Bug 49990 - Описание пакета устарело
Summary: Описание пакета устарело
Status: RESOLVED FIXED
Alias: None
Product: Sisyphus
Classification: Development
Component: firefox (show other bugs)
Version: unstable
Hardware: x86_64 Linux
: P5 enhancement
Assignee: Ajrat Makhmutov
QA Contact: qa-sisyphus
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-04-11 13:33 MSK by Sergey V Turchin
Modified: 2024-04-23 15:57 MSK (History)
6 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sergey V Turchin 2024-04-11 13:33:24 MSK
Обновить бы, а то уже давно не XUL.
Comment 1 Ajrat Makhmutov 2024-04-12 11:52:12 MSK
Ок, изменю его на: "Mozilla Firefox is a free open-source browser whose development is overseen by the Mozilla Corporation". Взял с https://developer.mozilla.org/en-US/docs/Glossary/Mozilla_Firefox.
Comment 2 Sergey V Turchin 2024-04-12 12:04:46 MSK
Предлагаю из Fedora, как более нейтральное:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
Comment 3 Ajrat Makhmutov 2024-04-12 12:16:54 MSK
Ок.
Comment 4 Repository Robot 2024-04-23 15:57:16 MSK
firefox-125.0.1-alt1 -> sisyphus:

 Wed Apr 17 2024 Ajrat Makhmutov <rauty@altlinux> 125.0.1-alt1
 - New version (125.0.1).
 - Update description (closes: 49990).
 - Enable VAAPI.
 - Security fixes:
   + CVE-2024-3852: GetBoundName in the JIT returned the wrong object
   + CVE-2024-3853: Use-after-free if garbage collection runs during realm initialization
   + CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement
   + CVE-2024-3855: Incorrect JIT optimization of MSubstr leads to out-of-bounds reads
   + CVE-2024-3856: Use-after-free in WASM garbage collection
   + CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection
   + CVE-2024-3858: Corrupt pointer dereference in js::CheckTracedThing<js::Shape>
   + CVE-2024-3859: Integer-overflow led to out-of-bounds-read in the OpenType sanitizer
   + CVE-2024-3860: Crash when tracing empty shape lists
   + CVE-2024-3861: Potential use-after-free due to AlignedBuffer self-move
   + CVE-2024-3862: Potential use of uninitialized memory in MarkStack assignment operator on self-assignment
   + CVE-2024-3863: Download Protections were bypassed by .xrm-ms files on Windows
   + CVE-2024-3302: Denial of Service using HTTP/2 CONTINUATION frames
   + CVE-2024-3864: Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10
   + CVE-2024-3865: Memory safety bugs fixed in Firefox 125