Overview

Request 605931 accepted

- update to Firefox 60.0esr
* Added a policy engine that allows customized Firefox deployments
in enterprise environments, using Windows Group Policy or a
cross-platform JSON file
* Applied Quantum CSS to render browser UI
* Added support for Web Authentication, allowing the use of USB
tokens for authentication to web sites
* Locale added: Occitan (oc)
MFSA 2018-11 (bsc#1092548)
* CVE-2018-5154 (bmo#1443092)
Use-after-free with SVG animations and clip paths
* CVE-2018-5155 (bmo#1448774)
Use-after-free with SVG animations and text paths
* CVE-2018-5157 (bmo#1449898)
Same-origin bypass of PDF Viewer to view protected PDF files
* CVE-2018-5158 (bmo#1452075)
Malicious PDF can inject JavaScript into PDF Viewer
* CVE-2018-5159 (bmo#1441941)
Integer overflow and out-of-bounds write in Skia
* CVE-2018-5160 (bmo#1436117)
Uninitialized memory use by WebRTC encoder
* CVE-2018-5152 (bmo#1415644, bmo#1427289)
WebExtensions information leak through webRequest API
* CVE-2018-5153 (bmo#1436809)
Out-of-bounds read in mixed content websocket messages
* CVE-2018-5163 (bmo#1426353)
Replacing cached data in JavaScript Start-up Bytecode Cache
* CVE-2018-5164 (bmo#1416045)
CSP not applied to all multipart content sent with
multipart/x-mixed-replace


Leap Reviewbot's avatar

openSUSE:Leap:15.0:SLE-workarounds/MozillaFirefox@3 -> openSUSE:Leap:15.0/MozillaFirefox

expected origin is 'SUSE:SLE-15:GA' (changed)

found package in openSUSE:Leap:15.0:SLE-workarounds

sr#605919 to openSUSE:Factory has different sources

Comment (at)leaper override accept to force accept.

the submitted sources are NOT in Factory


Ludwig Nussel's avatar
author source maintainer target maintainer

@leaper override accept


Leap Reviewbot's avatar

openSUSE:Leap:15.0:SLE-workarounds/MozillaFirefox@7abefe4164a367b4d6dcc3e76637e198 -> openSUSE:Leap:15.0/MozillaFirefox

expected origin is 'SUSE:SLE-15:GA' (changed)

found package in openSUSE:Leap:15.0:SLE-workarounds

sr#605347 waiting for review by legal-auto

submission is waiting for a Factory request to complete

Request History
Ludwig Nussel's avatar

lnussel_factory created request

- update to Firefox 60.0esr
* Added a policy engine that allows customized Firefox deployments
in enterprise environments, using Windows Group Policy or a
cross-platform JSON file
* Applied Quantum CSS to render browser UI
* Added support for Web Authentication, allowing the use of USB
tokens for authentication to web sites
* Locale added: Occitan (oc)
MFSA 2018-11 (bsc#1092548)
* CVE-2018-5154 (bmo#1443092)
Use-after-free with SVG animations and clip paths
* CVE-2018-5155 (bmo#1448774)
Use-after-free with SVG animations and text paths
* CVE-2018-5157 (bmo#1449898)
Same-origin bypass of PDF Viewer to view protected PDF files
* CVE-2018-5158 (bmo#1452075)
Malicious PDF can inject JavaScript into PDF Viewer
* CVE-2018-5159 (bmo#1441941)
Integer overflow and out-of-bounds write in Skia
* CVE-2018-5160 (bmo#1436117)
Uninitialized memory use by WebRTC encoder
* CVE-2018-5152 (bmo#1415644, bmo#1427289)
WebExtensions information leak through webRequest API
* CVE-2018-5153 (bmo#1436809)
Out-of-bounds read in mixed content websocket messages
* CVE-2018-5163 (bmo#1426353)
Replacing cached data in JavaScript Start-up Bytecode Cache
* CVE-2018-5164 (bmo#1416045)
CSP not applied to all multipart content sent with
multipart/x-mixed-replace


Ludwig Nussel's avatar

lnussel_factory added opensuse-review-team as a reviewer

please review


Ludwig Nussel's avatar

lnussel_factory added openSUSE:Leap:15.0:Staging:E as a reviewer

Being evaluated by staging project "openSUSE:Leap:15.0:Staging:E"


Ludwig Nussel's avatar

lnussel_factory accepted review

Picked openSUSE:Leap:15.0:Staging:E


Ludwig Nussel's avatar

lnussel_factory changed priority to moderate => important

raising priority for openSUSE:Leap:15.0:Staging:E


Factory Auto's avatar

factory-auto added repo-checker as a reviewer

Please review build success


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Leap Reviewbot's avatar

leaper added MozillaFirefox as a reviewer

Submission for MozillaFirefox by someone who is not maintainer in the devel project (mozilla:Factory). Please review


Leap Reviewbot's avatar

leaper added leap-reviewers as a reviewer


Ludwig Nussel's avatar

lnussel_factory added legal-auto as a reviewer

please review


Ludwig Nussel's avatar

lnussel_factory changed priority to important => important


Wolfgang Rosenauer's avatar

wrosenauer accepted review


Repo Checker's avatar

repo-checker accepted review

cycle and install check passed


mrdocs's avatar

mrdocs accepted review

OK


Ludwig Nussel's avatar

lnussel accepted review


Saul Goodman's avatar

licensedigger accepted review

ok


Leap Reviewbot's avatar

leaper accepted review

overridden by lnussel_factory


Ludwig Nussel's avatar

lnussel_factory accepted review

ready to accept


Ludwig Nussel's avatar

lnussel_factory approved review

ready to accept


Ludwig Nussel's avatar

lnussel_factory accepted request

Accept to openSUSE:Leap:15.0

openSUSE Build Service is sponsored by