Пакет firefox: Информация

    Исходный пакет: firefox
    Версия: 68.0.1-alt0.M80P.1
    Собран:  15 октября 2019 г. 21:24 в задании #236175
    Категория: Сети/WWW
    Сообщить об ошибке в пакете
    Домашняя страница: http://www.mozilla.org/projects/firefox/

    Лицензия: MPL/GPL/LGPL
    О пакете: The Mozilla Firefox project is a redesign of Mozilla's browser
    Описание: 
    The Mozilla Firefox project is a redesign of Mozilla's browser component,
    written using the XUL user interface language and designed to be
    cross-platform.

    Список rpm-пакетов, предоставляемых данным srpm-пакетом:
    firefox (x86_64, i586)
    firefox-debuginfo (x86_64, i586)
    firefox-wayland (noarch)
    rpm-build-firefox (noarch)

    Сопровождающий: Alexey Gladkov


      1. /proc
      2. libhunspell-devel
      3. libX11-devel
      4. fontconfig-devel
      5. libXScrnSaver-devel
      6. libXcomposite-devel
      7. libXcursor-devel
      8. libpulseaudio-devel
      9. libXdamage-devel
      10. libXext-devel
      11. libjpeg-devel
      12. libXft-devel
      13. libXi-devel
      14. libXt-devel
      15. python3-base
      16. libvpx5-devel
      17. libcairo-devel
      18. libalsa-devel
      19. gcc
      20. gcc-c++
      21. libwireless-devel
      22. libcurl-devel
      23. libxkbcommon-devel
      24. libdbus-devel
      25. libdbus-glib-devel
      26. rust >= 1.35.0
      27. rust-cargo >= 1.35.0
      28. rustfmt
      29. alternatives
      30. libshell
      31. lld-devel
      32. libevent-devel
      33. llvm6.0-devel
      34. autoconf_2.13
      35. autoconf_2.13
      36. libffi-devel
      37. rpm-build-mozilla.org
      38. libfreetype-devel
      39. rpm-macros-alternatives
      40. mozilla-common-devel
      41. pkgconfig(nspr) >= 4.21
      42. libstartup-notification-devel
      43. pkgconfig(nss) >= 3.45.0
      44. libstdc++-devel
      45. browser-plugins-npapi-devel
      46. bzlib-devel
      47. nasm
      48. libnotify-devel
      49. unzip
      50. node
      51. libnss-devel-static
      52. chrpath
      53. clang6.0
      54. clang6.0-devel
      55. gst-plugins1.0-devel
      56. gstreamer1.0-devel
      57. libopus-devel
      58. python-module-distribute
      59. libGL-devel
      60. zip
      61. zlib-devel
      62. xorg-cf-files
      63. yasm
      64. python-module-pip
      65. libgio-devel
      66. libgtk+2-devel
      67. python-modules-compiler
      68. libgtk+3-devel
      69. libpixman-devel
      70. python-modules-json
      71. python-modules-logging
      72. python-modules-sqlite3
      73. libproxy-devel

    Последнее изменение


    9 сентября 2019 г. Andrey Cherepanov 68.0.1-alt0.M80P.1
    - Backport new version with security fixes to p8 branch.
    1 августа 2019 г. Alexey Gladkov 68.0.1-alt1
    - New release (68.0.1).
    11 июля 2019 г. Alexey Gladkov 68.0-alt1
    - New release (68.0).
    - Fixed:
      + CVE-2019-9811: Sandbox escape via installation of malicious language pack
      + CVE-2019-11711: Script injection within domain through inner window reuse
      + CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects
      + CVE-2019-11713: Use-after-free with HTTP/2 cached stream
      + CVE-2019-11714: NeckoChild can trigger crash when accessed off of main thread
      + CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
      + CVE-2019-11715: HTML parsing error can contribute to content XSS
      + CVE-2019-11716: globalThis not enumerable until accessed
      + CVE-2019-11717: Caret character improperly escaped in origins
      + CVE-2019-11718: Activity Stream writes unsanitized content to innerHTML
      + CVE-2019-11719: Out-of-bounds read when importing curve25519 private key
      + CVE-2019-11720: Character encoding XSS vulnerability
      + CVE-2019-11721: Domain spoofing through unicode latin 'kra' character
      + CVE-2019-11730: Same-origin policy treats all files in a directory as having the same-origin
      + CVE-2019-11723: Cookie leakage during add-on fetching across private browsing boundaries
      + CVE-2019-11724: Retired site input.mozilla.org has remote troubleshooting permissions
      + CVE-2019-11725: Websocket resources bypass safebrowsing protections
      + CVE-2019-11727: PKCS#1 v1.5 signatures can be used for TLS 1.3
      + CVE-2019-11728: Port scanning through Alt-Svc header
      + CVE-2019-11710: Memory safety bugs fixed in Firefox 68
      + CVE-2019-11709: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8