1 UPDATED package

firefox-esr - The Mozilla Firefox project is a redesign of Mozilla's browser    
[640M]
* Fri Jun 26 2026 Pavel Vasenkov <pav@altlinux> 140.12.0-alt0.p10.1
- Backport new version.
* Thu Jun 18 2026 Pavel Vasenkov <pav@altlinux> 140.12.0-alt1
- New ESR version.
- Security fixes:
  + CVE-2026-12289 Privilege escalation in the Graphics: WebRender component
  + CVE-2026-12290 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12291 Use-after-free in the Networking: HTTP component
  + CVE-2026-12292 Incorrect boundary conditions in the Web Audio component
  + CVE-2026-12294 Sandbox escape in the DOM: Workers component
  + CVE-2026-12295 Sandbox escape in the DOM: Navigation component
  + CVE-2026-12298 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12296 Sandbox escape in the Security: Process Sandboxing component
  + CVE-2026-12297 Sandbox escape due to incorrect boundary conditions in the 
Networking component
  + CVE-2026-12299 JIT miscompilation in the DOM: Core & HTML component
  + CVE-2026-12329 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12302 Mitigation bypass in the DOM: Security component
  + CVE-2026-12304 Same-origin policy bypass in the Networking: Cookies 
component
  + CVE-2026-12305 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12306 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12307 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12308 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12309 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12310 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12311 Information disclosure, sandbox escape in the Security: 
Process Sandboxing component
  + CVE-2026-12312 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12313 Information disclosure, sandbox escape in the Security: 
Process Sandboxing component
  + CVE-2026-12314 Memory safety bug fixed in Firefox ESR 140.12
  + CVE-2026-12315 Mitigation bypass in the DOM: Security component
  + CVE-2026-12330 Incorrect boundary conditions in the Internationalization 
component
  + CVE-2026-12324 Incorrect boundary conditions in the Graphics: CanvasWebGL 
component
  + CVE-2026-12325 Denial-of-service in the Graphics: ImageLib component
  + CVE-2026-12327 Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird 
ESR 140.12, Firefox 152 and Thunderbird 152
  + CVE-2026-12328 Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 
140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
* Tue Jun 16 2026 Pavel Vasenkov <pav@altlinux> 140.11.0-alt2
- Fix FTBFS with glslopt once flag libc
* Fri Jun 05 2026 Pavel Vasenkov <pav@altlinux> 140.11.0-alt1
- New ESR version.
- Security fixes:
  + CVE-2026-8946 Incorrect boundary conditions in the Audio/Video: Web Codecs 
component
  + CVE-2026-8388 Incorrect boundary conditions in the JavaScript Engine: JIT 
component
  + CVE-2026-8947 Use-after-free in the DOM: Bindings (WebIDL) component
  + CVE-2026-8391 Other issue in the JavaScript Engine component
  + CVE-2026-8401 Sandbox escape in the Profile Backup component
  + CVE-2026-8949 Integer overflow in the Widget: Win32 component
  + CVE-2026-8950 Same-origin policy bypass in the Networking: HTTP component
  + CVE-2026-8953 Sandbox escape due to use-after-free in the Disability Access 
APIs component
  + CVE-2026-8954 Incorrect boundary conditions, integer overflow in the 
Audio/Video component
  + CVE-2026-8955 Privilege escalation in the DOM: Workers component
  + CVE-2026-8956 Integer overflow in the Networking: JAR component
  + CVE-2026-8957 Privilege escalation in the Enterprise Policies component
  + CVE-2026-8958 Information disclosure, sandbox escape in the Security: 
Process Sandboxing component
  + CVE-2026-8959 Sandbox escape due to incorrect boundary conditions in the 
Widget: Win32 component
  + CVE-2026-8961 Spoofing issue in the Form Autofill component
  + CVE-2026-8962 Mitigation bypass in the DOM: Security component
  + CVE-2026-8968 Denial-of-service due to invalid pointer in the Audio/Video: 
Web Codecs component
  + CVE-2026-8970 Privilege escalation in the Security component
  + CVE-2026-8974 Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151
  + CVE-2026-8975 Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 
140.11 and Firefox 151
* Thu Jun 04 2026 Pavel Vasenkov <pav@altlinux> 140.10.2-alt1
- New ESR version.
- Security fixes:
  + CVE-2026-8090 Use-after-free in the DOM: Networking component
  + CVE-2026-8094 Other issue in the WebRTC component
  + CVE-2026-8092 Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 
140.10.2 and Firefox 150.0.2
* Sun May 24 2026 Pavel Vasenkov <pav@altlinux> 140.10.1-alt1
- New ESR version.
- Security fixes:
  + CVE-2026-7320 Information disclosure due to incorrect boundary conditions 
in the Audio/Video component
  + CVE-2026-7321 Sandbox escape due to incorrect boundary conditions in the 
WebRTC: Networking component
  + CVE-2026-8091 Incorrect boundary conditions in the Audio/Video: Playback 
component
  + CVE-2026-7322 Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 
140.10.1 and Firefox 150.0.1
  + CVE-2026-7323 Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 
150.0.1
* Sun May 24 2026 Pavel Vasenkov <pav@altlinux> 140.10.0-alt1
- New ESR version.
- Security fixes:
  + CVE-2026-6746 Use-after-free in the DOM: Core & HTML component
  + CVE-2026-6747 Use-after-free in the WebRTC component
  + CVE-2026-6748 Uninitialized memory in the Audio/Video: Web Codecs component
  + CVE-2026-6749 Information disclosure due to uninitialized memory in the 
Graphics: Canvas2D component
  + CVE-2026-6750 Privilege escalation in the Graphics: WebRender component
  + CVE-2026-6751 Uninitialized memory in the Audio/Video: Web Codecs component
  + CVE-2026-6752 Incorrect boundary conditions in the WebRTC component
  + CVE-2026-6753 Incorrect boundary conditions in the WebRTC component
  + CVE-2026-6754 Use-after-free in the JavaScript Engine component
  + CVE-2026-6757 Invalid pointer in the JavaScript: WebAssembly component
  + CVE-2026-6759 Use-after-free in the Widget: Cocoa component
  + CVE-2026-6761 Privilege escalation in the Networking component
  + CVE-2026-6762 Spoofing issue in the DOM: Core & HTML component
  + CVE-2026-6763 Mitigation bypass in the File Handling component
  + CVE-2026-6764 Incorrect boundary conditions in the DOM: Device Interfaces 
component
  + CVE-2026-6765 Information disclosure in the Form Autofill component
  + CVE-2026-6766 Incorrect boundary conditions in the Libraries component in 
NSS
  + CVE-2026-6767 Other issue in the Libraries component in NSS
  + CVE-2026-6769 Privilege escalation in the Debugger component
  + CVE-2026-6770 Other issue in the Storage: IndexedDB component
  + CVE-2026-6771 Mitigation bypass in the DOM: Security component
  + CVE-2026-6772 Incorrect boundary conditions in the Libraries component in 
NSS
  + CVE-2026-6776 Incorrect boundary conditions in the WebRTC: Networking 
component
  + CVE-2026-6785 Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 
140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
  + CVE-2026-6786 Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird 
ESR 140.10, Firefox 150 and Thunderbird 150
* Sat Apr 11 2026 Pavel Vasenkov <pav@altlinux> 140.9.1-alt1
- New ESR version.
- Security fixes:
  + CVE-2026-5732 Incorrect boundary conditions, integer overflow in the 
Graphics: Text component
  + CVE-2026-5731 Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 
140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird
  + CVE-2026-5734 Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird 
ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
* Fri Mar 27 2026 Pavel Vasenkov <pav@altlinux> 140.9.0-alt1
Note: changelog entry for 140.9.1-alt0.p10.1 not found.

Total 19171 source packages.
_______________________________________________
Sisyphus-cybertalk mailing list
[email protected]
https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk

Reply via email to