<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>23809</bug_id>
          
          <creation_ts>2010-07-25 01:18:01 +0400</creation_ts>
          <short_desc>Обновить firefox</short_desc>
          <delta_ts>2010-09-16 15:26:37 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>3</classification_id>
          <classification>Distributions</classification>
          <product>Branch p5</product>
          <component>cross-component</component>
          <version>unspecified</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>24053</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="AEN">aen</reporter>
          <assigned_to name="Nobody&apos;s working on this, feel free to take it">nobody</assigned_to>
          <cc>cas</cc>
    
    <cc>dkoryavov</cc>
    
    <cc>oddity</cc>
          
          <qa_contact name="QA p5">qa-p5</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>110786</commentid>
    <comment_count>0</comment_count>
    <who name="AEN">aen</who>
    <bug_when>2010-07-25 01:18:01 +0400</bug_when>
    <thetext>Собрать 3.5.11</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>111789</commentid>
    <comment_count>1</comment_count>
    <who name="Ilya Mashkin">oddity</who>
    <bug_when>2010-09-01 02:45:17 +0400</bug_when>
    <thetext>Текущая версия 3.5.9 содержит 20 уязвимостей, более десятка из них  - критические.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>111790</commentid>
    <comment_count>2</comment_count>
    <who name="Ilya Mashkin">oddity</who>
    <bug_when>2010-09-01 02:51:26 +0400</bug_when>
    <thetext>Кроме того, на сколько я понимаю, текущая версия 3.5.9 собрана неправильно, со старой версией xulrunner (1.9.1.8) и, соответственно все ещё содержит ошибки исправленные в 3.5.9 (+ ещё 5 критических уязвимостей).   Посему нужно не забыть собрать xulrunner 1.9.1.11</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>111818</commentid>
    <comment_count>3</comment_count>
    <who name="Andrey Cherepanov">cas</who>
    <bug_when>2010-09-01 16:31:04 +0400</bug_when>
    <thetext>Соберу 3.6.x</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>112027</commentid>
    <comment_count>4</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-09-09 11:02:33 +0400</bug_when>
    <thetext>firefox-3.6-3.6.9-alt0.20100725.M50P.1 -&gt; p5:

* Mon Sep 06 2010 Andrey Cherepanov &lt;cas@altlinux&gt; 3.6.9-alt0.20100725.M50P.1
- backport to p5 branch (new version with security fixes) (closes: #23809)

* Thu Jul 29 2010 Alexey Gladkov &lt;legion@altlinux&gt; 3.6.9-alt1.20100725
- New release (3.6.8).
- Fixed:
  + MFSA 2010-48 Dangling pointer crash regression from plugin parameter array fix
  + MFSA 2010-47 Cross-origin data leakage from script filename in error messages
  + MFSA 2010-46 Cross-domain data theft using CSS
  + MFSA 2010-45 Multiple location bar spoofing vulnerabilities
  + MFSA 2010-44 Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish
  + MFSA 2010-43 Same-origin bypass using canvas context
  + MFSA 2010-42 Cross-origin data disclosure via Web Workers and importScripts
  + MFSA 2010-41 Remote code execution using malformed PNG image
  + MFSA 2010-40 nsTreeSelection dangling pointer remote code execution vulnerability
  + MFSA 2010-39 nsCSSValue::Array index integer overflow
  + MFSA 2010-38 Arbitrary code execution using SJOW and fast native function
  + MFSA 2010-37 Plugin parameter EnsureCachedAttrParamArrays remote code execution vulnerability
  + MFSA 2010-36 Use-after-free error in NodeIterator
  + MFSA 2010-35 DOM attribute cloning remote code execution vulnerability
  + MFSA 2010-34 Miscellaneous memory safety hazards (rv:1.9.2.7/ 1.9.1.11)

* Sun Jun 27 2010 Alexey Gladkov &lt;legion@altlinux&gt; 3.6.6-alt1.20100626
- New release (3.6.6).
- Fixed:
  + MFSA 2010-33 User tracking across sites using Math.random()
  + MFSA 2010-32 Content-Disposition: attachment ignored if Content-Type: multipart also present
  + MFSA 2010-31 focus() behavior can be used to inject or steal keystrokes
  + MFSA 2010-30 Integer Overflow in XSLT Node Sorting
  + MFSA 2010-29 Heap buffer overflow in nsGenericDOMDataNode::SetTextInternal
  + MFSA 2010-28 Freed object reuse across plugin instances
  + MFSA 2010-26 Crashes with evidence of memory corruption (rv:1.9.2.4/ 1.9.1.10)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>112045</commentid>
    <comment_count>5</comment_count>
    <who name="Ilya Mashkin">oddity</who>
    <bug_when>2010-09-10 00:04:58 +0400</bug_when>
    <thetext>По иронии судьбы вышла уже 3.6.9 версия с новыми критическими исправлениями :)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>112060</commentid>
    <comment_count>6</comment_count>
    <who name="Денис Корявов">dkoryavov</who>
    <bug_when>2010-09-10 14:08:42 +0400</bug_when>
    <thetext>Так же, у 3.6 проблемы - после некоторого времени использования на p5, почему-то перестает реагировать главное меню (вернее реагирует но с задержкой 5-10 секунд и сам firefox ооочень тормозит). 
Иногда, проявляется сразу, иногда, через неделю использования.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>112217</commentid>
    <comment_count>7</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-09-16 15:26:37 +0400</bug_when>
    <thetext>firefox-3.6-3.6.9-alt0.20100725.M50P.1 -&gt; 5.1:

* Mon Sep 06 2010 Andrey Cherepanov &lt;cas@altlinux&gt; 3.6.9-alt0.20100725.M50P.1
- backport to p5 branch (new version with security fixes) (closes: #23809)

* Thu Jul 29 2010 Alexey Gladkov &lt;legion@altlinux&gt; 3.6.9-alt1.20100725
- New release (3.6.8).
- Fixed:
  + MFSA 2010-48 Dangling pointer crash regression from plugin parameter array fix
  + MFSA 2010-47 Cross-origin data leakage from script filename in error messages
  + MFSA 2010-46 Cross-domain data theft using CSS
  + MFSA 2010-45 Multiple location bar spoofing vulnerabilities
  + MFSA 2010-44 Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish
  + MFSA 2010-43 Same-origin bypass using canvas context
  + MFSA 2010-42 Cross-origin data disclosure via Web Workers and importScripts
  + MFSA 2010-41 Remote code execution using malformed PNG image
  + MFSA 2010-40 nsTreeSelection dangling pointer remote code execution vulnerability
  + MFSA 2010-39 nsCSSValue::Array index integer overflow
  + MFSA 2010-38 Arbitrary code execution using SJOW and fast native function
  + MFSA 2010-37 Plugin parameter EnsureCachedAttrParamArrays remote code execution vulnerability
  + MFSA 2010-36 Use-after-free error in NodeIterator
  + MFSA 2010-35 DOM attribute cloning remote code execution vulnerability
  + MFSA 2010-34 Miscellaneous memory safety hazards (rv:1.9.2.7/ 1.9.1.11)

* Sun Jun 27 2010 Alexey Gladkov &lt;legion@altlinux&gt; 3.6.6-alt1.20100626
- New release (3.6.6).
- Fixed:
  + MFSA 2010-33 User tracking across sites using Math.random()
  + MFSA 2010-32 Content-Disposition: attachment ignored if Content-Type: multipart also present
  + MFSA 2010-31 focus() behavior can be used to inject or steal keystrokes
  + MFSA 2010-30 Integer Overflow in XSLT Node Sorting
  + MFSA 2010-29 Heap buffer overflow in nsGenericDOMDataNode::SetTextInternal
  + MFSA 2010-28 Freed object reuse across plugin instances
  + MFSA 2010-26 Crashes with evidence of memory corruption (rv:1.9.2.4/ 1.9.1.10)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>