* [cyber] I: t7/branch packages: +2 (15362)
@ 2017-05-20 4:48 QA Team Robot
0 siblings, 0 replies; only message in thread
From: QA Team Robot @ 2017-05-20 4:48 UTC (permalink / raw)
To: sisyphus-cybertalk
2 UPDATED packages
firefox-esr - The Mozilla Firefox project is a redesign of Mozilla's browser [179M]
* Fri May 19 2017 Andrey Cherepanov <cas@altlinux> 45.9.0-alt0.M70P.1
- Backport new ESR version to p7 branch
* Thu Apr 20 2017 Andrey Cherepanov <cas@altlinux> 45.9.0-alt1
- New ESR version
- Security fixes:
+ CVE-2017-5429: Memory safety bugs fixed in Firefox 53, Firefox ESR 45.9,
+ CVE-2017-5462: DRBG flaw in NSS
+ CVE-2017-5445: Uninitialized values used while parsing
+ CVE-2017-5469: Potential Buffer overflow in flex-generated code
+ CVE-2017-5437: Vulnerabilities in Libevent library
+ CVE-2017-5448: Out-of-bounds write in ClearKeyDecryptor
+ CVE-2017-5465: Out-of-bounds read in ConvolvePixel
+ CVE-2017-5447: Out-of-bounds read during glyph processing
+ CVE-2017-5446: Out-of-bounds read when HTTP/2 DATA frames are sent with
+ CVE-2017-5444: Buffer overflow while parsing application/http-index-format
+ CVE-2017-5443: Out-of-bounds write during BinHex decoding
+ CVE-2017-5464: Memory corruption with accessibility and DOM manipulation
+ CVE-2017-5442: Use-after-free during style changes
+ CVE-2017-5441: Use-after-free with selection during scroll events
+ CVE-2017-5440: Use-after-free in txExecutionState destructor during XSLT
+ CVE-2017-5439: Use-after-free in nsTArray Length() during XSLT processing
+ CVE-2017-5438: Use-after-free in nsAutoPtr during XSLT processing
+ CVE-2017-5460: Use-after-free in frame selection
+ CVE-2017-5432: Use-after-free in text input selection
+ CVE-2017-5434: Use-after-free during focus handling
+ CVE-2017-5459: Buffer overflow in WebGL
+ CVE-2017-5461: Out-of-bounds write in Base64 encoding in NSS
+ CVE-2017-5436: Out-of-bounds write with malicious font in Graphite 2
+ CVE-2017-5435: Use-after-free during transaction processing in the editor
+ CVE-2017-5433: Use-after-free in SMIL animation functions
* Wed Mar 08 2017 Andrey Cherepanov <cas@altlinux> 45.8.0-alt0.M70P.1
guile-evms - Guile bindings for EVMS
* Fri May 19 2017 Ivan Zakharyaschev <imz@altlinux> 0.4-alt15.M70T.2
- Build for t7. (Fix the crash of alterator-vm in installer.)
* Fri May 19 2017 Ivan Zakharyaschev <imz@altlinux> 0.4-alt15.M80P.2
- Fix the crash (of alterator-vm in installer) by reverting to using
our own copies of the typedefs of the standard types. (Importing all typedefs
was intended as a guarantee to avoid mismatches between guile-evms ABI
and libevms ABI, but something went wrong. Perhaps, wrong *.h were imported.)
* Tue Apr 18 2017 Ivan Zakharyaschev <imz@altlinux> 0.4-alt15.M70T.1
Total 15362 source packages.
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2017-05-20 4:48 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-05-20 4:48 [cyber] I: t7/branch packages: +2 (15362) QA Team Robot
ALT Linux Sisyphus cybertalk
This inbox may be cloned and mirrored by anyone:
git clone --mirror http://lore.altlinux.org/sisyphus-cybertalk/0 sisyphus-cybertalk/git/0.git
# If you have public-inbox 1.1+ installed, you may
# initialize and index your mirror using the following commands:
public-inbox-init -V2 sisyphus-cybertalk sisyphus-cybertalk/ http://lore.altlinux.org/sisyphus-cybertalk \
sisyphus-cybertalk@lists.altlinux.org sisyphus-cybertalk@lists.altlinux.ru sisyphus-cybertalk@lists.altlinux.com
public-inbox-index sisyphus-cybertalk
Example config snippet for mirrors.
Newsgroup available over NNTP:
nntp://lore.altlinux.org/org.altlinux.lists.sisyphus-cybertalk
AGPL code for this site: git clone https://public-inbox.org/public-inbox.git