From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Date: Wed, 10 May 2017 04:44:45 +0000 From: QA Team Robot To: sisyphus-cybertalk@lists.altlinux.org Message-ID: <20170510044445.GA24981@gyle.altlinux.org> Mail-Followup-To: sisyphus-cybertalk@lists.altlinux.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Subject: [cyber] I: p8/branch packages: -1 +7 (17655) X-BeenThere: sisyphus-cybertalk@lists.altlinux.org X-Mailman-Version: 2.1.12 Precedence: list Reply-To: devel@lists.altlinux.org List-Id: ALT Linux Sisyphus cybertalk List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 10 May 2017 04:44:45 -0000 Archived-At: List-Archive: 1 REMOVED package firefox-be 50.0-alt1 7 UPDATED packages GeoIP-ASNum - GeoIPASNum database file * Mon May 08 2017 Cronbuild Service 1:20170508-alt1 - repocop cronbuild 20170508. At your service. * Sat Apr 29 2017 Cronbuild Service 1:20170429-alt1 firefox - The Mozilla Firefox project is a redesign of Mozilla's browser [209M] * Tue May 09 2017 Andrey Cherepanov 53.0.2-alt0.M80P.1 - Backport new version to p8 branch * Sun May 07 2017 Alexey Gladkov 53.0.2-alt1 - New release (53.0.2). - Fixed: + CVE-2017-5031: Use after free in ANGLE * Mon May 01 2017 Alexey Gladkov 53.0-alt1 - New release (53.0). - Built with internal hunspell. - Fixed: + CVE-2017-5433: Use-after-free in SMIL animation functions + CVE-2017-5435: Use-after-free during transaction processing in the editor + CVE-2017-5436: Out-of-bounds write with malicious font in Graphite 2 + CVE-2017-5461: Out-of-bounds write in Base64 encoding in NSS + CVE-2017-5459: Buffer overflow in WebGL + CVE-2017-5466: Origin confusion when reloading isolated data:text/html URL + CVE-2017-5434: Use-after-free during focus handling + CVE-2017-5432: Use-after-free in text input selection + CVE-2017-5460: Use-after-free in frame selection + CVE-2017-5438: Use-after-free in nsAutoPtr during XSLT processing + CVE-2017-5439: Use-after-free in nsTArray Length() during XSLT processing + CVE-2017-5440: Use-after-free in txExecutionState destructor during XSLT processing + CVE-2017-5441: Use-after-free with selection during scroll events + CVE-2017-5442: Use-after-free during style changes + CVE-2017-5464: Memory corruption with accessibility and DOM manipulation + CVE-2017-5443: Out-of-bounds write during BinHex decoding + CVE-2017-5444: Buffer overflow while parsing application/http-index-format content + CVE-2017-5446: Out-of-bounds read when HTTP/2 DATA frames are sent with incorrect data + CVE-2017-5447: Out-of-bounds read during glyph processing + CVE-2017-5465: Out-of-bounds read in ConvolvePixel + CVE-2017-5448: Out-of-bounds write in ClearKeyDecryptor + CVE-2016-10196: Vulnerabilities in Libevent library + CVE-2017-5454: Sandbox escape allowing file system read access through file picker + CVE-2017-5455: Sandbox escape through internal feed reader APIs + CVE-2017-5456: Sandbox escape allowing local file system access + CVE-2017-5469: Potential Buffer overflow in flex-generated code + CVE-2017-5445: Uninitialized values used while parsing application/http-index-format content + CVE-2017-5449: Crash during bidirectional unicode manipulation with animation + CVE-2017-5450: Addressbar spoofing using javascript: URI on Firefox for Android + CVE-2017-5451: Addressbar spoofing with onblur event + CVE-2017-5462: DRBG flaw in NSS + CVE-2017-5463: Addressbar spoofing through reader view on Firefox for Android + CVE-2017-5467: Memory corruption when drawing Skia content + CVE-2017-5452: Addressbar spoofing during scrolling with editable content on Firefox for Android + CVE-2017-5453: HTML injection into RSS Reader feed preview page through TITLE element + CVE-2017-5458: Drag and drop of javascript: URLs can allow for self-XSS + CVE-2017-5468: Incorrect ownership model for Private Browsing information + CVE-2017-5430: Memory safety bugs fixed in Firefox 53 and Firefox ESR 52.1 + CVE-2017-5429: Memory safety bugs fixed in Firefox 53, Firefox ESR 45.9, and Firefox ESR 52.1 * Tue Mar 21 2017 Andrey Cherepanov 52.0-alt0.M80P.1 firefox-kk - Kazakh (KZ) Language Pack for Firefox * Mon May 08 2017 Alexey Gladkov 53.0.2-alt1 - New version (53.0.2). * Mon Mar 20 2017 Alexey Gladkov 52.0-alt1 firefox-ru - Russian (RU) Language Pack for Firefox * Mon May 08 2017 Alexey Gladkov 53.0.2-alt1 - New version (53.0.2). * Mon Mar 20 2017 Alexey Gladkov 52.0-alt1 firefox-uk - Ukrainian (UA) Language Pack for Firefox * Mon May 08 2017 Alexey Gladkov 53.0.2-alt1 - New version (53.0.2). * Mon Mar 20 2017 Alexey Gladkov 52.0-alt1 libwebkitgtk4 - Web browser engine [14M] * Tue May 09 2017 Yuri N. Sedunov 2.14.7-alt0.M80P.1 - 2.14.7 * Thu Apr 06 2017 Yuri N. Sedunov 2.14.6-alt0.M80P.1 synfigstudio - Synfig studio - animation program * Tue May 09 2017 Andrey Cherepanov 1.3.3-alt0.M80P.1 - Backport new version to p8 branch * Mon May 08 2017 Andrey Cherepanov 1.3.3-alt1 - New version * Thu Apr 13 2017 Andrey Cherepanov 1.3.2-alt0.M80P.1 Total 17655 source packages.