Commit graph

34 commits

Author SHA1 Message Date
ryoon
36ed025474 Recursive revbump from textproc/icu 58.1 2016-12-04 05:17:03 +00:00
joerg
1ce15f0294 Create a maintainable form of the patch. 2016-11-20 21:10:41 +00:00
ryoon
82f67120a8 Recursive revbump from multimedia/libvpx uppdate 2016-08-17 00:06:39 +00:00
ryoon
e37b97fe3c Recursive revbump from audio/pulseaudio 2016-08-04 17:03:30 +00:00
adam
77b8ed74db Revbump after graphics/gd update 2016-08-03 10:22:08 +00:00
wiz
ad0031c15e Remove python33: adapt all packages that refer to it. 2016-07-09 13:03:30 +00:00
wiz
73716d23de Bump PKGREVISION for perl-5.24.0 for everything mentioning perl. 2016-07-09 06:38:30 +00:00
ryoon
b8130d2097 Update to 38.8.0
Changelog:
Fixed in Firefox ESR 38.8
    2016-47 Write to invalid HashMap entry through JavaScript.watch()
    2016-44 Buffer overflow in libstagefright with CENC offsets
    2016-39 Miscellaneous memory safety hazards (rv:46.0 / rv:45.1 / rv:38.8)
    2016-36 Use-after-free during processing of DER encoded keys in NSS
    2016-29 Same-origin policy violation using performance.getEntries and history navigation with session restore
    2016-15 Use-after-free in NSS during SSL connections in low memory
    2016-07 Errors in mp_div and mp_exptmod cryptographic functions in NSS
2016-04-27 21:21:18 +00:00
ryoon
ac20a93574 Recursive revbump from textproc/icu 57.1 2016-04-11 19:01:33 +00:00
ryoon
5a236eb581 Update to 38.7.1
Changelog:
Fixed
    Loading from history can show the wrong url in the location bar (Bug 1256194)

Changed
    Disabled Graphite font shaping library
2016-03-19 23:01:35 +00:00
ryoon
b729430cbb Update to 38.7.0
Changelog:
Fixed in Firefox ESR 38.7
    2016-37 Font vulnerabilities in the Graphite 2 library
    2016-35 Buffer overflow during ASN.1 decoding in NSS
    2016-34 Out-of-bounds read in HTML parser following a failed allocation
    2016-31 Memory corruption with malicious NPAPI plugin
    2016-28 Addressbar spoofing though history navigation and Location protocol property
    2016-27 Use-after-free during XML transformations
    2016-25 Use-after-free when using multiple WebRTC data channels
    2016-24 Use-after-free in SetBody
    2016-23 Use-after-free in HTML5 string parser
    2016-21 Displayed page address can be overridden
    2016-20 Memory leak in libstagefright when deleting an array during MP4 processing
    2016-17 Local file overwriting and potential privilege escalation through CSP reports
    2016-16 Miscellaneous memory safety hazards (rv:45.0 / rv:38.7)
    2015-136 Same-origin policy violation using performance.getEntries and history navigation
    2015-81 Use-after-free in MediaStream playback
2016-03-12 03:47:20 +00:00
jperkin
17661ff9a5 Bump PKGREVISION for security/openssl ABI bump. 2016-03-05 11:27:40 +00:00
jperkin
02201cb05b Use OPSYSVARS. 2016-02-26 10:57:45 +00:00
ryoon
a2fafac61c Update 38.6.1
Changelog:
Fixed in Firefox ESR 38.6.1
    2016-14 Vulnerabilities in Graphite 2
2016-02-19 14:42:33 +00:00
ryoon
3bbae83624 Add workaround for build failure with binutils 2.26 ld from NetBSD current
Bump PKGREVISION.
2016-02-09 13:26:12 +00:00
ryoon
bc71fde725 Update to 38.6.0
Changelog:
Fixed in Firefox ESR 38.6
    2016-03 Buffer overflow in WebGL after out of memory allocation
    2016-01 Miscellaneous memory safety hazards (rv:44.0 / rv:38.6)
    2015-150 MD5 signatures accepted within TLS 1.2 ServerKeyExchange in server signature
2016-02-02 05:39:13 +00:00
joerg
f4822e6d67 Don't request static graphite, it breaks the build against newer
external graphite. Add all the graphite headers to the magic wrapper
list to avoid future fun. Remove manual unwind.h header where it still
exists.
2016-01-31 23:43:48 +00:00
ryoon
11f9554d51 Fix build with recent include/g++/complex on NetBSD current 2016-01-20 22:14:13 +00:00
ryoon
b1025e1035 Update to 38.5.0
Changelog:
    Fixed Various security fixes
    Fixed Improved stability with Java (1221448)

Fixed in Firefox ESR 38.5
    2015-149 Cross-site reading attack through data and view-source URIs
    2015-147 Integer underflow and buffer overflow processing MP4 metadata in libstagefright
    2015-146 Integer overflow in MP4 playback in 64-bit versions
    2015-145 Underflow through code inspection
    2015-139 Integer overflow allocating extremely large textures
    2015-138 Use-after-free in WebRTC when datachannel is used after being destroyed
    2015-134 Miscellaneous memory safety hazards (rv:43.0 / rv:38.5)
2015-12-16 23:51:34 +00:00
adam
7f3b4730ad Extend PYTHON_VERSIONS_INCOMPATIBLE to 35 2015-12-05 21:25:27 +00:00
jperkin
8530ce776d Remove mk/find-prefix.mk usage from the www category.
The find-prefix infrastructure was required in a pkgviews world where
packages installed from pkgsrc could have different installation
prefixes, and this was a way for a dependency prefix to be determined.

Now that pkgviews has been removed there is no longer any need for the
overhead of this infrastructure.  Instead we use BUILDLINK_PREFIX.pkg
for dependencies pulled in via buildlink, or LOCALBASE/PREFIX where the
dependency is coming from pkgsrc.

Provides a reasonable performance win due to the reduction of `pkg_info
-qp` calls, some of which were redundant anyway as they were duplicating
the same information provided by BUILDLINK_PREFIX.pkg.
2015-11-25 12:54:07 +00:00
joerg
e67965bc86 Avoid ambigious class references. 2015-11-20 14:48:20 +00:00
ryoon
b33059afe1 Recursive revbump from multimedia/libvpx 2015-11-18 14:19:46 +00:00
ryoon
5760c8cfbd Update to 38.4.0
Changelog:
Fixed in Firefox ESR 38.4

    2015-133 NSS and NSPR memory corruption issues
    2015-132 Mixed content WebSocket policy bypass through workers
    2015-131 Vulnerabilities found through code inspection
    2015-130 JavaScript garbage collection crash with Java applet
    2015-128 Memory corruption in libjar through zip files
    2015-127 CORS preflight is bypassed when non-standard Content-Type headers are received
    2015-123 Buffer overflow during image interactions in canvas
    2015-122 Trailing whitespace in IP address hostnames can bypass same-origin policy
    2015-116 Miscellaneous memory safety hazards (rv:42.0 / rv:38.4)
2015-11-03 23:39:08 +00:00
szptvlfn
591aafc814 remove redundant '--disable-libnotify' 2015-10-17 00:31:41 +00:00
ryoon
b141232e29 Recursive revbump from textproc/icu 2015-10-10 01:57:50 +00:00
tnn
fbacae5e7b Remove old and probably stale Gecko Media Plugin patches (from FreeBSD?).
It might still be possible that pkgsrc needs adjustments for gmp loading
if/when we adopt some gmp packages, but until then they serve no purpose
and in fact appear to be harmful. Fixes Firefox startup error message:

addons.manager  ERROR   Exception calling provider GMPProvider.startup
2015-09-27 23:46:31 +00:00
ryoon
e43b4513de Update to 38.3.0
Changelog:
Fixed in Firefox ESR 38.3

    2015-113 Memory safety errors in libGLES in the ANGLE graphics library
    2015-112 Vulnerabilities found through code inspection
    2015-111 Errors in the handling of CORS preflight request headers
    2015-110 Dragging and dropping images exposes final URL after redirects
    2015-106 Use-after-free while manipulating HTML media content
    2015-105 Buffer overflow while decoding WebM video
    2015-101 Buffer overflow in libvpx while parsing vp9 format video
    2015-100 Arbitrary file manipulation by local user through Mozilla updater
    2015-96 Miscellaneous memory safety hazards (rv:41.0 / rv:38.3)
2015-09-23 06:48:24 +00:00
markd
3d28b578a2 Fix PLIST.gnome entry 2015-08-30 04:22:39 +00:00
ryoon
a7a208d8b4 Update to 38.2.1
* Fix build with newer freetype.

Changelog:
Fixed in Firefox ESR 38.2.1

    2015-95 Add-on notification bypass through data URLs
    2015-94 Use-after-free when resizing canvas element during restyling
2015-08-29 12:48:25 +00:00
snj
85f155a8fb Add one more official-mozilla-branding case. 2015-08-21 21:58:51 +00:00
he
6f65360117 Update firefox38 to version 38.2.0esr.
Upstream changes, ref.
https://www.mozilla.org/en-US/firefox/38.2.0/releasenotes/

 * Firefox may crash during mp4 video playback
 * Significant memory leak with GreaseMonkey add-on
 * crash [@ RtlEnterCriticalSection | MessageLoop::PostTask_Helper]
   on browser shutdown
 * Browser UI becomes unresponsive state when using Unity Web Player Plugin
 * ESRs will not build on hppa platform
 * crash in mozilla::layers::SyncObjectD3D11::FinalizeFrame()

and a smattering of security fixes:
 * 2015-92 Use-after-free in XMLHttpRequest with shared workers
 * 2015-90 Vulnerabilities found through code inspection
 * 2015-89 Buffer overflows on Libvpx when decoding WebM video
 * 2015-88 Heap overflow in gdk-pixbuf when scaling bitmap images
 * 2015-87 Crash when using shared memory in JavaScript
 * 2015-85 Out-of-bounds write with Updater and malicious MAR file
 * 2015-84 Arbitrary file overwriting through Mozilla Maintenance Service
	with hard links
 * 2015-83 Overflow issues in libstagefright
 * 2015-82 Redefinition of non-configurable JavaScript object properties
 * 2015-80 Out-of-bounds read with malformed MP3 file
 * 2015-79 Miscellaneous memory safety hazards (rv:40.0 / rv:38.2)
2015-08-21 09:08:56 +00:00
he
6c8b57311a Upgrade from version 38.1.0 to 38.1.1.
Fixes Mozilla Foundation Security Advisory 2015-78:
Same origin violation and local file stealing via PDF reader

 * Fixes CVE-2015-4495 -  It's possible to read local files or
   perform privilege escalation by using a native setter, bug 1178058.
 * Remove PlayPreview registration from PDF viewer, bug 1179262.

ref. https://www.mozilla.org/en-US/security/advisories/mfsa2015-78/
2015-08-09 16:33:05 +00:00
ryoon
9cd6a39c3e Import firefox38-38.1.0 as www/firefox38.
Mozilla Firefox is a free, open-source and cross-platform web browser
for Windows, Linux, MacOS X and many other operating systems.

It is fast and easy to use, and offers many advantages over other web
browsers, such as tabbed browsing and the ability to block pop-up
windows.

Firefox also offers excellent bookmark and history management, and it
can be extended by developers using industry standards such as XML,
CSS, JavaScript, C++, etc. Many extensions are available.

This package tracks 38 ESR.
2015-07-09 14:13:51 +00:00