Commit graph

11 commits

Author SHA1 Message Date
is
a6bd9ad4b3 Update to 10.0.12 - see Mozilla.ORG mfsa2013-01.html 2013-01-10 12:01:02 +00:00
is
fbcda6119d Fixed in Firefox ESR 10.0.11:
MFSA 2012-106 Use-after-free, buffer overflow, and memory corruption
	issues found using Address Sanitizer
MFSA 2012-105 Use-after-free and buffer overflow issues found using
	Address Sanitizer
MFSA 2012-104 CSS and HTML injection through Style Inspector
MFSA 2012-103 Frames can shadow top.location
MFSA 2012-101 Improper character decoding in HZ-GB-2312 charset
MFSA 2012-100 Improper security filtering for cross-origin wrappers
MFSA 2012-98 Firefox installer DLL hijacking
MFSA 2012-93 evalInSanbox location context incorrectly applied
MFSA 2012-92 Buffer overflow while rendering GIF images
MFSA 2012-91 Miscellaneous memory safety hazards (rv:17.0/ rv:10.0.11)
2012-11-21 13:02:17 +00:00
is
0f7cb52875 Update to 10.0.10. Fixes MFSA 2012-90 (Fixes for Location object issues) 2012-11-15 09:48:30 +00:00
ryoon
ddeaacb3ff Update to 10.0.9
Changelog:
Fixed in Firefox ESR 10.0.9
MFSA 2012-89 defaultValue security checks not applied

Fixed in Firefox ESR 10.0.8
MFSA 2012-87 Use-after-free in the IME State Manager
MFSA 2012-86 Heap memory corruption issues found using Address Sanitizer
MFSA 2012-85 Use-after-free, buffer overflow, and out of bounds read issues found using Address Sanitizer
MFSA 2012-84 Spoofing and script injection through location.hash
MFSA 2012-83 Chrome Object Wrapper (COW) does not disallow acces to privileged functions or properties
MFSA 2012-82 top object and location property accessible by plugins
MFSA 2012-81 GetProperty function can bypass security checks
MFSA 2012-79 DOS and crash with full screen and history navigation
MFSA 2012-77 Some DOMWindowUtils methods bypass security checks
MFSA 2012-74 Miscellaneous memory safety hazards (rv:16.0/ rv:10.0.8)
MFSA 2012-59 Location object can be shadowed using Object.defineProperty
2012-10-13 10:16:23 +00:00
ryoon
d7fc46e4f7 devel/xulrunner10 and www/firefox10: Update to 10.0.7
Changelog:
FIXED Security fixes can be found here
FIXED Stability fixes can be found here
FIXED Contenteditable breaks middle-click to open links (674770)
FIXED Allow specifying wildcard that matches all simple netbiosnames in network.automatic-ntlm-auth.trusted-uris (452781)

Fixed in Firefox ESR 10.0.7
MFSA 2012-72 Web console eval capable of executing chrome-privileged code
MFSA 2012-70 Location object security checks bypassed by chrome code
MFSA 2012-69 Incorrect site SSL certificate data display
MFSA 2012-67 Installer will launch incorrect executable following new installation
MFSA 2012-65 Out-of-bounds read in format-number in XSLT
MFSA 2012-63 SVG buffer overflow and use-after-free issues
MFSA 2012-62 WebGL use-after-free and memory corruption
MFSA 2012-61 Memory corruption with bitmap format images with negative height
MFSA 2012-58 Use-after-free issues found using Address Sanitizer
MFSA 2012-57 Miscellaneous memory safety hazards (rv:15.0/ rv:10.0.7)
2012-09-06 17:24:59 +00:00
ryoon
1c64fed30b Update to 10.0.6
* --tracejit option is virtually obsolete, remove jit PLIST.

Changelog: from http://www.mozilla.org/en-US/firefox/10.0.6/releasenotes/
    FIXED
    Security fixes can be found https://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html
    FIXED
    Multiple stability bugs
    FIXED
    Text editing inconsistencies
2012-07-22 00:03:10 +00:00
ryoon
4f96bc4a1d Update to 10.0.5
Changelog:
* Security fixes can be found
  https://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html
	MFSA 2012-40 Buffer overflow and use-after-free issues found using Address Sanitizer
	MFSA 2012-39 NSS parsing errors with zero length items
	MFSA 2012-38 Use-after-free while replacing/inserting a node in a document
	MFSA 2012-37 Information disclosure though Windows file shares and shortcut files
	MFSA 2012-36 Content Security Policy inline-script bypass
	MFSA 2012-34 Miscellaneous memory safety hazards
* 10.5 Firefox top crash with signature [@ GLEngine@0x620cf ] (734848)
2012-06-06 14:39:21 +00:00
ryoon
8a1ac76085 Add MASTER_SITE_MOZILLA_ESR, for Extended Support Release version of
mozilla.org products (firefox and thunderbird).
Suggested by obache on pkgsrc-changes@.
2012-05-04 00:08:07 +00:00
ryoon
09db9bc659 Update to 10.0.4
Patches from Bernd Ernesti on pkgsrc-users.

Changelog:
The following problems are fixed.
* Security fixes
* extensions.checkCompatibility.* prefs didn't work as expected
  in ESR releases (734848)
* Firefox ESR 10.0.3 opened "Whats New" page after update (737535)
2012-04-29 16:30:08 +00:00
ryoon
6833a18c4f Add MASTER_SITE_MOZILLA_ALL to MASTER_SITES because ESR version is hosted
at ftp.mozilla.org (only?).
2012-03-19 20:32:18 +00:00
ryoon
7c73d57863 Import xulrunner-10.0.3 as devel/xulrunner
* Successor of devel/xulrunner, xulrunner-10.0.2.
* This is ESR (Extended Support Release) version.
* Fix security bugs
2012-03-15 08:58:26 +00:00