Package firefox-esr: Information

Source package: firefox-esr
Version: 115.3.1-alt1
Latest version according to Repology
Build time:  Sep 30, 2023, 08:09 AM in the task #330520
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser (ESR version)
Description: 
The Mozilla Firefox project is a redesign of Mozilla's browser component,
written using the XUL user interface language and designed to be
cross-platform.

List of rpms provided by this srpm:
firefox-esr (x86_64, i586, armh, aarch64)
firefox-esr-config-privacy (x86_64, i586, armh, aarch64)
firefox-esr-debuginfo (x86_64, i586, armh, aarch64)
firefox-esr-wayland (x86_64, i586, armh, aarch64)

Maintainer: Andrey Cherepanov



    1. libpixman-devel
    2. python3(pip)
    3. python3-base
    4. browser-plugins-npapi-devel
    5. /dev/shm
    6. bzlib-devel
    7. python3(click)
    8. libcairo-devel
    9. chrpath
    10. libproxy-devel
    11. clang15.0
    12. libpulseaudio-devel
    13. python3(curses)
    14. /proc
    15. clang15.0-devel
    16. libcurl-devel
    17. python3(setuptools)
    18. glibc-kernheaders-generic
    19. python3(hamcrest)
    20. libdav1d-devel
    21. fontconfig-devel
    22. libshell
    23. libdbus-devel
    24. libdbus-glib-devel
    25. libdrm-devel
    26. python3(sqlite3)
    27. libevent-devel
    28. libstartup-notification-devel
    29. libstdc++-devel
    30. rpm-build-mozilla.org
    31. libffi-devel
    32. gst-plugins1.0-devel
    33. alternatives
    34. gstreamer1.0-devel
    35. rpm-macros-alternatives
    36. libfreetype-devel
    37. autoconf_2.13
    38. autoconf_2.13
    39. libX11-devel
    40. libXScrnSaver-devel
    41. libXcomposite-devel
    42. libXcursor-devel
    43. libXdamage-devel
    44. libXext-devel
    45. libXft-devel
    46. libXi-devel
    47. libXt-devel
    48. libgio-devel
    49. libalsa-devel
    50. libaom-devel
    51. pkgconfig(alsa)
    52. pkgconfig(aom)
    53. pkgconfig(bzip2)
    54. pkgconfig(cairo)
    55. pkgconfig(dav1d)
    56. pkgconfig(dbus-1)
    57. pkgconfig(dbus-glib-1)
    58. pkgconfig(dri)
    59. pkgconfig(fontconfig)
    60. pkgconfig(freetype2)
    61. pkgconfig(gio-2.0)
    62. pkgconfig(graphite2)
    63. pkgconfig(gtk+-2.0)
    64. pkgconfig(gtk+-3.0)
    65. pkgconfig(harfbuzz)
    66. pkgconfig(hunspell)
    67. pkgconfig(icu-i18n)
    68. pkgconfig(libcurl)
    69. pkgconfig(libdrm)
    70. pkgconfig(libevent)
    71. pkgconfig(libffi)
    72. pkgconfig(libjpeg)
    73. pkgconfig(libnotify)
    74. pkgconfig(libproxy-1.0)
    75. pkgconfig(libpulse)
    76. pkgconfig(libstartup-notification-1.0)
    77. pkgconfig(nspr) >= 4.35
    78. pkgconfig(nss) >= 3.86
    79. pkgconfig(opus)
    80. libgtk+2-devel
    81. pkgconfig(pixman-1)
    82. pkgconfig(vpx)
    83. pkgconfig(x11)
    84. pkgconfig(xcomposite)
    85. pkgconfig(xcursor)
    86. pkgconfig(xdamage)
    87. pkgconfig(xext)
    88. pkgconfig(xft)
    89. libgtk+3-devel
    90. pkgconfig(xi)
    91. pkgconfig(xkbcommon)
    92. pkgconfig(xrandr)
    93. pkgconfig(xscrnsaver)
    94. pkgconfig(xt)
    95. pkgconfig(xtst)
    96. pkgconfig(zlib)
    97. libhunspell-devel
    98. libvpx-devel
    99. libjpeg-devel
    100. libwireless-devel
    101. rust >= 1.65.0
    102. rust-cargo >= 1.65.0
    103. libxkbcommon-devel
    104. unzip
    105. xorg-cf-files
    106. yasm
    107. zip
    108. zlib-devel
    109. libGL-devel
    110. libnotify-devel
    111. libnss-devel-static
    112. lld15.0-devel
    113. llvm15.0-devel
    114. nasm
    115. node
    116. mozilla-common-devel
    117. libopus-devel

Last changed


Sept. 29, 2023 Pavel Vasenkov 115.3.1-alt1
- New ESR version.
- Security fixes
  + CVE-2023-5168 Out-of-bounds write in FilterNodeD2D1
  + CVE-2023-5169 Out-of-bounds write in PathOps
  + CVE-2023-5171 Use-after-free in Ion Compiler
  + CVE-2023-5174 Double-free in process spawning on Windows
  + CVE-2023-5176 Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3
  + CVE-2023-5217 Heap buffer overflow in libvpx
Sept. 20, 2023 Pavel Vasenkov 115.2.1-alt2
- Restored build for 32bit archs
Sept. 8, 2023 Pavel Vasenkov 115.2.1-alt1
- New ESR version.
- Security fixes
  + CVE-2023-3600 Use-after-free in workers
  + CVE-2023-4045 Offscreen Canvas could have bypassed cross-origin restrictions
  + CVE-2023-4046 Incorrect value used during WASM compilation
  + CVE-2023-4047 Potential permissions request bypass via clickjacking
  + CVE-2023-4048 Crash in DOMParser due to out-of-memory conditions
  + CVE-2023-4049 Fix potential race conditions when releasing platform objects
  + CVE-2023-4050 Stack buffer overflow in StorageManager
  + CVE-2023-4052 File deletion and privilege escalation through Firefox uninstaller
  + CVE-2023-4054 Lack of warning when opening appref-ms files
  + CVE-2023-4055 Cookie jar overflow caused unexpected cookie jar state
  + CVE-2023-4056 Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14
  + CVE-2023-4057 Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1
  + CVE-2023-4573 Memory corruption in IPC CanvasTranslator
  + CVE-2023-4574 Memory corruption in IPC ColorPickerShownCallback
  + CVE-2023-4575 Memory corruption in IPC FilePickerShownCallback
  + CVE-2023-4576 Integer Overflow in RecordedSourceSurfaceCreation
  + CVE-2023-4577 Memory corruption in JIT UpdateRegExpStatics
  + CVE-2023-4051 Full screen notification obscured by file open dialog
  + CVE-2023-4578 Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception
  + CVE-2023-4053 Full screen notification obscured by external program
  + CVE-2023-4580 Push notifications saved to disk unencrypted
  + CVE-2023-4581 XLL file extensions were downloadable without warnings
  + CVE-2023-4582 Buffer Overflow in WebGL glGetProgramiv
  + CVE-2023-4583 Browsing Context potentially not cleared when closing Private Window
  + CVE-2023-4584 Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2
  + CVE-2023-4585 Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2
  + CVE-2023-4863 Heap buffer overflow in libwebp