Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (43m)  pkgsrc-2024Q1 (3d)  pkgsrc-2023Q4 (77d)  pkgsrc-2023Q2 (110d) 

2024-06-17 13:17:21 UTC Now

2022-04-13 07:16:37 UTC pkgsrc-2022Q1 commitmail json YAML

Pullup ticket #6612 - requested by nia
www/firefox91: security fix
www/firefox91-l10n: dependent update

Revisions pulled up:
- www/firefox91-l10n/Makefile                                  1.10
- www/firefox91-l10n/distinfo                                  1.12
- www/firefox91/Makefile                                        1.16
- www/firefox91/distinfo                                        1.12

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Sun Apr 10 13:43:44 UTC 2022

  Modified Files:
  pkgsrc/www/firefox91: Makefile distinfo
  pkgsrc/www/firefox91-l10n: Makefile distinfo

  Log Message:
  firefox91: update to 91.8.0

  Security Vulnerabilities fixed in Firefox ESR 91.8

  #CVE-2022-1097: Use-after-free in NSSToken objects

  #CVE-2022-28281: Out of bounds write due to unexpected WebAuthN Extensions

  #CVE-2022-1196: Use-after-free after VR Process destruction

  #CVE-2022-28282: Use-after-free in DocumentL10n::TranslateDocument

  #CVE-2022-28285: Incorrect AliasSet used in JIT Codegen

  #CVE-2022-28286: iframe contents could be rendered outside the border

  #CVE-2022-24713: Denial of Service via complex regular expressions

  #CVE-2022-28289: Memory safety bugs fixed in Firefox 99 and Firefox ESR 91.8

(bsiegert)