Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (13m)  pkgsrc-2024Q1 (10d)  pkgsrc-2023Q4 (57d)  pkgsrc-2023Q2 (89d)  pkgsrc-2023Q3 (169d) 

2024-05-28 04:25:56 UTC Now

2023-04-05 14:22:36 UTC MAIN commitmail json YAML

firefox: Update to 111.0.1

* Enable eventfd(2) for NetBSD 10 or later.
* Fix LICENSE in official Firefox branding case.

Changelog:
111.0.1
Fixed

  * Fixed a crash on macOS while pinch-zooming under some circumstances (bug
    1658986).

  * Fixed a bug causing Firefox to freeze on startup for some Windows users (
    bug 1823159).

111.0
New

  * Windows native notifications are now enabled.

  * Firefox Relay users can now opt-in to create Relay email masks directly
    from the Firefox credential manager. You must be signed in with your
    Firefox Account.

  * We've added two new locales: Silhe Friulian (fur) and Sardinian (sc).

Fixed

  * Various security fixes.

Security fixes
#CVE-2023-28159: Fullscreen Notification could have been hidden by download
popups on Android
#CVE-2023-25748: Fullscreen Notification could have been hidden by window
prompts on Android
#CVE-2023-25749: Firefox for Android may have opened third-party apps without a
prompt
#CVE-2023-25750: Potential ServiceWorker cache leak during private browsing
mode
#CVE-2023-25751: Incorrect code generation during JIT compilation
#CVE-2023-28160: Redirect to Web Extension files may have leaked local path
#CVE-2023-28164: URL being dragged from a removed cross-origin iframe into the
same tab triggered navigation
#CVE-2023-28161: One-time permissions granted to a local file were extended to
other local files loaded in the same tab
#CVE-2023-28162: Invalid downcast in Worklets
#CVE-2023-25752: Potential out-of-bounds when accessing throttled streams
#CVE-2023-28163: Windows Save As dialog resolved environment variables
#CVE-2023-28176: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9
#CVE-2023-28177: Memory safety bugs fixed in Firefox 111

(ryoon)