433 (bmo#1954033)
WebAuthn would allow a user to sign a challenge on a webpage
with an invalid TLS certificate
* CVE-2025-6434 (bmo#1955182)
HTTPS-Only exception screen lacked anti-clickjacking delay
* CVE-2025-6435 (bmo#1950056, bmo#1961777)
Save as in Devtools could download files without sanitizing
the extension
* CVE-2025-6436 (bmo#1941377, bmo#1960948, bmo#1966187,
bmo#1966505, bmo#1970764)
Memory safety bugs fixed in Firefox 140 and Thunderbird 140
- Requires:
NSS >= 3.112
cargo/rust 1.86
rust-cbindgen >= 0.28
* Sun Jun 08 2025 Bernhard Wiedemann <bwiedemann@suse.com>
- Replace usage of %jobs for reproducible builds (boo#1237231)
* Sun May 25 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.11.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.11.0
https://www.mozilla.org/security/advisories/mfsa2025-44
MFSA 2025-44 (boo#1243353)
* CVE-2025-5262 (bmo#1962421)
Double-free in libvpx encoder
* CVE-2025-5263 (bmo#1960745)
Error handling for script execution was incorrectly isolated
from web content
* CVE-2025-5264 (bmo#1950001)
Potential local code execution in “Copy as cURL” command
* CVE-2025-5265 (bmo#1962301)
Potential local code execution in “Copy as cURL” command
* CVE-2025-5266 (bmo#1965628)
Script element events leaked cross-origin resource status
* CVE-2025-5267 (bmo#1954137)
Clickjacking vulnerability could have led to leaking saved
payment card details
* CVE-2025-5268 (bmo#1950136, bmo#1958121, bmo#1960499,
bmo#1962634)
Memory safety bugs fixed in Firefox 139, Thunderbird 139,
Firefox ESR 128.11, and Thunderbird 128.11
* CVE-2025-5269 (bmo#1924108)
Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird
128.11
- create-tar.sh: Remove additional slash from candidates URL, which
upstream doesn't like, and protect against wiping the keyfile
accidentally. Fix typo.
* Mon May 19 2025 Manfred Hollstein <manfred.h@gmx.net>
- create-tar.sh: Update keyring-file, if necessary
* Sun May 18 2025 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox ESR 128.10.1
MFSA 2025-37 (boo#1243303)
* CVE-2025-4918 (bmo#1966612)
Out-of-bounds access when resolving Promise objects
* CVE-2025-4919 (bmo#1966614)
Out-of-bounds access when optimizing linear sums
* Sat May 10 2025 Christian Boltz <suse-beta@cboltz.de>
- build on s390x needs 14G memory - adjust _constraints
* Tue Apr 29 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.10.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.10
https://www.mozilla.org/security/advisories/mfsa2025-29
MFSA 2025-29 (boo#1241621)
* CVE-2025-2817 (bmo#1917536)
Privilege escalation in Firefox Updater
* MFSA-RESERVE-2025-1937097 (bmo#1937097)
WebGL shader attribute memory corruption in Firefox for macOS
* MFSA-RESERVE-2025-1958350 (bmo#1958350)
Process isolation bypass using `javascript:` URI links in
cross-origin frames
* MFSA-RESERVE-2025-1949994 (bmo#1949994, bmo#1956698,
bmo#1960198)
Potential local code execution in "copy as cURL" command
* MFSA-RESERVE-2025-1952465 (bmo#1952465)
Unsafe attribute access during XPath parsing
* MFSA-RESERVE-2025-3 (bmo#1951161, bmo#1952105)
Memory safety bugs fixed in Firefox 138, Thunderbird 138,
Firefox ESR 128.10, and Thunderbird 128.10
* MFSA-RESERVE-2025-7 (bmo#1894100)
Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird
128.10
* Thu Apr 03 2025 Manfred Hollstein <manfred.h@gmx.net>
- BuildRequires: clang-devel on Tumbleweed/Factory, which works for
both clang19-devel as well as clang20-devel
* Mon Mar 31 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.9.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.9.0
https://www.mozilla.org/security/advisories/mfsa2025-22
MFSA 2025-22 (boo#1240083)
* CVE-2025-3028 (bmo#1941002)
Use-after-free triggered by XSLTProcessor
* CVE-2025-3029 (bmo#1952213)
URL Bar Spoofing via non-BMP Unicode characters
* CVE-2025-3030 (bmo#1850615, bmo#1932468, bmo#1942551,
bmo#1951017, bmo#1951494)
Memory safety bugs fixed in Firefox 137, Thunderbird 137,
Firefox ESR 128.9, and Thunderbird 128.9
* Thu Mar 27 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.8.1 ESR
* Fixed: Security fix.
- Mozilla Firefox 136.0.4, ESR 128.8.1, ESR 115.21.1
https://www.mozilla.org/security/advisories/mfsa2025-19
MFSA 2025-19 (boo#???????)
* CVE-2025-2857 (bmo#1956398,
bmo#https://www.cve.org/CVERecord?id=CVE-2025-2783)
Incorrect handle could lead to sandbox escapes
* Sun Mar 16 2025 Manfred Hollstein <manfred.h@gmx.net>
- Don't build the various langpacks in parallel. This may be fixing
boo#1239446, but will have to be monitored.
* Tue Mar 04 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.8.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.8.0
https://www.mozilla.org/security/advisories/mfsa2025-16
MFSA 2025-16 (boo#1237683)
* CVE-2024-43097 (bmo#1945624)
Overflow when growing an SkRegion's RunArray
* CVE-2025-1930 (bmo#1902309)
AudioIPC StreamData could trigger a use-after-free in the
Browser process
* CVE-2025-1931 (bmo#1944126)
Use-after-free in WebTransportChild
* CVE-2025-1932 (bmo#1944313)
Inconsistent comparator in XSLT sorting led to out-of-bounds
access
* CVE-2025-1933 (bmo#1946004)
JIT corruption of WASM i32 return values on 64-bit CPUs
* CVE-2025-1934 (bmo#1942881)
Unexpected GC during RegExp bailout processing
* CVE-2025-1935 (bmo#1866661)
Clickjacking the registerProtocolHandler info-bar
* CVE-2025-1936 (bmo#1940027)
Adding %00 and a fake extension to a jar: URL changed the
interpretation of the contents
* CVE-2025-1937 (bmo#1938471, bmo#1940716)
Memory safety bugs fixed in Firefox 136, Thunderbird 136,
Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
* CVE-2025-1938 (bmo#1922889, bmo#1935004, bmo#1943586,
bmo#1943912, bmo#1948111)
Memory safety bugs fixed in Firefox 136, Thunderbird 136,
Firefox ESR 128.8, and Thunderbird 128.8
* Mon Feb 03 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.7.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.7.0
https://www.mozilla.org/security/advisories/mfsa2025-09
MFSA 2025-09 (boo#1236539)
* CVE-2025-1009 (bmo#1936613)
Use-after-free in XSLT
* CVE-2025-1010 (bmo#1936982)
Use-after-free in Custom Highlight
* CVE-2025-1011 (bmo#1936454)
A bug in WebAssembly code generation could result in a crash
* CVE-2025-1012 (bmo#1939710)
Use-after-free during concurrent delazification
* CVE-2024-11704 (bmo#1899402)
Potential double-free vulnerability in PKCS#7 decryption
handling
* CVE-2025-1013 (bmo#1932555)
Potential opening of private browsing tabs in normal browsing
windows
* CVE-2025-1014 (bmo#1940804)
Certificate length was not properly checked
* CVE-2025-1016 (bmo#1936601, bmo#1936844, bmo#1937694,
bmo#1938469, bmo#1939583, bmo#1940994)
Memory safety bugs fixed in Firefox 135, Thunderbird 135,
Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20,
and Thunderbird 128.7
* CVE-2025-1017 (bmo#1926256, bmo#1935471, bmo#1935984)
Memory safety bugs fixed in Firefox 135, Thunderbird 135,
Firefox ESR 128.7, and Thunderbird 128.7
* Tue Jan 07 2025 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.6.0 ESR
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.6.0
https://www.mozilla.org/security/advisories/mfsa2025-02
MFSA 2025-02 (boo#1234991)
* CVE-2025-0237 (bmo#1915257)
WebChannel APIs susceptible to confused deputy attack
* CVE-2025-0238 (bmo#1915535)
Use-after-free when breaking lines in text
* CVE-2025-0239 (bmo#1929156)
Alt-Svc ALPN validation failure when redirected
* CVE-2025-0240 (bmo#1929623)
Compartment mismatch when parsing JavaScript JSON module
* CVE-2025-0241 (bmo#1933023)
Memory corruption when using JavaScript Text Segmentation
* CVE-2025-0242 (bmo#1874523, bmo#1926454, bmo#1931873,
bmo#1932169)
Memory safety bugs fixed in Firefox 134, Thunderbird 134,
Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19,
and Thunderbird 128.6
* CVE-2025-0243 (bmo#1827142, bmo#1932783)
Memory safety bugs fixed in Firefox 134, Thunderbird 134,
Firefox ESR 128.6, and Thunderbird 128.6
* Fri Dec 13 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.5.2 ESR
* Fixed: Fixed a crash experienced by Windows users with Qihoo
360 Total Security Antivirus software installed (bmo#1934258)
* Wed Dec 11 2024 Manfred Hollstein <manfred.h@gmx.net>
- Add MozillaFirefox.changes.txt as a hard link to firefox-esr.changes
- Rename firefox-esr.changes into firefox-esr.changes.txt in order
to trick source_validator because of the two possible package
names "firefox-esr" vs. "MozillaFirefox" (in Leap).
* Fri Nov 29 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.5.1 ESR
* Fixed: Fixed an issue that prevented some websites from
loading when using SSL Inspection. (bmo#1933747)
* Tue Nov 26 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.5.0 ESR
* Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.5.0
https://www.mozilla.org/security/advisories/mfsa2024-64
MFSA 2024-64 (boo#1233695)
* CVE-2024-11691 (bmo#1914707, bmo#1924184)
Memory corruption in Apple GPU drivers
* CVE-2024-11692 (bmo#1909535)
Select list elements could be shown over another site
* CVE-2024-11693 (bmo#1921458)
Download Protections were bypassed by .library-ms files on
Windows
* CVE-2024-11694 (bmo#1924167)
CSP Bypass and XSS Exposure via Web Compatibility Shims
* CVE-2024-11695 (bmo#1925496)
URL Bar Spoofing via Manipulated Punycode and Whitespace
Characters
* CVE-2024-11696 (bmo#1929600)
Unhandled Exception in Add-on Signature Verification
* CVE-2024-11697 (bmo#1842187)
Improper Keypress Handling in Executable File Confirmation
Dialog
* CVE-2024-11698 (bmo#1916152)
Fullscreen Lock-Up When Modal Dialog Interrupts Transition on
macOS
* CVE-2024-11699 (bmo#1880582, bmo#1929911)
Memory safety bugs fixed in Firefox 133, Firefox ESR 128.5,
and Thunderbird 128.5
* Mon Nov 18 2024 Manfred Hollstein <manfred.h@gmx.net>
- Add "mozilla-fix-cmath-issues.patch" to fix math issues on TW/i586
* Mon Nov 18 2024 Manfred Hollstein <manfred.h@gmx.net>
- Remove old, unneeded patches:
* mozilla-bmo1504834-part3.patch
* mozilla-bmo1512162.patch
* mozilla-bmo1822730.patch
* mozilla-bmo531915.patch
* mozilla-fix-aarch64-libopus.patch
* mozilla-partial-revert-1768632.patch
* Thu Nov 14 2024 Manfred Hollstein <manfred.h@gmx.net>
- require xdg-desktop-portal (boo#1233166)
- remove KDE integration patches
- mozilla-kde.patch
- firefox-kde.patch
on KDE use these settings instead
widget.use-xdg-desktop-portal.file-picker=1
widget.use-xdg-desktop-portal.mime-handler=1
(those are set by the latest branding package as well)
* Sun Nov 10 2024 Manfred Hollstein <manfred.h@gmx.net>
- Don't use clang-devel >= 19 on Tumbleweed!
* Fri Nov 08 2024 Manfred Hollstein <manfred.h@gmx.net>
- Ensure this package is always called "firefox-esr" on Tumbleweed
and Slowroll. Use the ff_esr_name macro to override the default
name "MozillaFirefox" on SLE and Leap.
This allows parallel installation of firefox-esr and the
default version of MozillaFirefox.
* Tue Oct 29 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.4.0 ESR
* Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.4.0
https://www.mozilla.org/security/advisories/mfsa2024-56
MFSA 2024-56 (boo#1231879)
* CVE-2024-10458 (bmo#1921733)
Permission leak via embed or object elements
* CVE-2024-10459 (bmo#1919087)
Use-after-free in layout with accessibility
* CVE-2024-10460 (bmo#1912537)
Confusing display of origin for external protocol handler
prompt
* CVE-2024-10461 (bmo#1914521)
XSS due to Content-Disposition being ignored in
multipart/x-mixed-replace response
* CVE-2024-10462 (bmo#1920423)
Origin of permission prompt could be spoofed by long URL
* CVE-2024-10463 (bmo#1920800)
Cross origin video frame leak
* CVE-2024-10464 (bmo#1913000)
History interface could have been used to cause a Denial of
Service condition in the browser
* CVE-2024-10465 (bmo#1918853)
Clipboard "paste" button persisted across tabs
* CVE-2024-10466 (bmo#1924154)
DOM push subscription message could hang Firefox
* CVE-2024-10467 (bmo#1829029, bmo#1888538, bmo#1900394,
bmo#1904059, bmo#1917742, bmo#1919809, bmo#1923706)
Memory safety bugs fixed in Firefox 132, Thunderbird 132,
Firefox ESR 128.4, and Thunderbird 128.4
- Remove obsolete patch mozilla-rust-disable-future-incompat.patch
* Wed Oct 09 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.3.1 ESR
* Fixed: Security fix.
- Mozilla Firefox ESR 128.3.1
https://www.mozilla.org/security/advisories/mfsa2024-51
MFSA 2024-51 (boo#1231413)
* CVE-2024-9680 (bmo#1923344)
Use-after-free in Animation timeline
* Mon Sep 30 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.3.0 ESR
* Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.3.0
https://www.mozilla.org/security/advisories/mfsa2024-47
MFSA 2024-47 (boo#1230979)
* CVE-2024-9392 (bmo#1899154, bmo#1905843)
Compromised content process can bypass site isolation
* CVE-2024-9393 (bmo#1918301)
Cross-origin access to PDF contents through multipart
responses
* CVE-2024-9394 (bmo#1918874)
Cross-origin access to JSON contents through multipart
responses
* CVE-2024-8900 (bmo#1872841)
Clipboard write permission bypass
* CVE-2024-9396 (bmo#1912471)
Potential memory corruption may occur when cloning certain
objects
* CVE-2024-9397 (bmo#1916659)
Potential directory upload bypass via clickjacking
* CVE-2024-9398 (bmo#1881037)
External protocol handlers could be enumerated via popups
* CVE-2024-9399 (bmo#1907726)
Specially crafted WebTransport requests could lead to denial
of service
* CVE-2024-9400 (bmo#1915249)
Potential memory corruption during JIT compilation
* CVE-2024-9401 (bmo#1872744, bmo#1897792, bmo#1911317,
bmo#1916476)
Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16,
Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3
* CVE-2024-9402 (bmo#1872744, bmo#1897792, bmo#1911317,
bmo#1913445, bmo#1914106, bmo#1914475, bmo#1914963,
bmo#1915008, bmo#1916476)
Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3,
Thunderbird 131, and Thunderbird 128.3
* Wed Sep 04 2024 pallas wept <pallaswept@proton.me>
- Added mozilla-bmo1746799.patch to fix incorrect audio volume scaling
* Tue Sep 03 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.2.0 ESR
* Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.2.0
https://www.mozilla.org/security/advisories/mfsa2024-40
MFSA 2024-40 (boo#1229821)
* CVE-2024-8385 (bmo#1911909)
WASM type confusion involving ArrayTypes
* CVE-2024-8381 (bmo#1912715)
Type confusion when looking up a property name in a
"with" block
* CVE-2024-8382 (bmo#1906744)
Internal event interfaces were exposed to web content when
browser EventHandler listener callbacks ran
* CVE-2024-8383 (bmo#1908496)
Firefox did not ask before openings news: links in an
external application
* CVE-2024-8384 (bmo#1911288)
Garbage collection could mis-color cross-compartment objects
in OOM conditions
* CVE-2024-8386 (bmo#1907032, bmo#1909163, bmo#1909529)
SelectElements could be shown over another site if popups are
allowed
* CVE-2024-8387 (bmo#1857607, bmo#1911858, bmo#1914009)
Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2,
and Thunderbird 128.2
- Remove mozilla-bmo1898476.patch and mozilla-bmo1907511.patch,
implemented upstream.
* Tue Aug 06 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.1.0 ESR
* Fixed: Various security fixes and other quality improvements.
- Mozilla Firefox ESR 128.1.0
https://www.mozilla.org/security/advisories/mfsa2024-35
MFSA 2024-35 (boo#1228648)
* CVE-2024-7518 (bmo#1875354)
Fullscreen notification dialog can be obscured by document
content
* CVE-2024-7519 (bmo#1902307)
Out of bounds memory access in graphics shared memory
handling
* CVE-2024-7520 (bmo#1903041)
Type confusion in WebAssembly
* CVE-2024-7521 (bmo#1904644)
Incomplete WebAssembly exception handing
* CVE-2024-7522 (bmo#1906727)
Out of bounds read in editor component
* CVE-2024-7524 (bmo#1909241)
CSP strict-dynamic bypass using web-compatibility shims
* CVE-2024-7525 (bmo#1909298)
Missing permission check when creating a StreamFilter
* CVE-2024-7526 (bmo#1910306)
Uninitialized memory used by WebGL
* CVE-2024-7527 (bmo#1871303)
Use-after-free in JavaScript garbage collection
* CVE-2024-7528 (bmo#1895951)
Use-after-free in IndexedDB
* CVE-2024-7529 (bmo#1903187)
Document content could partially obscure security prompts
* CVE-2024-7531 (bmo#1905691)
PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel
Sandy Bridge machines
* Wed Jul 17 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- add wayland upstream fixes (bmo#1907511, bmo#1898476)
(mozilla-bmo1898476.patch and mozilla-bmo1907511.patch)
* Tue Jul 09 2024 Manfred Hollstein <manfred.h@gmx.net>
- Firefox Extended Support Release 128.0esr ESR
* New: ### General
* Windows 7-8.1 and macOS 10.12-10.14 are no longer supported
operating systems.
* Firefox now supports automated translation of web content.
Also, unlike cloud-based alternatives, translation is done
locally so that the text being translated never leaves the
machine.
* The line breaking rules of web content now match the
Unicode standard, improving cross-browser compatibility.
Additionally, for East Asian and South East Asian end users,
Firefox now supports proper language-aware word selection
when double-clicking on text for languages including Chinese,
Japanese, Burmese, Lao, Khmer, and Thai.
* Video effects and background blur are now available to
Firefox users on Google Meet.
Firefox now displays images and descriptions for search
suggestions when provided by the search engine.
* It is now possible to copy and paste any file from the
operating system into Firefox.
* Having any issues with a website on Firefox, yet the site
seems to be working as expected on another browser? You can
now let us know via the Web Compatibility Reporting Tool! By
filing a web compatibility issue, you’re directly helping us
detect, target, and fix the most impacted sites to make your
browsing experience on Firefox smoother.
* Firefox now prompts users in the US and Canada to save
their addresses upon submitting an address form, allowing
Firefox to autofill stored address information in the future.
* Support for credit card autofill has been extended to users
running Firefox in the IT, ES, AT, BE, and PL locales.
* Recently closed tabs now persist between sessions that
don't have automatic session restore enabled. Manually
restoring a previous session will continue to reopen any
previously open tabs or windows.
* When migrating data from Chrome, Firefox now offers the
ability to import certain extensions as well.
* The Screenshots feature in Firefox has been updated. It now
supports taking screenshots of file types like SVG, XML, and
more as well as various about: pages within Firefox. The
screenshot tool was also made more accessible to everyone by
implementing new keyboard shortcuts and adding theme
compatibility and High Contrast Mode (HCM) support. And
finally, performance for capturing large screenshots has been
improved. (bmo#None)
* New: ### PDF Viewer
* The Firefox PDF viewer has expanded PDF editing
capabilities:
* Text highlighting is now supported.
* Editing already-existing text annotations is now
supported.
* Images and alt text can be added in addition to text
and drawings.
* A floating button is now included to simplify deleting
drawings, text, and images added in PDFs.
* Caret browsing mode now also works in the PDF viewer.
(Learn more)
* New: ### Firefox View
* Firefox View includes more content. You can now see all
open tabs from all windows. If you sync open tabs, you’ll see
all tabs from other devices. Browsing history is now listed
and you can sort by date or by site. As before, recently
closed tabs are also listed on Firefox View.
To access Firefox View, select the file folder icon at the
top left of your tab strip.
* We’ve integrated search into Firefox View. You can now
search through all of the tabs on each of the section
subpages - Recent Browsing, Open Tabs, Recently Closed Tabs,
Tabs from other devices, or History.
* In Firefox View, open tabs can now be sorted by either
recent activity or tab order. Recent activity is the default
setting.
* Firefox View now displays pinned tabs in the Open tabs
section. Tab indicators have also been added to Open tabs, so
users can do things like see which tabs are playing media and
quickly mute or unmute across windows. Indicators were also
added for bookmarks, tabs with notifications, and more!
* It is now possible to close all duplicate tabs in a window
with the `Close duplicate tabs` command available from the
`List all tabs` widget in the tab bar or a tab context menu.
* New: ### Security & Privacy
* For added protection on macOS and Windows, a device sign in
(e.g. operating system password, fingerprint, face or voice
login if enabled) can be required when accessing and filling
stored passwords in the Firefox Password Manager about:logins
page.
* Firefox now supports creating and using passkeys stored in
the iCloud Keychain on macOS.
* Firefox now imports user-added TLS trust anchors (e.g.,
certificates) from the operating system root store. This will
be enabled by default on Windows, macOS, and Android, and if
needed, can be turned off in settings (Settings → Privacy &
Security → Certificates).
* The Storage Access API web standard was updated to improve
security while mitigating website breakages and further
enabling the phase out of third-party cookies in Firefox.
* Encrypted Client Hello (ECH) is now available to Firefox
users, delivering a more private browsing experience. ECH
extends the encryption used in TLS connections to cover more
of the handshake and better protect sensitive fields. Read
more about the launch of ECH on Mozilla Distilled.
* Firefox supports a new “Copy Link Without Site Tracking”
feature in the context menu which ensures that copied links
no longer contain tracking information.
* Firefox now supports a setting (in Preferences → Privacy &
Security) to enable Global Privacy Control. With this opt-in
feature, Firefox informs the websites that the user doesn’t
want their data to be shared or sold. This feature is enabled
in private browsing mode by default.
* Firefox now more proactively blocks downloads from URLs
that are considered to be potentially untrustworthy.
* New: ### Anti-Fingerprinting
* Web Audio in Firefox now uses the FDLIBM math library on
all systems to improve anonymity with Fingerprint Protection.
* As part of Total Cookie Protection, Firefox now supports
the partitioning of Blob URLs, this mitigates a potential
tracking vector that third-party agents could use to track an
individual.
* To mitigate font fingerprinting, the visibility of fonts to
websites has been restricted to system fonts and language
pack fonts when in Private Browsing Mode or with Enhanced
Tracking Protection set to strict mode.
* Firefox’s private windows and ETP-Strict privacy
configuration now enhance the Canvas APIs with Fingerprinting
Protection.
* To reduce user fingerprinting information and the risk of
some website compatibility issues, the CPU architecture for
32-bit x86 Linux will now be reported as x86_64 in Firefox's
User-Agent string and `navigator.platform` and
`navigator.oscpu` Web APIs.
* New: ### Windows
* Firefox can now be set to automatically launch whenever the
computer starts up. (Learn more)
* The background updater now updates properly when there are
multiple user accounts on a system.
* Firefox now populates the Windows taskbar jump list more
efficiently, which should allow for a smoother overall
browsing experience.
* New: ### macOS
* Firefox now supports Voice Control commands on macOS
systems.
* Links and other focusable elements are now tab-navigable by
default on macOS, instead of following macOS' "Keyboard
navigation" setting. This is a more accessible default and
matches the default in all other platforms. A checkbox in the
settings page still allows users to restore the old behavior.
* Firefox on Mac now uses the macOS fullscreen API for all
types of fullscreen windows. This should better match the
expected macOS user experience for fullscreen spaces, menubar
and the Dock.
* New: ### Linux
* Firefox now defaults to the Wayland compositor when
available instead of XWayland. This brings support for
touchpad & touchscreen gestures, swipe-to-nav, per-monitor
DPI settings, better graphics performance, and more.
* Firefox now ships with a new .deb package for Linux users
on Ubuntu, Debian, and Linux Mint.
* New: ### Video Playback
* Enabled AV1 hardware decode acceleration on macOS for M3
Macs.
* Firefox now supports the AV1 codec for Encrypted Media
Extensions (EME), enabling higher-quality playback from video
streaming providers.
* NVIDIA RTX Video Super Resolution (“VSR”) is now available
in Firefox. RTX VSR enhances and sharpens lower resolution
video when upscaled to higher resolutions and also removes
blocky artifacts commonly visible on low bitrate streamed
video. VSR requires at least a 20-series or higher NVIDIA RTX
GPU, Microsoft Windows 10/11 64-bit, and NVIDIA driver
version R530 or higher. The feature can be enabled in the
NVIDIA control panel.
* NVIDIA RTX Video HDR is now available in Firefox. RTX Video
HDR automatically converts SDR video to vibrant HDR10 in real
time, letting you enjoy video with improved clarity on your
HDR10 panel. It requires at least a 20-series NVIDIA RTX GPU,
Microsoft Windows 10/11 64-bit, and NVIDIA driver version 550
or higher. The feature can be enabled in the NVIDIA control
panel. (bmo#None)
* Developer: * Firefox now supports DNS prefetching for HTTPS
documents via the `rel="dns-prefetch"` link hint. This
standard allows web developers to specify domain names for
important assets that should be resolved preemptively.
* Firefox will now automatically try to upgrade <img>,
<audio>, and <video> elements from HTTP to HTTPS
if they are embedded within an HTTPS page. If these so-called
mixed content elements do not support HTTPS, they will no
longer load.
* Firefox now supports Content-encoding: zstd (zstandard
compression). This is an alternative to brotli and gzip
compression for web content, and can provide higher
compression levels for the same CPU used, or conversely lower
server CPU use to get the same compression.
[2]: http://facebook.github.io/zstd/ (bmo#None)
* Enterprise: * The FirefoxHome policy has been updated to
reflect that the Snippets option is now deprecated.
* The DNSOverHTTPS policy has been updated to support setting
a `Fallback` value to prevent falling back to your default
DNS Provider.
* The AllowFileSelectionDialogs policy has been added for
controlling file selection dialogs.
* The TranslateEnabled policy has been added.
* The DisableEncryptedClientHello policy has been added to
control Encrypted Client Hello.
* The PostQuantumKeyAgreementEnabled policy has been added to
control post-quantum key agreement for TLS.
* The HttpsOnlyMode policy has been added to control HTTPS-
Only Mode.
* The HttpAllowlist policy has been added to add exceptions
to HTTPS-Only Mode.
* The Preferences policy has been updated to allow setting
the preferences
`security.mixed_content.block_display_content` and
`security.mixed_content.upgrade_display_content`.
* The UserMessaging policy has been updated to remove the
WhatsNew option.
* The ExtensionSettings policy has been updated to add
`temporarily_allow_weak_signatures` to allow installing
extensions signed using deprecated signature algorithms.
* Fixed: Various security fixes.
- Mozilla Firefox ESR 128.0
https://www.mozilla.org/security/advisories/mfsa2024-29
MFSA 2024-29 (boo#1226316)
* CVE-2024-6605 (bmo#1836786)
Firefox Android missed activation delay to prevent tapjacking
* CVE-2024-6606 (bmo#1902305)
Out-of-bounds read in clipboard component
* CVE-2024-6607 (bmo#1694513)
Leaving pointerlock by pressing the escape key could be
prevented
* CVE-2024-6608 (bmo#1743329)
Cursor could be moved out of the viewport using pointerlock.
* CVE-2024-6609 (bmo#1839258)
Memory corruption in NSS
* CVE-2024-6610 (bmo#1883396)
Form validation popups could block exiting full-screen mode
* CVE-2024-6600 (bmo#1888340)
Memory corruption in WebGL API
* CVE-2024-6601 (bmo#1890748)
Race condition in permission assignment
* CVE-2024-6602 (bmo#1895032)
Memory corruption in NSS
* CVE-2024-6603 (bmo#1895081)
Memory corruption in thread creation
* CVE-2024-6611 (bmo#1844827)
Incorrect handling of SameSite cookies
* CVE-2024-6612 (bmo#1880374)
CSP violation leakage when using devtools
* CVE-2024-6613 (bmo#1900523)
Incorrect listing of stack frames
* CVE-2024-6614 (bmo#1902983)
Incorrect listing of stack frames
* CVE-2024-6604 (bmo#1748105, bmo#1837550, bmo#1884266)
Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13,
and Thunderbird 115.13
* CVE-2024-6615 (bmo#1892875, bmo#1894428, bmo#1898364)
Memory safety bugs fixed in Firefox 128
- Update mozilla-bmo1504834-part1.patch,
mozilla-rust-disable-future-incompat.patch,
mozilla-silence-no-return-type.patch
- Update create_tar.sh from our firefox-scripts git
- Use cargo/rust1.78 for building.
* Mon Jul 01 2024 Andrei Dziahel <develop7@develop7.info>
- Mozilla Firefox 127.0.2
* Fixed an issue where YouTube playback may experience stalling under
certain conditions (bmo#1900191, bmo#1878510).
* Fixed an issue where the Private Window icon was displayed in the taskbar
on Windows when browser.privateWindowSeparation.enabled was
set to false (bmo#1901840).
- Mozilla Firefox 127.0.1
* Fixed an issue where users with a primary password set on their profile
could lose their previous session of tabs upon upgrading if they dismissed
the primary password prompt (bmo#1901899).
* Fixed an issue where Linux users with accessibility.monoaudio.enable set
to true were experiencing slow audio speeds (bmo#1900972).
* Fixed an issue where, in some circumstances, the Firefox installer
on Windows failed to complete the installation (bmo#1896868).
* Fixed an issue causing Firefox to incorrectly reject cookies
for certain websites (bmo#1901325).
* Fri Jun 28 2024 Martin Sirringhaus <martin.sirringhaus@suse.com>
- Fix GNOME search provider (boo#1225278)
* Tue Jun 11 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 127.0
https://www.mozilla.org/en-US/firefox/127.0/releasenotes
MFSA 2024-25 (bsc#1226027)
* CVE-2024-5687 (bmo#1889066)
An incorrect principal could have been used when opening new tabs
* CVE-2024-5688 (bmo#1895086)
Use-after-free in JavaScript object transplant
* CVE-2024-5689 (bmo#1389707)
User confusion and possible phishing vector via Firefox Screenshots
* CVE-2024-5690 (bmo#1883693)
External protocol handlers leaked by timing attack
* CVE-2024-5691 (bmo#1888695)
Sandboxed iframes were able to bypass sandbox restrictions to
open a new window
* CVE-2024-5692 (bmo#1837514, bmo#1891234)
Bypass of file name restrictions during saving
* CVE-2024-5693 (bmo#1891319)
Cross-Origin Image leak via Offscreen Canvas
* CVE-2024-5694 (bmo#1895055)
Use-after-free in JavaScript Strings
* CVE-2024-5695 (bmo#1895579)
Memory Corruption using allocation using out-of-memory conditions
* CVE-2024-5696 (bmo#1896555)
Memory Corruption in Text Fragments
* CVE-2024-5697 (bmo#1414937)
Website was able to detect when Firefox was taking a
screenshot of them
* CVE-2024-5698 (bmo#1828259)
Data-list could have overlaid address bar
* CVE-2024-5699 (bmo#1891349)
Cookie prefixes not treated as case-sensitive
* CVE-2024-5700 (bmo#1862809, bmo#1889355, bmo#1893388, bmo#1895123)
Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12,
and Thunderbird 115.12
* CVE-2024-5701 (bmo#1890909, bmo#1891422, bmo#1893915,
bmo#1894047, bmo#1896024)
Memory safety bugs fixed in Firefox 127
- removed obsolete mozilla-bmo1886378.patch
* Wed May 29 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 126.0.1
* Fixed an issue with reading tagged PDF documents in a screen reader
bmo#1894849
* Fixed not displaying localized text for non-en-US locales in the
Crash Reporter dialog box on macOS. (bmo#1896097)
* Fixed issues with drag-and-drop functionality on Linux. (bmo#1897115)
* Fixed an issue causing high GPU memory usage on certain versions
of AMD cards. (bmo#1897006)
* Tue May 28 2024 Guillaume GARDET <guillaume.gardet@opensuse.org>
- Backport upstream patches to fix build on aarch64 - boo#1225460
* mozilla-bmo1886378.patch
* Wed May 15 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 126.0
https://www.mozilla.org/en-US/firefox/126.0/releasenotes
MFSA 2024-21 (bsc#1224056)
* CVE-2024-4764 (bmo#1879093)
Use-after-free when audio input connected with multiple consumers
* CVE-2024-4367 (bmo#1893645)
Arbitrary JavaScript execution in PDF.js
* CVE-2024-4765 (bmo#1871109)
Web application manifests could have been overwritten via
hash collision
* CVE-2024-4766 (bmo#1871214, bmo#1871217)
Fullscreen notification could have been obscured on Firefox
for Android
* CVE-2024-4767 (bmo#1878577)
IndexedDB files retained in private browsing mode
* CVE-2024-4768 (bmo#1886082)
Potential permissions request bypass via clickjacking
* CVE-2024-4769 (bmo#1886108)
Cross-origin responses could be distinguished between script
and non-script content-types
* CVE-2024-4770 (bmo#1893270)
Use-after-free could occur when printing to PDF
* CVE-2024-4771 (bmo#1893891)
Failed allocation could lead to use-after-free
* CVE-2024-4772 (bmo#1870579)
Use of insecure rand() function to generate nonce
* CVE-2024-4773 (bmo#1875248)
URL bar could be cleared after network error
* CVE-2024-4774 (bmo#1886598)
Undefined behavior in ShmemCharMapHashEntry()
* CVE-2024-4775 (bmo#1887332)
Invalid memory access in the built-in profiler
* CVE-2024-4776 (bmo#1887343)
Window may remain disabled after file dialog is shown in
full-screen
* CVE-2024-4777 (bmo#1878199, bmo#1893340)
Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11,
and Thunderbird 115.11
* CVE-2024-4778 (bmo#1838834, bmo#1889291, bmo#1889595,
bmo#1890204, bmo#1891545)
Memory safety bugs fixed in Firefox 126
- requires NSS 3.100
- removed obsolete mozilla-libproxy-fix.patch
* Mon Apr 29 2024 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 125.0.3
* Fixed: Fixed an extra blank tab with an address of
`https://0.0.0.1` sometimes appearing when attempting to
launch Firefox when it is already running (bmo#1892612).
* Fixed: Fixed an issue that could cause incorrect font
selection in some situations for users with the Japanese
locale set (bmo#1892363).
* Fixed: Fixed text corruption when dragging text containing
unicode characters on Linux systems (bmo#1888202).
* Fixed: Fixed a correctness error when checking
`arguments.length` (and not using arguments otherwise) inside
of a generator or async function (bmo#1892699).
* Fixed: Fixed an issue that could lead to inconsistent focus
handling of `<select>` elements when opened (bmo#1893177).
* Wed Apr 24 2024 Manfred Hollstein <manfred.h@gmx.net>
- Fix build on Leap by requiring gcc13 which has been made available
as an update.
* Sun Apr 21 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 125.0.2
* The 125.0 and 125.0.1 releases were skipped due to problems
with a feature that proactively blocked downloads from
potentially untrustworthy URLs.
* New: Firefox now supports the AV1 codec for Encrypted Media
Extensions (EME), enabling higher-quality playback from video
streaming providers
* New: The Firefox PDF viewer now supports text highlighting.
* New: Firefox View now displays pinned tabs in the Open tabs
section. Tab indicators have also been added to Open tabs, so
users can do things like see which tabs are playing media and
quickly mute or unmute across windows. Indicators were also
added for bookmarks, tabs with notifications, and more!
their addresses upon submitting an address form, allowing
Firefox to autofill stored address information in the future.
* New: The URL Paste Suggestion feature provides a convenient
way for users to quickly visit URLs copied to the clipboard
in the address bar of Firefox. When the clipboard contains a
URL and the URL bar is focused, an autocomplete result
appears automatically. Activating the clipboard suggestion
will navigate the user to the URL with 1 click.
* New: Users of tab-specific Container add-ons can now search
in the Address Bar for tabs that are open in different
containers. Special thanks to volunteer contributor atararx
for kicking off the work on this feature!
* New: Firefox now provides an option to enable Web Proxy Auto-
Discovery (WPAD) while configured to use system proxy
settings.
* Changed: In a group of radio buttons where no option is
selected, the tab key now only reaches the first option
rather than cycling through all available options. The arrow
keys navigate between options as they do when there is a
selected option. This makes keyboard navigation more
efficient and consistent
* HTML5: Firefox now supports the `popover` global attribute
used for designating an element as a popover element. The
element won't be rendered until it is made visible, after
which it will appear on top of other page content.
* HTML5: WebAssembly multi-memory is now enabled by default.
Wasm multi-memory allows wasm modules to use and import
multiple independent linear memories. This enables more
efficient interoperability between modules and provides
better polyfills for upcoming wasm standards, such as the
component model.
* HTML5: Added support for Unicode Text Segmentation to
JavaScript.
* HTML5: Added support for `contextlost` and `contextrestored`
events on HTMLCanvasElement and OffscreenCanvas to allow user
code to recover from context loss with hardware accelerated
2d canvas.
* HTML5: Firefox now supports the
`navigator.clipboard.readText()` web API. A paste context
menu will appear for the user to confirm when attempting to
read clipboard data not provided by the same-origin page.
* HTML5: Added support for the `content-box` and `stroke-box`
keywords of the `transform-box` CSS property.
* HTML5: The `align-content` property now works in block
layout, allowing block direction alignment without needing a
flex or grid container.
* HTML5: Support for `SVGAElement.text` was removed in favor of
the more widely-implemented `SVGAElement.textContent` method.
* Developer: Following several requests, we have reintroduced
the option to disable the Pause Debugger Overlay
(`devtools.debugger.features.overlay`). This overlay appears
over the page content when the debugger pauses JavaScript
execution. In certain scenarios, the overlay can be
intrusive, making it challenging to interact with the page,
for instance, evaluating shades of color underneath.
* Developer: We've added a new drop-down menu button at the
bottom of the source view in the Debugger panel, specifically
designed for Source Map related actions. Users can now easily
disable or enable Source Maps support, open the Source Map
file in a new tab, switch between the original source and the
generated bundle, toggle the "open original source by
default" option, and view the Source Map status such as
errors, loading status, etc.
MFSA 2024-18 (bsc#1221327)
* CVE-2024-3852 (bmo#1883542)
GetBoundName in the JIT returned the wrong object
* CVE-2024-3853 (bmo#1884427)
Use-after-free if garbage collection runs during realm
initialization
* CVE-2024-3854 (bmo#1884552)
Out-of-bounds-read after mis-optimized switch statement
* CVE-2024-3855 (bmo#1885828)
Incorrect JIT optimization of MSubstr leads to out-of-bounds
reads
* CVE-2024-3856 (bmo#1885829)
Use-after-free in WASM garbage collection
* CVE-2024-3857 (bmo#1886683)
Incorrect JITting of arguments led to use-after-free during
garbage collection
* CVE-2024-3858 (bmo#1888892)
Corrupt pointer dereference in
js::CheckTracedThing<js::Shape>
* CVE-2024-3859 (bmo#1874489)
Integer-overflow led to out-of-bounds-read in the OpenType
sanitizer
* CVE-2024-3860 (bmo#1881417)
Crash when tracing empty shape lists
* CVE-2024-3861 (bmo#1883158)
Potential use-after-free due to AlignedBuffer self-move
* CVE-2024-3862 (bmo#1884457)
Potential use of uninitialized memory in MarkStack assignment
operator on self-assignment
* CVE-2024-3863 (bmo#1885855)
Download Protections were bypassed by .xrm-ms files on
Windows
* CVE-2024-3302 (bmo#1881183,
bmo#https://kb.cert.org/vuls/id/421644)
Denial of Service using HTTP/2 CONTINUATION frames
* CVE-2024-3864 (bmo#1888333)
Memory safety bug fixed in Firefox 125, Firefox ESR 115.10,
and Thunderbird 115.10
* CVE-2024-3865 (bmo#1881076, bmo#1884887, bmo#1885359,
bmo#1889049)
Memory safety bugs fixed in Firefox 125
- requires
NSS 3.99
rust 1.76
- add mozilla-libproxy-fix.patch to fix with-libproxy build variant
* Wed Apr 03 2024 Martin Sirringhaus <martin.sirringhaus@suse.com>
- Mozilla Firefox 124.0.2
https://www.mozilla.org/en-US/firefox/124.0.2/releasenotes/
* Fixed an issue where users with a large amount of bookmarks would
be unable to restore a bookmarks backup. (bmo#1884308)
* Fixed an issue that would cause open Firefox windows
to go blank or crash during video playback on sites such as
Netflix. (bmo#1883932)
* Fixed a crash that affected Linux AArch64 builds. (bmo#1866396)
* Fixed an issue where some users experienced difficulties loading
webpages due to changes made to the default AppArmor configuration
shipping in Ubuntu 24.04. (bmo#1884347)
* Fri Mar 22 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 124.0.1
https://www.mozilla.org/en-US/firefox/124.0.1/releasenotes/
MFSA 2024-15 (bsc#1221850)
* CVE-2024-29943 (bmo#1886849)
Out-of-bounds access via Range Analysis bypass
* CVE-2024-29944 (bmo#1886852)
Privileged JavaScript Execution via Event Handlers
Mozilla Firefox 124.0
https://www.mozilla.org/en-US/firefox/124.0/releasenotes/
MFSA 2024-12 (bsc#1221327)
* CVE-2024-2605 (bmo#1872920)
Windows Error Reporter could be used as a Sandbox escape vector
* CVE-2024-2606 (bmo#1879237)
Mishandling of WASM register values
* CVE-2024-2607 (bmo#1879939)
JIT code failed to save return registers on Armv7-A
* CVE-2024-2608 (bmo#1880692)
Integer overflow could have led to out of bounds write
* CVE-2023-5388 (bmo#1780432)
NSS susceptible to timing attack against RSA decryption
* CVE-2024-2609 (bmo#1866100)
Permission prompt input delay could expire when not in focus
* CVE-2024-2610 (bmo#1871112)
Improper handling of html and body tags enabled CSP nonce leakage
* CVE-2024-2611 (bmo#1876675)
Clickjacking vulnerability could have led to a user accidentally
granting permissions
* CVE-2024-2612 (bmo#1879444)
Self referencing object could have potentially led to a use-
after-free
* CVE-2024-2613 (bmo#1875701)
Improper handling of QUIC ACK frame data could have led to OOM
* CVE-2024-2614 (bmo#1685358, bmo#1861016, bmo#1880405, bmo#1881093)
Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9,
and Thunderbird 115.9
* CVE-2024-2615 (bmo#1881074, bmo#1881650, bmo#1882438)
Memory safety bugs fixed in Firefox 124
- requires
NSS = 3.98
rust-cbindgen >= 0.26
* Fri Mar 08 2024 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 123.0.1
* Fixed the *Firefox Translation* language indicator in the
address bar displaying a colored square icon instead of the
language code icon. (bmo#1879415)
* Fixed a regression with the `onChange` event not firing when
clearing the value of a `textarea` HTML field.
(bmo#1881457)
* Fixed a regression in the JavaScript JIT engine incorrectly
inlining strings in some cases. (bmo#1882386)
* Fixed: Fixed low contrast of text when selecting rows in the
Developer tools' Storage panel. (bmo#1877090)
* Thu Feb 22 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 123.0
https://www.mozilla.org/en-US/firefox/123.0/releasenotes/
MFSA 2024-05 (bsc#1220048)
* CVE-2024-1546 (bmo#1843752)
Out-of-bounds memory read in networking channels
* CVE-2024-1547 (bmo#1877879)
Alert dialog could have been spoofed on another site
* CVE-2024-1554 (bmo#1816390)
fetch could be used to effect cache poisoning
* CVE-2024-1548 (bmo#1832627)
Fullscreen Notification could have been hidden by select element
* CVE-2024-1549 (bmo#1833814)
Custom cursor could obscure the permission dialog
* CVE-2024-1550 (bmo#1860065)
Mouse cursor re-positioned unexpectedly could have led to
unintended permission grants
* CVE-2024-1551 (bmo#1864385)
Multipart HTTP Responses would accept the Set-Cookie header
in response parts
* CVE-2024-1555 (bmo#1873223)
SameSite cookies were not properly respected when opening a
website from an external browser
* CVE-2024-1556 (bmo#1870414)
Invalid memory access in the built-in profiler
* CVE-2024-1552 (bmo#1874502)
Incorrect code generation on 32-bit ARM devices
* CVE-2024-1553 (bmo#1855686, bmo#1867982, bmo#1871498, bmo#1872296,
bmo#1873521, bmo#1873577, bmo#1873597, bmo#1873866, bmo#1874080,
bmo#1874740, bmo#1875795, bmo#1875906, bmo#1876425, bmo#1878211,
bmo#1878286)
Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8,
and Thunderbird 115.8
* CVE-2024-1557 (bmo#1746471, bmo#1848829, bmo#1864011, bmo#1869175,
bmo#1869455, bmo#1869938, bmo#1871606)
Memory safety bugs fixed in Firefox 123
- requires NSS 3.97
* Tue Feb 13 2024 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 122.0.1
https://www.mozilla.org/en-US/firefox/122.0.1/releasenotes/
* Fixed the Library and Sidebar context menus only displaying
Multi-Account Containers icons in the "Open in New Container
Tab" menu. (bmo#1876518)
* Fixed an issue when clicking the Dismiss button in
notification pop-ups on Windows causing a webpage in a new tab.
(bmo#1848801)
* Fixed the yaru-remix system theme not applying correctly on
Linux. (bmo#1877002)
* Fixed adding an extra new line to a rule in the Developer
Tools' Inspector when copying it to the clipboard.
(bmo#1876220)
* Rolled back a keyboard behavior change made to the Developer
Tools' Rules view when validating a property name or input with
the Enter key.
This moves the focus to the next input, as was the behavior
in Firefox 121. (bmo#1877457)
* Tue Jan 30 2024 Martin Sirringhaus <martin.sirringhaus@suse.com>
- Recommend libfido2-udev on codestreams that exist, in order to try
to get security keys (e.g. Yubikeys) work out of the box. (bsc#1184272)
* Sat Jan 27 2024 Andreas Schwab <schwab@suse.de>
- Fix file list
* Sun Jan 21 2024 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 122.0
https://www.mozilla.org/en-US/firefox/122.0/releasenotes/
MFSA 2024-01 (bsc#1218955)
* CVE-2024-0741 (bmo#1864587)
Out of bounds write in ANGLE
* CVE-2024-0742 (bmo#1867152)
Failure to update user input timestamp
* CVE-2024-0743 (bmo#1867408)
Crash in NSS TLS method
* CVE-2024-0744 (bmo#1871089)
Wild pointer dereference in JavaScript
* CVE-2024-0745 (bmo#1871838)
Stack buffer overflow in WebAudio
* CVE-2024-0746 (bmo#1660223)
Crash when listing printers on Linux
* CVE-2024-0747 (bmo#1764343)
Bypass of Content Security Policy when directive unsafe-inline was set
* CVE-2024-0748 (bmo#1783504)
Compromised content process could modify document URI
* CVE-2024-0749 (bmo#1813463)
Phishing site popup could show local origin in address bar
* CVE-2024-0750 (bmo#1863083)
Potential permissions request bypass via clickjacking
* CVE-2024-0751 (bmo#1865689)
Privilege escalation through devtools
* CVE-2024-0752 (bmo#1866840)
Use-after-free could occur when applying update on macOS
* CVE-2024-0753 (bmo#1870262)
HSTS policy on subdomain could bypass policy of upper domain
* CVE-2024-0754 (bmo#1871605)
Crash when using some WASM files in devtools
* CVE-2024-0755 (bmo#1868456, bmo#1871445, bmo#1873701)
Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7,
and Thunderbird 115.7
- requires NSS 3.96.1
- rebased patches
* Tue Jan 09 2024 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 121.0.1
* Fixed unexpected line wrapping in some CJK contexts caused by
changes in ideographic space handling. bmo#1870973)
* Fixed a hang when loading sites containing column-based
layouts under some circumstances. bmo#1867784)
* Fixed missing rounded corners for videos playing over another
video. bmo#1869994)
* Fixed Firefox not closing properly and other applications being
unable to use a USB security key after being previously used
during a Firefox session. bmo#1863135)
* Wed Dec 20 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 121.0
https://www.mozilla.org/en-US/firefox/121.0/releasenotes
MFSA 2023-56 (bsc#1217974)
* CVE-2023-6856 (bmo#1843782)
Heap-buffer-overflow affecting WebGL DrawElementsInstanced
method with Mesa VM driver
* CVE-2023-6135 (bmo#1853908)
NSS susceptible to "Minerva" attack
* CVE-2023-6865 (bmo#1864123)
Potential exposure of uninitialized data in EncryptingOutputStream
* CVE-2023-6857 (bmo#1796023)
Symlinks may resolve to smaller than expected buffers
* CVE-2023-6858 (bmo#1826791)
Heap buffer overflow in nsTextFragment
* CVE-2023-6859 (bmo#1840144)
Use-after-free in PR_GetIdentitiesLayer
* CVE-2023-6866 (bmo#1849037)
TypedArrays lack sufficient exception handling
* CVE-2023-6860 (bmo#1854669)
Potential sandbox escape due to VideoBridge lack of texture
validation
* CVE-2023-6867 (bmo#1863863)
Clickjacking permission prompts using the popup transition
* CVE-2023-6861 (bmo#1864118)
Heap buffer overflow affected nsWindow::PickerOpen(void) in
headless mode
* CVE-2023-6868 (bmo#1865488)
WebPush requests on Firefox for Android did not require VAPID key
* CVE-2023-6869 (bmo#1799036)
Content can paint outside of sandboxed iframe
* CVE-2023-6870 (bmo#1823316)
Android Toast notifications may obscure fullscreen event
notifications
* CVE-2023-6871 (bmo#1828334)
Lack of protocol handler warning in some instances
* CVE-2023-6872 (bmo#1849186)
Browsing history leaked to syslogs via GNOME
* CVE-2023-6863 (bmo#1868901)
Undefined behavior in ShutdownObserver()
* CVE-2023-6864 (bmo#1736385, bmo#1810805, bmo#1846328, bmo#1856090,
bmo#1858033, bmo#1858509, bmo#1862777, bmo#1864015)
Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6,
and Thunderbird 115.6
* CVE-2023-6873 (bmo#1855327, bmo#1862089, bmo#1862723)
Memory safety bugs fixed in Firefox 121
- requires NSS 3.95
* Fri Dec 08 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 120.0.1 (boo#1217910)
* Fixed a bug that was causing persistent startup slowdowns
(bmo#1867095)
* Fixed an issue that was causing 100% CPU usage on sites such as
Google Maps. (bmo#1866409)
* Fixed an issue that was causing YouTube videos to show a green
screen when hardware acceleration was enabled. (bmo#1865928)
* Fixed an issue where the status bar was still visible when
viewing fullscreen video. (bmo#1853896)
* Fixed a startup crash affecting Linux users on some aarch64
systems with page sizes other than 4KB. (bmo#1866025)
* Wed Nov 22 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 120.0
https://www.mozilla.org/en-US/firefox/120.0/releasenotes
MFSA 2023-49 (bsc#1217230)
* CVE-2023-6204 (bmo#1841050)
Out-of-bound memory access in WebGL2 blitFramebuffer
* CVE-2023-6205 (bmo#1854076)
Use-after-free in MessagePort::Entangled
* CVE-2023-6206 (bmo#1857430)
Clickjacking permission prompts using the fullscreen
transition
* CVE-2023-6207 (bmo#1861344)
Use-after-free in ReadableByteStreamQueueEntry::Buffer
* CVE-2023-6208 (bmo#1855345)
Using Selection API would copy contents into X11 primary
selection.
* CVE-2023-6209 (bmo#1858570)
Incorrect parsing of relative URLs starting with "///"
* CVE-2023-6210 (bmo#1801501)
Mixed-content resources not blocked in a javascript: pop-up
* CVE-2023-6211 (bmo#1850200)
Clickjacking to load insecure pages in HTTPS-only mode
* CVE-2023-6212 (bmo#1658432, bmo#1820983, bmo#1829252,
bmo#1856072, bmo#1856091, bmo#1859030, bmo#1860943,
bmo#1862782)
Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5,
and Thunderbird 115.5
* CVE-2023-6213 (bmo#1849265, bmo#1851118, bmo#1854911)
Memory safety bugs fixed in Firefox 120
- rebased patches
* Wed Nov 08 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 119.0.1
* Fixed a bug causing colors in the <select> HTML element to not
be applied to dropdown menu arrows (bmo#1861253)
* Fixed a bug with the <input> HTML element state not changing
when dynamically updating the `disabled` attribute on an
ancestor <fieldset> (bmo#1861027)
* Fixed a bug causing elements with the indeterminate CSS
selector in a radio group to not update (bmo#1861346)
* Thu Oct 26 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 119.0
https://www.mozilla.org/en-US/firefox/119.0/releasenotes
MFSA 2023-45 (bsc#1216338)
* CVE-2023-5721 (bmo#1830820)
Queued up rendering could have allowed websites to clickjack
* CVE-2023-5722 (bmo#1738426)
Cross-Origin size and header leakage
* CVE-2023-5723 (bmo#1802057)
Invalid cookie characters could have led to unexpected errors
* CVE-2023-5724 (bmo#1836705)
Large WebGL draw could have led to a crash
* CVE-2023-5725 (bmo#1845739)
WebExtensions could open arbitrary URLs
* CVE-2023-5726 (bmo#1846205)
Full screen notification obscured by file open dialog on macOS
* CVE-2023-5727 (bmo#1847180)
Download Protections were bypassed by .msix, .msixbundle,
.appx, and .appxbundle files on Windows
* CVE-2023-5728 (bmo#1852729)
Improper object tracking during GC in the JavaScript engine
could have led to a crash.
* CVE-2023-5729 (bmo#1823720)
Fullscreen notification dialog could have been obscured by
WebAuthn prompts
* CVE-2023-5730 (bmo#1836607, bmo#1840918, bmo#1848694, bmo#1848833,
bmo#1850191, bmo#1850259, bmo#1852596, bmo#1853201, bmo#1854002,
bmo#1855306, bmo#1855640, bmo#1856695)
Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4,
and Thunderbird 115.4.1
* CVE-2023-5731 (bmo#1690111, bmo#1721904, bmo#1851803, bmo#1854068)
Memory safety bugs fixed in Firefox 119
- requires NSS 3.94
* Wed Oct 11 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 118.0.2
* Fix games not loading on betsoft.com (bmo#1856145)
* Fix printing issues for some SVG images (bmo#1853727)
* Fix CORS XHR with authentication no longer working (bmo#1855650)
* Fix h264 WebRTC video not working in some contexts (bmo#1855636)
* Fix Firefox Translations not working on some pages
(bmo#1841656, bmo#1855307)
* Stability fixes (bmo#1851991, bmo#1799326, bmo#1856637)
* Sat Sep 30 2023 Björn Bidar <bjorn.bidar@thaodan.de>
- Activate KDE integration again, included rebased and updated
patches, firefox-kde.patch and mozilla-kde.patch, (upstream
removed special files handling for preferences but that has no
effect since we haven't shipped obsolete kde.js for a while)
(boo#1216027)
* Fri Sep 29 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 118.0.1
MFSA 2023-44 (bsc#1215814)
* CVE-2023-5217 (bmo#1855550),
Heap buffer overflow in libvpx
* Mon Sep 25 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 118.0
MFSA 2023-41 (bsc#1215575)
* CVE-2023-5168 (bmo#1846683)
Out-of-bounds write in FilterNodeD2D1
* CVE-2023-5169 (bmo#1846685)
Out-of-bounds write in PathOps
* CVE-2023-5170 (bmo#1846686)
Memory leak from a privileged process
* CVE-2023-5171 (bmo#1851599)
Use-after-free in Ion Compiler
* CVE-2023-5172 (bmo#1852218)
Memory Corruption in Ion Hints
* CVE-2023-5173 (bmo#1823172)
Out-of-bounds write in HTTP Alternate Services
* CVE-2023-5174 (bmo#1848454)
Double-free in process spawning on Windows
* CVE-2023-5175 (bmo#1849704)
Use-after-free of ImageBitmap during process shutdown
* CVE-2023-5176 (bmo#1836353, bmo#1842674, bmo#1843824, bmo#1843962,
bmo#1848890, bmo#1850180, bmo#1850983, bmo#1851195)
Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3,
and Thunderbird 115.3
- requires NSS 3.93
- add mozilla-bmo1822730.patch
- deactivated KDE integration temporarily
(removed mozilla-kde.patch and firefox-kde.patch for now)
* Tue Sep 12 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 117.0.1
* Fix a bug causing extensions using an event page for long-
running tasks to be terminated while running, causing
unexpected behavior changes (bmo#1851373)
* Temporarily revert an intentional behavior change preventing
Javascript from changing URL.protocol (bmo#1850954).
* Fix audio worklets not working for sites using WebAssembly
exception handling (bmo#1851468)
* Fix the Reopen all tabs option in the Recently closed tabs
menu sometimes failing to open all tabs (bmo#1850856)
* Fix the bookmarks menu sometimes remaining partially visible
when minimizing Firefox (bmo#1843700)
* Fix an issue causing incorrect time zones to be detected on
some sites (bmo#1848615)
* MFSA 2023-40 CVE-2023-4863 (boo#1215231)
Heap buffer overflow in WebP
* Sun Aug 27 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 117.0
https://www.mozilla.org/en-US/firefox/117.0/releasenotes
MFSA 2023-34 (bsc#1214606)
* CVE-2023-4573 (bmo#1846687)
Memory corruption in IPC CanvasTranslator
* CVE-2023-4574 (bmo#1846688)
Memory corruption in IPC ColorPickerShownCallback
* CVE-2023-4575 (bmo#1846689)
Memory corruption in IPC FilePickerShownCallback
* CVE-2023-4576 (bmo#1846694)
Integer Overflow in RecordedSourceSurfaceCreation
* CVE-2023-4577 (bmo#1847397)
Memory corruption in JIT UpdateRegExpStatics
* CVE-2023-4578 (bmo#1839007)
Error reporting methods in SpiderMonkey could have triggered
an Out of Memory Exception
* CVE-2023-4579 (bmo#1842766)
Persisted search terms were formatted as URLs
* CVE-2023-4580 (bmo#1843046)
Push notifications saved to disk unencrypted
* CVE-2023-4581 (bmo#1843758)
XLL file extensions were downloadable without warnings
* CVE-2023-4582 (bmo#1773874)
Buffer Overflow in WebGL glGetProgramiv
* CVE-2023-4583 (bmo#1842030)
Browsing Context potentially not cleared when closing Private
Window
* CVE-2023-4584 (bmo#1843968, bmo#1845205, bmo#1846080,
bmo#1846526, bmo#1847529)
Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15,
Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2
* CVE-2023-4585 (bmo#1751583, bmo#1841082, bmo#1847904, bmo#1848999)
Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2,
and Thunderbird 115.2
- requires
NSS = 3.92
rustc = 1.71
* Thu Aug 17 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 116.0.3
* Fixed an issue for OPFS users that broke access to files that
were locally cached in a previous version
(bmo#1847989, bmo#1847619)
* Fixed an issue that was breaking screensharing for some users
on Wayland (bmo#1841851)
* Fixed an issue where a fullscreen notification was persistently
being shown to a user, even after disabling it (bmo#1847901)
* Fixed an issue where Firefox would hang when doing a Google
search (bmo#1847066)
* Tue Aug 15 2023 Adam Majer <adam.majer@suse.de>
- After further testing on memory consumption during linking, it's
safe to remove most of the memory reducing options for ix86 linker.
A combination of these actually resulted in the OOM condition.
It's even possible to add basic debugging info while keeping
linker memory consumption at about 2GB
* Thu Aug 10 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 116.0.2
* fixes for other platforms
* Wed Aug 09 2023 Adam Majer <adam.majer@suse.de>
- Workarold ld bug causing OOM when linking on 32-bit
- Remove -j1 limit on x86. The build runs on 64-bit kernel with a
32-bit userland. This means there is plenty of memory available
but userland is limited to just under 4GB per process.
* Sat Aug 05 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 116.0.1
* fixes for other platforms
* Sat Aug 05 2023 Andreas Schwab <schwab@suse.de>
- ship vaapitest binary for supported archs
* Fri Aug 04 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- re-enable ppc64le
- ship v4l2test binary for supported archs
- drop obsolete mozilla-bmo1775202.patch
* Sun Jul 30 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 116.0
* https://www.mozilla.org/en-US/firefox/116.0/releasenotes/
MFSA 2023-29 (bsc#1213746)
* CVE-2023-4045 (bmo#1833876)
Offscreen Canvas could have bypassed cross-origin restrictions
* CVE-2023-4046 (bmo#1837686)
Incorrect value used during WASM compilation
* CVE-2023-4047 (bmo#1839073)
Potential permissions request bypass via clickjacking
* CVE-2023-4048 (bmo#1841368)
Crash in DOMParser due to out-of-memory conditions
* CVE-2023-4049 (bmo#1842658)
Fix potential race conditions when releasing platform objects
* CVE-2023-4050 (bmo#1843038)
Stack buffer overflow in StorageManager
* CVE-2023-4051 (bmo#1821884)
Full screen notification obscured by file open dialog
* CVE-2023-4052 (bmo#1824420)
File deletion and privilege escalation through Firefox uninstaller
* CVE-2023-4053 (bmo#1839079)
Full screen notification obscured by external program
* CVE-2023-4054 (bmo#1840777)
Lack of warning when opening appref-ms files
* CVE-2023-4055 (bmo#1782561)
Cookie jar overflow caused unexpected cookie jar state
* CVE-2023-4056 (bmo#1820587, bmo#1824634, bmo#1839235,
bmo#1842325, bmo#1843847)
Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1,
Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14
* CVE-2023-4057 (bmo#1841682)
Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1,
and Thunderbird 115.1
* CVE-2023-4058 (bmo#1819160, bmo#1828024)
Memory safety bugs fixed in Firefox 116
- require NSS 3.91
- remove obsolete mozilla-fix-top-level-asm.patch
- re-enable LTO
* Fri Jul 28 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 115.0.3
* fixes for other platforms
- remove bashisms from firefox startup script (boo#1213657)
* Thu Jul 13 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 115.0.2
* Fixed a bug with displaying a caret in the text editor on some websites
(bmo#1840804)
* Fixed a bug with broken audio rendering on some websites (bmo#1841982)
* Fixed a bug with patternTransform translate using the wrong units
(bmo#1840746)
MFSA 2023-26 (bsc#1213230)
* CVE-2023-3600 (bmo#1839703)
Use-after-free in workers
* Fri Jul 07 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
- Mozilla Firefox 115.0.1
* fixes for other platforms
* Sun Jul 02 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 115.0
* Support for importing payment methods saved in Chrome-based browser
* Hardware video decoding is now enabled for Intel GPUs on Linux
* The Tab Manager dropdown now features close buttons, so tabs
can be closed more quickly
* Streamlined the user interface for importing data in from other browsers
* Users without platform support for H264 video decoding can now
fallback to Cisco's OpenH264 plugin for playback.
* Undo and redo are now available in Password fields
* Changed: On Linux, middle clicks on the new tab button will
now open the xclipboard contents in the new tab. If the
xclipboard content is a URL then that URL is opened, any
other text is opened with your default search provider.
* Changed: For users with a Firefox Colorways built-in theme,
the theme will be automatically migrated to the same theme
hosted on addons.mozilla.org for Firefox profiles that have
disabled add-ons auto-updates. This will allow users to keep
their Colorways theme when they are later removed from
Firefox installer files.
* Changed: Certain Firefox users may come across a message in
the extensions panel indicating that their add-ons are not
allowed on the site currently open. We have introduced a new
back-end feature to only allow some extensions monitored by
Mozilla to run on specific websites for various reasons,
including security concerns.
* HTML5: The builtin editor now behaves similarly to other
browsers with `contenteditable` and `designMode` when
splitting a node, e.g. typing Enter to split a paragraph, and
also when joining two nodes, e.g. typing Backspace at the
start of a paragraph to join the paragraph and the previous
one.
When a node is split, the builtin editor creates a new node
after the original one instead of before, i.e. creates the
right node instead of the left node.
Similarly, when two nodes are joined, the builtin editor
deletes the latter node and moves its children to the end of
the preceding node instead of deleting the former node and
moving its child to the start of the following node.
* HTML5: WebRTC application developers can now specify a target
in milliseconds of media for the jitter buffer to hold.
Altering the target value allows applications to control the
tradeoff between playout delay and the risk of running out of
audio or video frames due to network jitter.
* HTML5: Change array by copy provides additional methods on
`Array.prototype` and `TypedArray.prototype` to enable
changes on the array by returning a new copy of it with the
change.
* HTML5: The animation-composition property is now supported,
allowing a declarative way to define the composite operation
used when multiple animations affect the same property
simultaneously.
* HTML5: Added the URL.canParse() function to allow easy and
fast checking if URLs are valid and parseable.
* HTML5: IndexedDB is now also supported in private browsing
without memory limits thanks to encrypted storage on disk.
The temporary keys to decrypt the information are hold in RAM
only and all stored information is purged at the normal end
of a private browsing session from disk.
* HTML5: Supports conditions are now supported in CSS import
rules @import supports(...)
* Developer: In web development, we rely on third-party
libraries which you may not be interested in while debugging.
These can be ignored. Ignoring them means that breakpoints
will not get hit and they are skipped during stepping.
You can now choose to **Hide ignore-listed sources** in the
Developer Tools source tree
* Developer: We have introduced a new option,
`devtools.f12_enabled`, that can be utilized to prevent the
accidental use of the F12 key, which opens the DevTools
toolbox (bug).
* Enterprise: You can find information about policy updates and
enterprise specific bug fixes in the Firefox for Enterprise
115 Release Notes.
MFSA 2023-22 (bsc#1212438)
* CVE-2023-3482 (bmo#1839464)
Block all cookies bypass for localstorage
* CVE-2023-37201 (bmo#1826002)
Use-after-free in WebRTC certificate generation
* CVE-2023-37202 (bmo#1834711)
Potential use-after-free from compartment mismatch in SpiderMonkey
* CVE-2023-37203 (bmo#291640)
Drag and Drop API may provide access to local system files
* CVE-2023-37204 (bmo#1832195)
Fullscreen notification obscured via option element
* CVE-2023-37205 (bmo#1704420)
URL spoofing in address bar using RTL characters
* CVE-2023-37206 (bmo#1813299)
Insufficient validation of symlinks in the FileSystem API
* CVE-2023-37207 (bmo#1816287)
Fullscreen notification obscured
* CVE-2023-37208 (bmo#1837675)
Lack of warning when opening Diagcab files
* CVE-2023-37209 (bmo#1837993)
Use-after-free in `NotifyOnHistoryReload`
* CVE-2023-37210 (bmo#1821886)
Full-screen mode exit prevention
* CVE-2023-37211 (bmo#1832306, bmo#1834862, bmo#1835886,
bmo#1836550, bmo#1837450)
Memory safety bugs fixed in Firefox 115, Firefox ESR 102.13,
and Thunderbird 102.13
* CVE-2023-37212 (bmo#1750870, bmo#1825552, bmo#1826206, bmo#1827076,
bmo#1828690, bmo#1833503, bmo#1835710, bmo#1838587)
Memory safety bugs fixed in Firefox 115
- Requires NSS 3.90
- Add patches:
mozilla-rust-disable-future-incompat.patch
mozilla-bmo1775202.patch
mozilla-partial-revert-1768632.patch
- removed obsolete mozilla-buildfixes.patch
* Tue Jun 20 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
- Mozilla Firefox 114.0.2:
* Several crash fixes
* Web Extensions: Fixes for 114 regressions in Native Messaging
support
* Tue Jun 20 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- do not enable LTO as it caused crashes now (boo#1212101)
* Sat Jun 10 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
- Mozilla Firefox 114.0.1
* Fix a startup crash (bmo#1837201, boo#1212101)
* Fri Jun 09 2023 Martin Sirringhaus <martin.sirringhaus@suse.com>
- Only install vaapitest for wayland-enabled builds, where it gets built
- Rebase mozilla-silence-no-return-type.patch
- Rebase s390x-patches, and remove obsolete patches:
mozilla-bmo1005535.patch mozilla-s390x-skia-gradient.patch
* Mon Jun 05 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 114.0
MFSA 2023-20 (bsc#1211922)
* CVE-2023-34414 (bmo#1695986)
Click-jacking certificate exceptions through rendering lag
* CVE-2023-34415 (bmo#1811999)
Site-isolation bypass on sites that allow open redirects to
data: urls
* CVE-2023-34416 (bmo#1752703, bmo#1818394, bmo#1826875,
bmo#1827340, bmo#1827655, bmo#1828065, bmo#1830190,
bmo#1830206, bmo#1830795, bmo#1833339)
Memory safety bugs fixed in Firefox 114 and Firefox ESR
102.12
* CVE-2023-34417 (bmo#1746447, bmo#1820903, bmo#1832832)
Memory safety bugs fixed in Firefox 114
* New: Added UI to manage the DNS over HTTPS exception list.
(bmo#1596847)
* New: Bookmarks can now be searched from the Bookmarks menu.
The Bookmarks menu is accessible by adding the *Bookmarks
menu* button to the toolbar. (bmo#1736937)
* New: Restrict searches to your local browsing history by
selecting *Search history* from the History, Library or
Application menu buttons. (bmo#1736939)
* New: Mac users can now capture video from their cameras in
all supported native resolutions. This enables resolutions
higher than 1280x720. (bmo#1806604)
* New: It is now possible to reorder the extensions listed in
the extensions panel. (bmo#1805924)
* New: Users on macOS, Linux, and Windows 7 can now use FIDO2 /
WebAuthn authenticators over USB. Some advanced features,
such as fully passwordless logins, require a PIN to be set on
the authenticator. (bmo#1814487)
* New: Pocket Recommended content can now be seen in France,
Italy, and Spain. (bmo#None)
* Changed: DNS over HTTPS settings are now part of the
* Privacy & Security* section of the *Settings* page and allow
the user to choose from all the supported modes.
(bmo#1610741)
* HTML5: DOM: Added support for ES Modules on DedicatedWorker
and SharedWorker
* HTML5: WebTransport is now enabled by default and will be
going to release with 114. As the original Explainer notes,
it enables multiple use-cases that are hard or impossible to
handle without it, especially for Gaming and live streaming.
It covers cases that are problematic for alternative
mechanisms, such as WebSockets.
Built on top of HTTP3 (HTTP2 support will be coming later).
The current implementation in Firefox is passing 505 out of
565 Web-Platform Tests.
* HTML5: CSS: The `infinity` and `NaN` constants are now
supported inside the `calc()` function. (bmo#1830759)
* Developer: The *Copy as cURL* feature, available in the
Network panel, has been enhanced. It now supports the
- `-compressed` argument. (bmo#1776120)
* Developer: The Accessibility Inspector has been improved to
accurately recognize all the ARIA roles like `banner`,
`main`, `navigation`, and `contentinfo`, etc. This
enhancement is particularly beneficial for web developers
working with ARIA roles to improve web accessibility.
(bmo#1572512)
* Developer: Firefox now provides support for the CSS Cascading
Level 4 `supports()` syntax for `@import` rules. This allows
for the importation of other stylesheets based on support-
dependency. In addition, the Inspector panel now accurately
displays the conditions at the top of the imported rule.
- requires NSS 3.89.1
* Wed May 24 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
- Mozilla Firefox 113.0.2 (boo#1211696)
* Fixed: Fixed a bug which could cause Firefox to freeze on
some pages when loading them with the Developer Tools Web
Console open (bmo#1828026)
* Fixed: Fixed a bug which would cause the bookmarks and
history sidebars to not properly react to the browser window
being vertically resized (bmo#1831535)
* Sat May 13 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
- Mozilla Firefox 113.0.1
* UI fixes for other platforms
- upstream signing key updated
* Tue May 09 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 113.0
* https://www.mozilla.org/en-US/firefox/113.0/releasenotes
MFSA 2023-16 (bsc#1211175)
* CVE-2023-32205 (bmo#1753339, bmo#1753341)
Browser prompts could have been obscured by popups
* CVE-2023-32206 (bmo#1824892)
Crash in RLBox Expat driver
* CVE-2023-32207 (bmo#1826116)
Potential permissions request bypass via clickjacking
* CVE-2023-32208 (bmo#1646034)
Leak of script base URL in service workers via import()
* CVE-2023-32209 (bmo#1767194)
Persistent DoS via favicon image
* CVE-2023-32210 (bmo#1776755)
Incorrect principal object ordering
* CVE-2023-32211 (bmo#1823379)
Content process crash due to invalid wasm code
* CVE-2023-32212 (bmo#1826622)
Potential spoof due to obscured address bar
* CVE-2023-32213 (bmo#1826666)
Potential memory corruption in FileReader::DoReadData()
* MFSA-TMP-2023-0002 (bmo#1814560, bmo#1814790, bmo#1819796)
Race condition in dav1d decoding
* CVE-2023-32214 (bmo#1828716)
Potential DoS via exposed protocol handlers
* CVE-2023-32215 (bmo#1540883, bmo#1751943, bmo#1814856, bmo#1820210,
bmo#1821480, bmo#1827019, bmo#1827024, bmo#1827144, bmo#1827359,
bmo#1830186)
Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
* CVE-2023-32216 (bmo#1746479, bmo#1806852, bmo#1815987,
bmo#1820359, bmo#1823568, bmo#1824803, bmo#1824834, bmo#1825170,
bmo#1827020, bmo#1828130)
Memory safety bugs fixed in Firefox 113
- removed obsolete mozilla-bmo1568145.patch
* Sun May 07 2023 Aaron Puchert <aaronpuchert@alice-dsl.net>
- Fix i586 build by reducing debug info to -g1. (boo#1210168)
* Tue Apr 25 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 112.0.2
* Fix a high memory usage issue with animated images in minimized
(or completely covered) windows, especially when using animated
themes (bmo#1828587)
* Fix an issue where Linux users with bitmap fonts installed may
have had entire sections of text invisible to them on some
sites (bmo#1827950)
* Fri Apr 21 2023 Manfred Hollstein <manfred.h@gmx.net>
- Include Leap 15.5 in check for which python version is required.
* Thu Apr 20 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
- Mozilla Firefox 112.0.1
* Fix a bug where cookie dates appear to be set in the far
future after updating Firefox. This may have caused cookies to
be unintentionally purged (bmo#1827669)
* Mon Apr 10 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 112.0
* https://www.mozilla.org/en-US/firefox/112.0/releasenotes/
MFSA 2023-13 (bsc#1210212)
* CVE-2023-29531 (bmo#1794292)
Out-of-bound memory access in WebGL on macOS
* CVE-2023-29532 (bmo#1806394)
Mozilla Maintenance Service Write-lock bypass
* CVE-2023-29533 (bmo#1798219, bmo#1814597)
Fullscreen notification obscured
* CVE-2023-29534 (bmo#1816007, bmo#1816059, bmo#1821155, bmo#1821576,
bmo#1821906, bmo#1822298, bmo#1822305)
Fullscreen notification could have been obscured on Firefox
for Android
* MFSA-TMP-2023-0001 (bmo#1819244)
Double-free in libwebp
* CVE-2023-29535 (bmo#1820543)
Potential Memory Corruption following Garbage Collector compaction
* CVE-2023-29536 (bmo#1821959)
Invalid free from JavaScript code
* CVE-2023-29537 (bmo#1823365, bmo#1824200, bmo#1825569)
Data Races in font initialization code
* CVE-2023-29538 (bmo#1685403)
Directory information could have been leaked to WebExtensions
* CVE-2023-29539 (bmo#1784348)
Content-Disposition filename truncation leads to Reflected
File Download
* CVE-2023-29540 (bmo#1790542)
Iframe sandbox bypass using redirects and sourceMappingUrls
* CVE-2023-29541 (bmo#1810191)
Files with malicious extensions could have been downloaded
unsafely on Linux
* CVE-2023-29542 (bmo#1810793, bmo#1815062)
Bypass of file download extension restrictions
* CVE-2023-29543 (bmo#1816158)
Use-after-free in debugging APIs
* CVE-2023-29544 (bmo#1818781)
Memory Corruption in garbage collector
* CVE-2023-29545 (bmo#1823077)
Windows Save As dialog resolved environment variables
* CVE-2023-29546 (bmo#1780842)
Screen recording in Private Browsing included address bar on
Android
* CVE-2023-29547 (bmo#1783536)
Secure document cookie could be spoofed with insecure cookie
* CVE-2023-29548 (bmo#1822754)
Incorrect optimization result on ARM64
* CVE-2023-29549 (bmo#1823042)
Javascript's bind function may have failed
* CVE-2023-29550 (bmo#1720594, bmo#1751945, bmo#1812498, bmo#1814217,
bmo#1818357, bmo#1818762, bmo#1819493, bmo#1820389, bmo#1820602,
bmo#1821448, bmo#1822413, bmo#1824828)
Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10
* CVE-2023-29551 (bmo#1763625, bmo#1814314, bmo#1815798, bmo#1815890,
bmo#1819239, bmo#1819465, bmo#1819486, bmo#1819492, bmo#1819957,
bmo#1820514, bmo#1820776, bmo#1821838, bmo#1822175, bmo#1823547)
Memory safety bugs fixed in Firefox 112
- requires
* NSS 3.89
* Python >= 3.7 (for build)
- removed obsolete mozilla-bmo1807652.patch
- Fix Icons displayed incorrectly on GNOME/wayland via WMCLASS
in desktop file
* Mon Mar 27 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 111.0.1 (boo#1209688)
* Fixed a crash on macOS while pinch-zooming under some circumstances
(bmo#1658986)
* Fixed a bug causing Firefox to freeze on startup for some
Windows users (bmo#1823159)
- fix build on Tumbleweed (mozilla-bmo1807652.patch)
- exclude i586/i686 once again because it fails to link libxul due
to its size
* Tue Mar 14 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 111.0
* https://www.mozilla.org/en-US/firefox/111.0/releasenotes
MFSA 2023-09 (bsc#1209173)
* CVE-2023-28159 (bmo#1783561)
Fullscreen Notification could have been hidden by download
popups on Android
* CVE-2023-25748 (bmo#1798798)
Fullscreen Notification could have been hidden by window
prompts on Android
* CVE-2023-25749 (bmo#1810705)
Firefox for Android may have opened third-party apps without
a prompt
* CVE-2023-25750 (bmo#1814733)
Potential ServiceWorker cache leak during private browsing mode
* CVE-2023-25751 (bmo#1814899)
Incorrect code generation during JIT compilation
* CVE-2023-28160 (bmo#1802385)
Redirect to Web Extension files may have leaked local path
* CVE-2023-28164 (bmo#1809122)
URL being dragged from a removed cross-origin iframe into the
same tab triggered navigation
* CVE-2023-28161 (bmo#1811181)
One-time permissions granted to a local file were extended to
other local files loaded in the same tab
* CVE-2023-28162 (bmo#1811327)
Invalid downcast in Worklets
* CVE-2023-25752 (bmo#1811627)
Potential out-of-bounds when accessing throttled streams
* CVE-2023-28163 (bmo#1817768)
Windows Save As dialog resolved environment variables
* CVE-2023-28176 (bmo#1808352, bmo#1811637, bmo#1815904, bmo#1817442,
bmo#1818674)
Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9
* CVE-2023-28177 (bmo#1803109, bmo#1808832, bmo#1809542, bmo#1817336)
Memory safety bugs fixed in Firefox 111
- ensure gcc11-c++ gets used on Leap 15.5
- requires NSS >= 3.88.1
- removed obsolete patches
gcc13-fix.patch
mozilla-bmo1810584.patch
- rebased patches
- update create-tar.sh
* Tue Mar 07 2023 Martin Liška <mliska@suse.cz>
- Cherry-pick upstream changes for GCC 13 in gcc13-fix.patch.
* Mon Mar 06 2023 Andreas Schwab <schwab@suse.de>
- Limit memory use on riscv64
* Sat Mar 04 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Fix 32 bit build bmo#1810584 (add mozilla-bmo1810584.patch)
* Fri Mar 03 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 110.0.1 (boo#1208886)
* Fixed clearing recent cookies clears all cookies
(bmo#1816279)
* Fixed WebGL crashes on Linux when ran inside a VMWare virtual
machine (bmo#1807942)
* Fixed a bug with CSP serialization causing bugs with the MitID
Digital ID in Denmark (bmo#1819096)
* Wed Feb 15 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 110.0
* https://www.mozilla.org/en-US/firefox/110.0/releasenotes
MFSA 2023-05 (bsc#1208144)
* CVE-2023-25728 (bmo#1790345)
Content security policy leak in violation reports using iframes
* CVE-2023-25730 (bmo#1794622)
Screen hijack via browser fullscreen mode
* CVE-2023-25743 (bmo#1800203)
Fullscreen notification not shown in Firefox Focus
* CVE-2023-0767 (bmo#1804640)
Arbitrary memory write via PKCS 12 in NSS
* CVE-2023-25735 (bmo#1810711)
Potential use-after-free from compartment mismatch in SpiderMonkey
* CVE-2023-25737 (bmo#1811464)
Invalid downcast in SVGUtils::SetupStrokeGeometry
* CVE-2023-25738 (bmo#1811852)
Printing on Windows could potentially crash Firefox with some
device drivers
* CVE-2023-25739 (bmo#1811939)
Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext
* CVE-2023-25729 (bmo#1792138)
Extensions could have opened external schemes without user knowledge
* CVE-2023-25732 (bmo#1804564)
Out of bounds memory write from EncodeInputStream
* CVE-2023-25734 (bmo#1784451, bmo#1809923, bmo#1810143, bmo#1812338)
Opening local .url files could cause unexpected network loads
* CVE-2023-25740 (bmo#1812354)
Opening local .scf files could cause unexpected network loads
* CVE-2023-25731 (bmo#1801542)
Prototype pollution when rendering URLPreview
* CVE-2023-25733 (bmo#1808632)
Possible null pointer dereference in TaskbarPreviewCallback
* CVE-2023-25736 (bmo#1811331)
Invalid downcast in GetTableSelectionMode
* CVE-2023-25741 (bmo#1437126, bmo#1812611, bmo#1813376)
Same-origin policy leak via image drag and drop
* CVE-2023-25742 (bmo#1813424)
Web Crypto ImportKey crashes tab
* CVE-2023-25744 (bmo#1789449, bmo#1803628, bmo#1810536)
Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8
* CVE-2023-25745 (bmo#1688592, bmo#1797186, bmo#1804998,
bmo#1806521, bmo#1813284)
Memory safety bugs fixed in Firefox 110
- requires
NSS = 3.87
rust/cargo = 1.66
- update create-tar.sh
* Wed Feb 01 2023 Andreas Stieger <andreas.stieger@gmx.de>
- Mozilla Firefox 109.0.1
* Fixed jank when loading pages containing a large number of
emoji characters (bmo#1809081)
* Fixed an issue causing authentication prompts to not appear
when loading pages in some enterprise environments
(bmo#1809151)
* ixed inconsistent sizing of event listener checkboxes inside
the Inspector developer tool (bmo#1811760)
* Mon Jan 16 2023 Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Firefox 109.0
MFSA 2023-01 (bsc#1207119)
* CVE-2023-23597 (bmo#1538028)
Logic bug in process allocation allowed to read arbitrary
files
* CVE-2023-23598 (bmo#1800425)
Arbitrary file read from GTK drag and drop on Linux
* CVE-2023-23599 (bmo#1777800)
Malicious command could be hidden in devtools output on
Windows
* CVE-2023-23600 (bmo#1787034)
Notification permissions persisted between Normal and Private
Browsing on Android
* CVE-2023-23601 (bmo#1794268)
URL being dragged from cross-origin iframe into same tab
triggers navigation
* CVE-2023-23602 (bmo#1800890)
Content Security Policy wasn't being correctly applied to
WebSockets in WebWorkers
* CVE-2023-23603 (bmo#1800832)
Calls to <code>console.log</code> allowed bypasing Content
Security Policy via format directive
* CVE-2023-23604 (bmo#1802346)
Creation of duplicate <code>SystemPrincipal</code> from less
secure contexts
* CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)
Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
* CVE-2023-23606 (bmo#1764974, bmo#1798591, bmo#1799201,
bmo#1800446, bmo#1801248, bmo#1802100, bmo#1803393,
bmo#1804626, bmo#1804971, bmo#1807004)
Memory safety bugs fixed in Firefox 109
- requires NSS 3.86
- rebased patches
* Fri Jan 06 2023 Luciano Santos <luc14n0@opensuse.org>
- Mozilla Firefox 108.0.2
* Fixes a crash that might occur when managing browser history
(bmo#1806408).
- Drop merged-upstream mozilla-bmo1805809.patch.
/usr/lib/firefox-esr /usr/lib/firefox-esr/browser/extensions /usr/lib/firefox-esr/browser/extensions/langpack-ar@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-ca@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-cs@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-da@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-de@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-el@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-en-GB@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-es-AR@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-es-CL@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-es-ES@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-fi@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-fr@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-hu@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-it@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-ja@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-ko@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-nb-NO@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-nl@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-pl@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-pt-BR@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-pt-PT@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-ru@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-sv-SE@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-zh-CN@firefox.mozilla.org.xpi /usr/lib/firefox-esr/browser/extensions/langpack-zh-TW@firefox.mozilla.org.xpi
Generated by rpm2html 1.8.1
Fabrice Bellet, Thu Apr 16 22:47:58 2026