Package firefox-esr: Information

    Source package: firefox-esr
    Version: 115.11.0-alt1
    Latest version according to Repology
    Build time:  May 19, 2024, 09:48 PM in the task #347636
    Category: Networking/WWW
    Report package bug
    FTBFS
    ArchitectureFTBFS sinceUpdate
    x86_64May 23, 2024June 9, 2024
    i586May 25, 2024June 8, 2024

    License: MPL-2.0
    Summary: The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
    Description: 
    The Mozilla Firefox project is a redesign of Mozilla's browser component,
    written using the XUL user interface language and designed to be
    cross-platform.

    List of rpms provided by this srpm:
    firefox-esr (x86_64, i586, aarch64)
    firefox-esr-config-privacy (x86_64, i586, aarch64)
    firefox-esr-debuginfo (x86_64, i586, aarch64)
    firefox-esr-wayland (x86_64, i586, aarch64)

    Maintainer: Andrey Cherepanov



      1. /dev/shm
      2. /proc
      3. alternatives
      4. autoconf_2.13
      5. autoconf_2.13
      6. browser-plugins-npapi-devel
      7. bzlib-devel
      8. chrpath
      9. clang15.0
      10. clang15.0-devel
      11. glibc-kernheaders-generic
      12. gst-plugins1.0-devel
      13. gstreamer1.0-devel
      14. libvpx-devel
      15. libwireless-devel
      16. libxkbcommon-devel
      17. lld15.0-devel
      18. llvm15.0-devel
      19. mozilla-common-devel
      20. nasm
      21. node
      22. libGL-devel
      23. rpm-build-mozilla.org
      24. pkgconfig(alsa)
      25. pkgconfig(aom)
      26. pkgconfig(bzip2)
      27. pkgconfig(cairo)
      28. pkgconfig(dav1d)
      29. pkgconfig(dbus-1)
      30. rpm-macros-alternatives
      31. pkgconfig(dbus-glib-1)
      32. pkgconfig(dri)
      33. pkgconfig(fontconfig)
      34. pkgconfig(freetype2)
      35. pkgconfig(gio-2.0)
      36. pkgconfig(graphite2)
      37. pkgconfig(gtk+-2.0)
      38. pkgconfig(gtk+-3.0)
      39. fontconfig-devel
      40. pkgconfig(harfbuzz)
      41. pkgconfig(hunspell)
      42. pkgconfig(icu-i18n)
      43. pkgconfig(libcurl)
      44. pkgconfig(libdrm)
      45. pkgconfig(libevent)
      46. pkgconfig(libffi)
      47. pkgconfig(libjpeg)
      48. pkgconfig(libnotify)
      49. pkgconfig(libproxy-1.0)
      50. pkgconfig(libpulse)
      51. pkgconfig(libstartup-notification-1.0)
      52. pkgconfig(nspr) >= 4.35
      53. pkgconfig(nss) >= 3.86
      54. pkgconfig(opus)
      55. pkgconfig(pixman-1)
      56. pkgconfig(vpx)
      57. pkgconfig(x11)
      58. pkgconfig(xcomposite)
      59. pkgconfig(xcursor)
      60. pkgconfig(xdamage)
      61. pkgconfig(xext)
      62. pkgconfig(xft)
      63. pkgconfig(xi)
      64. pkgconfig(xkbcommon)
      65. pkgconfig(xrandr)
      66. pkgconfig(xscrnsaver)
      67. pkgconfig(xt)
      68. pkgconfig(xtst)
      69. pkgconfig(zlib)
      70. python3(click)
      71. python3(curses)
      72. python3(hamcrest)
      73. libX11-devel
      74. libXScrnSaver-devel
      75. libXcomposite-devel
      76. libXcursor-devel
      77. libXdamage-devel
      78. python3(imp)
      79. libXext-devel
      80. libXft-devel
      81. libXi-devel
      82. libXt-devel
      83. libalsa-devel
      84. libaom-devel
      85. python3(pip)
      86. rust >= 1.65.0
      87. rust-cargo >= 1.65.0
      88. python3(setuptools)
      89. unzip
      90. libcairo-devel
      91. python3(sqlite3)
      92. xorg-cf-files
      93. libcurl-devel
      94. yasm
      95. libdav1d-devel
      96. zip
      97. zlib-devel
      98. libdbus-devel
      99. libdbus-glib-devel
      100. libevent-devel
      101. libdrm-devel
      102. libgio-devel
      103. libjpeg-devel
      104. python3-base
      105. libffi-devel
      106. libnotify-devel
      107. libfreetype-devel
      108. libnss-devel-static
      109. libgtk+2-devel
      110. libgtk+3-devel
      111. libshell
      112. libproxy-devel
      113. libstartup-notification-devel
      114. libstdc++-devel
      115. libpulseaudio-devel
      116. libhunspell-devel
      117. libopus-devel
      118. libpixman-devel

    Last changed


    May 19, 2024 Pavel Vasenkov 115.11.0-alt1
    - New ESR version.
    - Security fixes
      + CVE-2024-4367 Arbitrary JavaScript execution in PDF.js
      + CVE-2024-4767 IndexedDB files retained in private browsing mode
      + CVE-2024-4768 Potential permissions request bypass via clickjacking
      + CVE-2024-4769 Cross-origin responses could be distinguished between script and non-script content-types
      + CVE-2024-4770 Use-after-free could occur when printing to PDF
      + CVE-2024-4777 Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11
    April 16, 2024 Pavel Vasenkov 115.10.0-alt1
    - New ESR version.
    - Security fixes
      + CVE-2024-3852 GetBoundName in the JIT returned the wrong object
      + CVE-2024-3854 Out-of-bounds-read after mis-optimized switch statement
      + CVE-2024-3857 Incorrect JITting of arguments led to use-after-free during garbage collection
      + CVE-2024-2609 Permission prompt input delay could expire when not in focus
      + CVE-2024-3859 Integer-overflow led to out-of-bounds-read in the OpenType sanitizer
      + CVE-2024-3861 Potential use-after-free due to AlignedBuffer self-move
      + CVE-2024-3863 Download Protections were bypassed by .xrm-ms files on Windows
      + CVE-2024-3302 Denial of Service using HTTP/2 CONTINUATION frames
      + CVE-2024-3864 Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10
    April 3, 2024 Pavel Vasenkov 115.9.1-alt1
    - New ESR version.
    - Security fixes
      + CVE-2024-0743 Crash in NSS TLS method
      + CVE-2024-2605 Windows Error Reporter could be used as a Sandbox escape vector
      + CVE-2024-2607 JIT code failed to save return registers on Armv7-A
      + CVE-2024-2608 Integer overflow could have led to out of bounds write
      + CVE-2024-2616 Improve handling of out-of-memory conditions in ICU
      + CVE-2023-5388 NSS susceptible to timing attack against RSA decryption
      + CVE-2024-2610 Improper handling of html and body tags enabled CSP nonce leakage
      + CVE-2024-2611 Clickjacking vulnerability could have led to a user accidentally granting permissions
      + CVE-2024-2612 Self referencing object could have potentially led to a use-after-free
      + CVE-2024-2614 Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9
      + CVE-2024-29944 Privileged JavaScript Execution via Event Handlers