Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

MozillaFirefox-95.0.2-1.2 RPM for armv7hl

From OpenSuSE Ports Tumbleweed for armv7hl

Name: MozillaFirefox Distribution: openSUSE Tumbleweed
Version: 95.0.2 Vendor: openSUSE
Release: 1.2 Build date: Sat Jan 1 14:08:24 2022
Group: Productivity/Networking/Web/Browsers Build host: obs-arm-6
Size: 201663716 Source RPM: MozillaFirefox-95.0.2-1.2.src.rpm
Packager: http://bugs.opensuse.org
Url: http://www.mozilla.org/
Summary: Mozilla Firefox Web Browser
Mozilla Firefox is a standalone web browser, designed for standards
compliance and performance.  Its functionality can be enhanced via a
plethora of extensions.

Provides

Requires

License

MPL-2.0

Changelog

* Tue Dec 28 2021 Bjørn Lie <bjorn.lie@gmail.com>
  - Add upstream patches:
    * mozilla-bmo1745560.patch: Fix build against wayland 1.20.
    * mozilla-bmo1744896.patch: Create WaylandVsyncSource on window
      creation
* Mon Dec 20 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 95.0.2
    * Addresses frequent crashes experienced by users with C/E/Z-Series
      "Bobcat" CPUs running on Windows 7, 8, and 8.1.
  - updated constraints for ppc and x86-64
* Fri Dec 17 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 95.0.1 (bsc#1193845)
    * Fixed frequent
      MOZILLA_PKIX_ERROR_OCSP_RESPONSE_FOR_CERT_MISSING error
      messages when trying to connect to various microsoft.com
      domains (bmo#1745600)
    * Fix for a WebRender crash on some Linux/X11 systems (bmo#1741956)
    * Fix for a frequent Windows shutdown crash (bmo#1738984)
    * Fix websites contrast issues for some Linux users with
      Dark mode set at OS level (bmo#1740518)
* Sat Dec 04 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 95.0
    * You can now move the Picture-in-Picture toggle button to the
      opposite side of the video. Simply look for the new context menu
      option Move Picture-in-Picture Toggle to Left (Right) Side.
    * To better protect Firefox users against side-channel attacks such
      as Spectre, Site Isolation is now enabled for all Firefox 95 users.
    * https://www.mozilla.org/en-US/firefox/95.0/releasenotes
    MFSA 2021-52 (bsc#1193485)
    * CVE-2021-43536 (bmo#1730120)
      URL leakage when navigating while executing asynchronous
      function
    * CVE-2021-43537 (bmo#1738237)
      Heap buffer overflow when using structured clone
    * CVE-2021-43538 (bmo#1739091)
      Missing fullscreen and pointer lock notification when
      requesting both
    * CVE-2021-43539 (bmo#1739683)
      GC rooting failure when calling wasm instance methods
    * MOZ-2021-0010 (bmo#1735852)
      Use-after-free in fullscreen objects on MacOS
    * CVE-2021-43540 (bmo#1636629)
      WebExtensions could have installed persistent ServiceWorkers
    * CVE-2021-43541 (bmo#1696685)
      External protocol handler parameters were unescaped
    * CVE-2021-43542 (bmo#1723281)
      XMLHttpRequest error codes could have leaked the existence of
      an external protocol handler
    * CVE-2021-43543 (bmo#1738418)
      Bypass of CSP sandbox directive when embedding
    * CVE-2021-43544 (bmo#1739934)
      Receiving a malicious URL as text through a SEND intent could
      have led to XSS
    * CVE-2021-43545 (bmo#1720926)
      Denial of Service when using the Location API in a loop
    * CVE-2021-43546 (bmo#1737751)
      Cursor spoofing could overlay user interface when native
      cursor is zoomed
    * MOZ-2021-0009 (bmo#1393362, bmo#1736046, bmo#1736751,
      bmo#1737009, bmo#1739372, bmo#1739421)
      Memory safety bugs fixed in Firefox 95 and Firefox ESR 91.4
  - requires
    NSS >= 3.72
* Thu Dec 02 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - remove x-scheme-handler/ftp from firefox.desktop boo#1193321
* Thu Nov 25 2021 Bjørn Lie <bjorn.lie@gmail.com>
  - Drop unused libidl-devel BuildRequires.
* Tue Nov 23 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 94.0.2:
    * Update preference design for Firefox Suggest for improved clarity
    * Resolved general instability/crashes on Linux caused by a file
      descriptor leak when backgrounding tabs using WebGL
      (bmo#1741997)
* Fri Nov 05 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 94.0.1:
    * fixes for other platforms
* Sat Oct 30 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 94.0
    * https://www.mozilla.org/en-US/firefox/94.0/releasenotes
    MFSA 2021-48 (bsc#1192250)
    * CVE-2021-38503 (bmo#1729517)
      iframe sandbox rules did not apply to XSLT stylesheets
    * CVE-2021-38504 (bmo#1730156)
      Use-after-free in file picker dialog
    * CVE-2021-38505 (bmo#1730194)
      Windows 10 Cloud Clipboard may have recorded sensitive user data
    * CVE-2021-38506 (bmo#1730750)
      Firefox could be coaxed into going into fullscreen mode
      without notification or warning
    * CVE-2021-38507 (bmo#1730935)
      Opportunistic Encryption in HTTP2 could be used to bypass the
      Same-Origin-Policy on services hosted on other ports
    * MOZ-2021-0003 (bmo#1736886)
      Universal XSS in Firefox for Android via QR Code URLs
    * CVE-2021-38508 (bmo#1366818)
      Permission Prompt could be overlaid, resulting in user
      confusion and potential spoofing
    * MOZ-2021-0004 (bmo#1659155)
      Web Extensions could access pre-redirect URL when their
      context menu was triggered by a user
    * CVE-2021-38509 (bmo#1718571)
      Javascript alert box could have been spoofed onto an
      arbitrary domain
    * CVE-2021-38510 (bmo#1731779)
      Download Protections were bypassed by .inetloc files on Mac OS
    * MOZ-2021-0005 (bmo#1719203)
      'Copy Image Link' context menu action could have been abused
      to see authentication tokens
    * MOZ-2021-0006 (bmo#1724233)
      URL Parsing may incorrectly parse internationalized domains
    * MOZ-2021-0007 (bmo#1606864, bmo#1712671, bmo#1730048, bmo#1735152)
      Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3
  - removed obsolete patches
    * mozilla-bmo1602730.patch
    * mozilla-bmo1725828.patch
    * mozilla-bmo1729124.patch
  - requires
    NSS >= 3.71
    rust >= 1.53
  - fix Plasma detection (boo#1191825)
  - fix Link error "undefined hidden symbol:"
    https://github.com/openSUSE/firefox-maintenance/issues/37
* Tue Oct 26 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Drop unused pkgconfig(gdk-x11-2.0) BuildRequires
  - (re-)enable LTO on Tumbleweed
* Wed Oct 20 2021 Martin Sirringhaus <martin.sirringhaus@suse.com>
  - Rebase mozilla-sandbox-fips.patch to punch another hole in the
    sandbox containment, to be able to open /proc/sys/crypto/fips_enabled
    from within the newly introduced socket process sandbox.
    This fixes bsc#1191815 and bsc#1190141
* Mon Oct 18 2021 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Add patch to fix build on aarch64 (bmo#1729124)
    * mozilla-bmo1729124.patch
* Fri Oct 01 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 93.0
    * supports the new AVIF image format
    * PDF viewer now supports filling more forms (XFA-based forms)
    * now blocks downloads that rely on insecure connections,
      protecting against potentially malicious or unsafe downloads
    * Improved web compatibility for privacy protections with SmartBlock 3.0
    * Introducing a new referrer tracking protection in Strict Tracking
      Protection and Private Browsing
    * TLS ciphersuites that use 3DES have been disabled. Such
      ciphersuites can only be enabled when deprecated versions of
      TLS are also enabled
    * The download panel now follows the Firefox visual styles
    MFSA 2021-43 (bsc#1191332)
    * CVE-2021-38496 (bmo#1725335)
      Use-after-free in MessageTask
    * CVE-2021-38497 (bmo#1726621)
      Validation message could have been overlaid on another origin
    * CVE-2021-38498 (bmo#1729642)
      Use-after-free of nsLanguageAtomService object
    * CVE-2021-32810 (bmo#1729813)
      https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-pqqp-xmhj-wgcw)
      Data race in crossbeam-deque
    * CVE-2021-38500 (bmo#1725854, bmo#1728321)
      Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15,
      and Firefox ESR 91.2
    * CVE-2021-38501 (bmo#1685354, bmo#1715755, bmo#1723176)
      Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2
    * CVE-2021-38499 (bmo#1667102, bmo#1723170, bmo#1725356, bmo#1727364)
      Memory safety bugs fixed in Firefox 93
  - removed obsolete mozilla-bmo1708709.patch
  - require NSS >= 3.70
  - allow to override wayland detection by defining MOZ_ENABLE_WAYLAND
    explicitely as 0 or 1
  - fix aarch64 build by updating constraints
  - add mozilla-bmo1725828.patch to fix widevine (bsc#1190842)
  - add mozilla-bmo531915.patch to fix build for i586
* Sat Sep 25 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 92.0.1
    * Fixed: Fixes an issue where audio playback was not working on
      some Linux systems (bmo#1730499)
    * Fixed: Fixes issues with the findbar close button on
      different operating systems (bmo#1728368)
* Mon Sep 06 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 92.0
    * More secure connections: Firefox can now automatically upgrade to
      HTTPS using HTTPS RR as Alt-Svc headers
    * Full-range color levels are now supported for video playback on
      many systems
    MFSA 2021-38 (bsc#1190269)
    * CVE-2021-29993 (bmo#1708544, bmo#1708767, bmo#1712240,
      bmo#1712242, bmo#1729259)
      Handling custom intents could lead to crashes and UI spoofs
    * CVE-2021-38491 (bmo#1551886)
      Mixed-Content-Blocking was unable to check opaque origins
    * CVE-2021-38492 (bmo#1721107)
      Navigating to `mk:` URL scheme could load Internet Explorer
    * CVE-2021-38493 (bmo#1723391, bmo#1724101, bmo#1724107)
      Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and
      Firefox ESR 91.1
    * CVE-2021-38494 (bmo#1723920, bmo#1725638)
      Memory safety bugs fixed in Firefox 92
  - updated appdata
  - remove mozilla-disable-wasm-emulate-arm-unaligned-fp-access.patch
    (does not apply anymore; unclear if obsolete)
  - bring back mozilla-silence-no-return-type.patch and
    run post-build-checks everywhere again
  - requires NSS 3.69.1
* Tue Aug 31 2021 Atri Bhattacharya <badshah400@gmail.com>
  - Add mozilla-bmo1708709.patch: On [wayland] popup can be wrongly
    repositioned due to rounding errors when font scaling != 1
    (bmo#1708709); patch taken from upstream bug report and rebased
    to apply cleanly against current version.
* Sun Aug 29 2021 Martin Liška <mliska@suse.cz>
  - Bump using with GCC (tested locally).
* Fri Aug 27 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 91.0.2:
    * Fixed: Firefox no longer clears authentication data when
      purging trackers, to avoid repeatedly prompting for a
      password (bmo#1721084)
* Wed Aug 18 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 91.0.1
    * Fixed an issue causing buttons on the tab bar to be resized when
      loading certain websites (bmo#1704404)
    * Fixed an issue which caused tabs from private windows to be
      visible in non-private windows when viewing switch-to-tab results
      in the address bar panel (bmo#1720369)
    * Various stability fixes
    MFSA 2021-37 (bsc#1189547)
    * CVE-2021-29991 (bmo#1724896)
      Header Splitting possible with HTTP/3 Responses
* Mon Aug 09 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 91.0
    MFSA 2021-33 (bsc#1188891)
    * CVE-2021-29986 (bmo#1696138)
      Race condition when resolving DNS names could have led to
      memory corruption
    * CVE-2021-29981 (bmo#1707774)
      Live range splitting could have led to conflicting
      assignments in the JIT
    * CVE-2021-29988 (bmo#1717922)
      Memory corruption as a result of incorrect style treatment
    * CVE-2021-29983 (bmo#1719088)
      Firefox for Android could get stuck in fullscreen mode
    * CVE-2021-29984 (bmo#1720031)
      Incorrect instruction reordering during JIT optimization
    * CVE-2021-29980 (bmo#1722204)
      Uninitialized memory in a canvas object could have led to
      memory corruption
    * CVE-2021-29987 (bmo#1716129)
      Users could have been tricked into accepting unwanted
      permissions on Linux
    * CVE-2021-29985 (bmo#1722083)
      Use-after-free media channels
    * CVE-2021-29982 (bmo#1715318)
      Single bit data leak due to incorrect JIT optimization and
      type confusion
    * CVE-2021-29989 (bmo#1662676, bmo#1666184, bmo#1719178,
      bmo#1719998, bmo#1720568)
      Memory safety bugs fixed in Firefox 91 and Firefox ESR 78.13
    * CVE-2021-29990 (bmo#1544190, bmo#1716481, bmo#1717778,
      bmo#1719319, bmo#1722073)
      Memory safety bugs fixed in Firefox 91
  - requires
    * rustc/cargo >= 1.51
    * NSPR >= 4.32
    * NSS >= 3.68
  - force-disable webrender on BE platforms
* Sat Jul 24 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 90.0.2:
    * Changed: Updates to support DoH Canada rollout (bmo#1713036)
    * Fixed: Fixed truncated output when printing (bmo#1720621)
    * Fixed: Fixed menu styling on some Gtk themes (bmo#1720441,
      bmo#1720874)
* Mon Jul 19 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 90.0.1 (boo#1188480):
    * Fixed: Fixed busy looping processing some HTTP3 responses
      (bmo#1720079)
    * Fixed: Fixed transient errors authenticating with some smart
      cards (bmo#1715325)
    * Fixed: Fixed a rare crash on shutdown (bmo#1707057)
    * Fixed: Fixed a race on startup that caused about:support to
      end up empty after upgrade (bmo#1717894, boo#1188330)
* Sun Jul 11 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 90.0
    MFSA 2021-28 (bsc#1188275)
    * CVE-2021-29970 (bmo#1709976)
      Use-after-free in accessibility features of a document
    * CVE-2021-29971 (bmo#1713638)
      Granted permissions only compared host; omitting scheme and
      port on Android
    * CVE-2021-30547 (bmo#1715766)
      Out of bounds write in ANGLE
    * CVE-2021-29972 (bmo#1696816)
      Use of out-of-date library included use-after-free
      vulnerability
    * CVE-2021-29973 (bmo#1701932)
      Password autofill on HTTP websites was enabled without user
      interaction on Android
    * CVE-2021-29974 (bmo#1704843)
      HSTS errors could be overridden when network partitioning was
      enabled
    * CVE-2021-29975 (bmo#1713259)
      Text message could be overlaid on top of another website
    * CVE-2021-29976 (bmo#1700895, bmo#1703334, bmo#1706910,
      bmo#1711576, bmo#1714391)
      Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12
    * CVE-2021-29977 (bmo#1665836, bmo#1686138, bmo#1704316,
      bmo#1706314, bmo#1709931, bmo#1712084, bmo#1712357,
      bmo#1714066)
      Memory safety bugs fixed in Firefox 90
  - requires
    NSPR 4.31
    NSS 3.66
  - Gtk2 support removed (was only for Flash plugin before)
* Wed Jun 23 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 89.0.2 (boo#1187648):
    * Fix occasional hangs with Software WebRender on Linux (bmo#1708224)
* Sat Jun 19 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 89.0.1 (boo#1187475):
    * Updated translations, including full Spanish (Mexico)
      localization and other improvements (bmo#1714946)
    * Fix various font related regressions (bmo#1694174)
    * Linux: Fix performance and stability regressions with
      WebRender (bmo#1715895, bmo#1715902)
    * Enterprise: Fix for the `DisableDeveloperTools` policy not
      having effect anymore (bmo#1715777)
    * Linux: Fix broken scrollbars on some GTK themes (bmo#1714103)
    * Various stability fixes
* Sat May 29 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 89.0
    * UI redesign
    * The Event Timing API is now supported
    * The CSS forced-colors media query is now supported
    MFSA 2021-23 (bsc#1186696)
    * CVE-2021-29965 (bmo#1709257)
      Password Manager on Firefox for Android susceptible to domain
      spoofing
    * CVE-2021-29960 (bmo#1675965)
      Filenames printed from private browsing mode incorrectly
      retained in preferences
    * CVE-2021-29961 (bmo#1700235)
      Firefox UI spoof using `<select>` elements and CSS scaling
    * CVE-2021-29963 (bmo#1705068)
      Shared cookies for search suggestions in private browsing mode
    * CVE-2021-29964 (bmo#1706501)
      Out of bounds-read when parsing a `WM_COPYDATA` message
    * CVE-2021-29959 (bmo#1395819)
      Devices could be re-enabled without additional permission prompt
    * CVE-2021-29962 (bmo#1701673)
      No rate-limiting for popups on Firefox for Android
    * CVE-2021-29967 (bmo#1602862, bmo#1703191, bmo#1703760,
      bmo#1704722, bmo#1706041)
      Memory safety bugs fixed in Firefox 89 and Firefox ESR 78.11
    * CVE-2021-29966 (bmo#1660307, bmo#1686154, bmo#1702948, bmo#1708124)
      Memory safety bugs fixed in Firefox 89
  - require
    NSS >= 3.64
    rust-cbindgen >= 0.19.0
  - do not rely on nodejs10 packagename anymore
  - updated mozilla.keyring
  - switched TW/x86_64 to clang as the last platform due to
    https://bugs.gentoo.org/792705
  - but LTO with clang is broken in TW so disable LTO for it
    https://bugs.llvm.org/show_bug.cgi?id=47872
* Thu May 06 2021 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Relax RAM and disk constraints for aarch64
* Wed May 05 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 88.0.1
    * Fixed: Resolved an issue caused by a recent Widevine plugin
      update which prevented some purchased video content from
      playing correctly (bmo#1705138)
    * Fixed: Fixed corruption of videos playing on Twitter or
      WebRTC calls on some Gen6 Intel graphics chipsets
      (bmo#1708937)
    * Fixed: Fixed menulists in Preferences being unreadable for
      users with High Contrast Mode enabled (bmo#1706496)
    MFSA 2021-20 (bsc#1185633)
    * CVE-2021-29952 (bmo#1704227)
      Race condition in Web Render Components
  - devel package: move macros to /usr/lib/rpm/macros.d (boo#1185658)
* Sun May 02 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - add compatibility for libavcodec58_134
* Sun Apr 18 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 88.0
    * New: PDF forms now support JavaScript embedded in PDF files.
      Some PDF forms use JavaScript for validation and other
      interactive features
    * New: Print updates: Margin units are now localized
    * New: Smooth pinch-zooming using a touchpad is now supported
      on Linux
    * New: To protect against cross-site privacy leaks, Firefox now
      isolates window.name data to the website that created it.
      Learn more
    * Changed: Firefox will not prompt for access to your
      microphone or camera if you’ve already granted access to the
      same device on the same site in the same tab within the past
      50 seconds. This new grace period reduces the number of times
      you’re prompted to grant device access
    * Changed: The ‘Take a Screenshot’ feature was removed from the
      Page Actions menu in the url bar. To take a screenshot,
      right-click to open the context menu. You can also add a
      screenshots shortcut directly to your toolbar via the
      Customize menu. Open the Firefox menu and select Customize…
    * Changed: FTP support has been disabled, and its full removal
      is planned for an upcoming release. Addressing this security
      risk reduces the likelihood of an attack while also removing
      support for a non-encrypted protocol
    * Developer: Introduced a new toggle button in the Network
      panel for switching between JSON formatted HTTP response and
      raw data (as received over the wire).
      !enter image description here
    * Enterprise: Various bug fixes and new policies have been
      implemented in the latest version of Firefox. You can see
      more details in the Firefox for Enterprise 88 Release Notes.
    * Fixed: Screen readers no longer incorrectly read content that
      websites have visually hidden, as in the case of articles in
      the Google Help panel
    MFSA 2021-16 (bsc#1184960)
    * CVE-2021-23994 (bmo#1699077)
      Out of bound write due to lazy initialization
    * CVE-2021-23995 (bmo#1699835)
      Use-after-free in Responsive Design Mode
    * CVE-2021-23996 (bmo#1701834)
      Content rendered outside of webpage viewport
    * CVE-2021-23997 (bmo#1701942)
      Use-after-free when freeing fonts from cache
    * CVE-2021-23998 (bmo#1667456)
      Secure Lock icon could have been spoofed
    * CVE-2021-23999 (bmo#1691153)
      Blob URLs may have been granted additional privileges
    * CVE-2021-24000 (bmo#1694698)
      requestPointerLock() could be applied to a tab different from
      the visible tab
    * CVE-2021-24001 (bmo#1694727)
      Testing code could have enabled session history manipulations
      by a compromised content process
    * CVE-2021-24002 (bmo#1702374)
      Arbitrary FTP command execution on FTP servers using an
      encoded URL
    * CVE-2021-29945 (bmo#1700690)
      Incorrect size computation in WebAssembly JIT could lead to
      null-reads
    * CVE-2021-29944 (bmo#1697604)
      HTML injection vulnerability in Firefox for Android's Reader View
    * CVE-2021-29946 (bmo#1698503)
      Port blocking could be bypassed
    * CVE-2021-29947 (bmo#1651449, bmo#1674142, bmo#1693476,
      bmo#1696886, bmo#1700091)
      Memory safety bugs fixed in Firefox 88
  - requires
    * NSPR 4.30
    * NSS 3.63.1
  - align wayland support logic
* Sat Mar 27 2021 Manfred Hollstein <manfred.h@gmx.net>
  - Switch to clang_build globally; just on TW/x86_64 it does not work
    due to unreolved externals `__rust_probestack' - disable clang_build
    then.
  - useccache: Add conditionals to enable/disable ccache.
* Tue Mar 23 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 87.0
    * requires NSS 3.62
    * removed obsolete BigEndian ICU build workaround
    * rebased patches
    MFSA 2021-10 (bsc#1183942)
    * CVE-2021-23981 (bmo#1692832)
      Texture upload into an unbound backing buffer resulted in an
      out-of-bound read
    * CVE-2021-23982 (bmo#1677046)
      Internal network hosts could have been probed by a malicious
      webpage
    * CVE-2021-23983 (bmo#1692684)
      Transitions for invalid ::marker properties resulted in memory
      corruption
    * CVE-2021-23984 (bmo#1693664)
      Malicious extensions could have spoofed popup information
    * CVE-2021-23985 (bmo#1659129)
      Devtools remote debugging feature could have been enabled
      without indication to the user
    * CVE-2021-23986 (bmo#1692623)
      A malicious extension could have performed credential-less
      same origin policy violations
    * CVE-2021-23987 (bmo#1513519, bmo#1683439, bmo#1690169,
      bmo#1690718)
      Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9
    * CVE-2021-23988 (bmo#1684994, bmo#1686653)
      Memory safety bugs fixed in Firefox 87
* Tue Mar 16 2021 Martin Liška <mliska@suse.cz>
  - Set memory limits for DWZ to 4x.
* Sat Mar 13 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 86.0.1
    * Fixed: Fixed an issue on Apple Silicon machines that caused
      Firefox to be unresponsive after system sleep (bmo#1682713)
    * Fixed: Fixed an issue causing windows to gain or lose focus
      unexpectedly (bmo#1694927)
    * Fixed: Fixed truncation of date and time widgets due to
      incorrect width calculation (bmo#1695578)
    * Fixed: Fixed an issue causing unexpected behavior with
      extensions managing tab groups (bmo#1694699)
    * Fixed: Fixed a frequent Linux crash on browser launch
      (bmo#1694670)
* Sun Feb 21 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 86.0
    * requires NSS >= 3.61
    * requires rust-cbindgen >= 0.16.0
    * Firefox now supports simultaneously watching multiple videos in
      Picture-in-Picture.
    * Total Cookie Protection to Strict Mode
    * https://www.mozilla.org/en-US/firefox/86.0/releasenotes
    MSFA 2021-07 (bsc#1182614)
    * CVE-2021-23969 (bmo#1542194)
      Content Security Policy violation report could have contained
      the destination of a redirect
    * CVE-2021-23970 (bmo#1681724)
      Multithreaded WASM triggered assertions validating separation
      of script domains
    * CVE-2021-23968 (bmo#1687342)
      Content Security Policy violation report could have contained
      the destination of a redirect
    * CVE-2021-23974 (bmo#1528997, bmo#1683627)
      noscript elements could have led to an HTML Sanitizer bypass
    * CVE-2021-23971 (bmo#1678545)
      A website's Referrer-Policy could have been be overridden,
      potentially resulting in the full URL being sent as a Referrer
    * CVE-2021-23976 (bmo#1684627)
      Local spoofing of web manifests for arbitrary pages in
      Firefox for Android
    * CVE-2021-23977 (bmo#1684761)
      Malicious application could read sensitive data from Firefox
      for Android's application directories
    * CVE-2021-23972 (bmo#1683536)
      HTTP Auth phishing warning was omitted when a redirect is
      cached
    * CVE-2021-23975 (bmo#1685145)
      about:memory Measure function caused an incorrect pointer
      operation
    * CVE-2021-23973 (bmo#1690976)
      MediaError message property could have leaked information
      about cross-origin resources
    * CVE-2021-23978 (bmo#1682928, bmo#1687391, bmo#1687597, bmo#786797)
      Memory safety bugs fixed in Firefox 86 and Firefox ESR 78.8
    * CVE-2021-23979 (bmo#1663222, bmo#1666607, bmo#1672120, bmo#1678463,
      bmo#1678927, bmo#1679560, bmo#1681297, bmo#1681684, bmo#1683490,
      bmo#1684377, bmo#1684902)
      Memory safety bugs fixed in Firefox 86
  - updated create-tar.sh (bsc#1182357)
  - removed obsolete mozilla-bmo1554971.patch
  - remove buildsymbols subpackage
    * we haven't done anything with it for years
    * mozilla is collecting those from our debuginfo packages
    * would require a local dump_syms tool
* Wed Feb 17 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 85.0.2
    * Fixed: Fixed a deadlock during startup (bmo#1679933)
* Wed Feb 17 2021 Michel Normand <normand@linux.vnet.ibm.com>
  - Use %limit_build macros for PowerPC to avoid oom build failure
* Tue Feb 09 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 85.0.1
    MFSA 2021-06 (bsc#1181848)
    * MOZ-2021-0001 (bmo#1676636)
      Buffer overflow in depth pitch calculations for compressed
      textures
    * Fixed: Avoid printing an extra blank page at the end of some
      documents (bmo#1689789).
    * Fixed: Fixed a browser crash in case of unexpected Cache API
      state (bmo#1684838).
* Sun Jan 24 2021 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 85.0
    * Adobe Flash is completely history
    * supercookie protection
    * new bookmark handling and features
    MFSA 2021-03 (bsc#1181414)
    * CVE-2021-23953 (bmo#1683940)
      Cross-origin information leakage via redirected PDF requests
    * CVE-2021-23954 (bmo#1684020)
      Type confusion when using logical assignment operators in
      JavaScript switch statements
    * CVE-2021-23955 (bmo#1684837)
      Clickjacking across tabs through misusing requestPointerLock
    * CVE-2021-23956 (bmo#1338637)
      File picker dialog could have been used to disclose a
      complete directory
    * CVE-2021-23957 (bmo#1584582)
      Iframe sandbox could have been bypassed on Android via the
      intent URL scheme
    * CVE-2021-23958 (bmo#1642747)
      Screen sharing permission leaked across tabs
    * CVE-2021-23959 (bmo#1659035)
      Cross-Site Scripting in error pages on Firefox for Android
    * CVE-2021-23960 (bmo#1675755)
      Use-after-poison for incorrectly redeclared JavaScript
      variables during GC
    * CVE-2021-23961 (bmo#1677940)
      More internal network hosts could have been probed by a
      malicious webpage
    * CVE-2021-23962 (bmo#1677194)
      Use-after-poison in
      <code>nsTreeBodyFrame::RowCountChanged</code>
    * CVE-2021-23963 (bmo#1680793)
      Permission prompt inaccessible after asking for additional
      permissions
    * CVE-2021-23964 (bmo#1662507, bmo#1666285, bmo#1673526, bmo#1674278,
      bmo#1674835, bmo#1675097, bmo#1675844, bmo#1675868, bmo#1677590,
      bmo#1677888, bmo#1680410, bmo#1681268, bmo#1682068, bmo#1682938,
      bmo#1683736, bmo#1685260, bmo#1685925)
      Memory safety bugs fixed in Firefox 85 and Firefox ESR 78.7
    * CVE-2021-23965 (bmo#1670378, bmo#1673555, bmo#1676812, bmo#1678582,
      bmo#1684497)
      Memory safety bugs fixed in Firefox 85
  - requires NSS 3.60.1
  - requires rust 1.47
  - remove obsolete mozilla-pipewire-0-3.patch
* Mon Jan 11 2021 Matthias Mailänder <mailaender@opensuse.org>
  - Fix AppStream screenshot links
* Thu Jan 07 2021 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 84.0.2
    MFSA 2021-01 (bsc#1180623)
    * CVE-2020-16044 (bmo#1683964)
      Use-after-free write when handling a malicious COOKIE-ECHO
      SCTP chunk
* Sun Dec 27 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 84.0.1
    * Fixed problems loading secure websites and crashes for users
      with certain third-party PKCS11 modules and smartcards installed
      (bmo#1682881) (fixed in NSS 3.59.1)
    * Fixed a bug causing some Unity JS games to not load on Apple
      Silicon devices due to improper detection of the OS version
      (bmo#1680516)
  - requires NSS 3.59.1
* Sun Dec 13 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 84.0
    * Firefox 84 is the final release to support Adobe Flash
    * WebRender is enabled by default when run on GNOME-based X11
      Linux desktops
    MFSA 2020-54 (bsc#1180039))
    * CVE-2020-16042 (bmo#1679003)
      Operations on a BigInt could have caused uninitialized memory
      to be exposed
    * CVE-2020-26971 (bmo#1663466)
      Heap buffer overflow in WebGL
    * CVE-2020-26972 (bmo#1671382)
      Use-After-Free in WebGL
    * CVE-2020-26973 (bmo#1680084)
      CSS Sanitizer performed incorrect sanitization
    * CVE-2020-26974 (bmo#1681022)
      Incorrect cast of StyleGenericFlexBasis resulted in a heap
      use-after-free
    * CVE-2020-26975 (bmo#1661071)
      Malicious applications on Android could have induced Firefox
      for Android into sending arbitrary attacker-specified headers
    * CVE-2020-26976 (bmo#1674343)
      HTTPS pages could have been intercepted by a registered
      service worker when they should not have been
    * CVE-2020-26977 (bmo#1676311)
      URL spoofing via unresponsive port in Firefox for Android
    * CVE-2020-26978 (bmo#1677047)
      Internal network hosts could have been probed by a malicious
      webpage
    * CVE-2020-26979 (bmo#1641287, bmo#1673299)
      When entering an address in the address or search bars, a
      website could have redirected the user before they were
      navigated to the intended url
    * CVE-2020-35111 (bmo#1657916)
      The proxy.onRequest API did not catch view-source URLs
    * CVE-2020-35112 (bmo#1661365)
      Opening an extension-less download may have inadvertently
      launched an executable instead
    * CVE-2020-35113 (bmo#1664831, bmo#1673589)
      Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6
    * CVE-2020-35114 (bmo#1607449, bmo#1640416, bmo#1656459,
      bmo#1669914, bmo#1673567)
      Memory safety bugs fixed in Firefox 84
  - requires
    NSS >= 3.59
    rust >= 1.44
    rust-cbindgen >= 0.15.0
  - remove revert-795c8762b16b.patch and replace with mozilla-pgo.patch
* Sat Nov 21 2020 Kirill Kirillov <kkirill@opensuse.org>
  - Add/Enable GNOME search provider
* Sun Nov 15 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 83.0
    * major update for SpiderMonkey improving performance significantly
    * optional HTTPS-Only mode
    * more improvements
      https://www.mozilla.org/en-US/firefox/83.0/releasenotes/
    MFSA 2020-50 (bsc#1178824))
    * CVE-2020-26951 (bmo#1667113)
      Parsing mismatches could confuse and bypass security
      sanitizer for chrome privileged code
    * CVE-2020-26952 (bmo#1667685)
      Out of memory handling of JITed, inlined functions could lead
      to a memory corruption
    * CVE-2020-16012 (bmo#1642028)
      Variable time processing of cross-origin images during
      drawImage calls
    * CVE-2020-26953 (bmo#1656741)
      Fullscreen could be enabled without displaying the security UI
    * CVE-2020-26954 (bmo#1657026)
      Local spoofing of web manifests for arbitrary pages in
      Firefox for Android
    * CVE-2020-26955 (bmo#1663261)
      Cookies set during file downloads are shared between normal
      and Private Browsing Mode in Firefox for Android
    * CVE-2020-26956 (bmo#1666300)
      XSS through paste (manual and clipboard API)
    * CVE-2020-26957 (bmo#1667179)
      OneCRL was not working in Firefox for Android
    * CVE-2020-26958 (bmo#1669355)
      Requests intercepted through ServiceWorkers lacked MIME type
      restrictions
    * CVE-2020-26959 (bmo#1669466)
      Use-after-free in WebRequestService
    * CVE-2020-26960 (bmo#1670358)
      Potential use-after-free in uses of nsTArray
    * CVE-2020-15999 (bmo#1672223)
      Heap buffer overflow in freetype
    * CVE-2020-26961 (bmo#1672528)
      DoH did not filter IPv4 mapped IP Addresses
    * CVE-2020-26962 (bmo#610997)
      Cross-origin iframes supported login autofill
    * CVE-2020-26963 (bmo#1314912)
      History and Location interfaces could have been used to hang
      the browser
    * CVE-2020-26964 (bmo#1658865)
      Firefox for Android's Remote Debugging via USB could have
      been abused by untrusted apps on older versions of Android
    * CVE-2020-26965 (bmo#1661617)
      Software keyboards may have remembered typed passwords
    * CVE-2020-26966 (bmo#1663571)
      Single-word search queries were also broadcast to local
      network
    * CVE-2020-26967 (bmo#1665820)
      Mutation Observers could break or confuse Firefox Screenshots
      feature
    * CVE-2020-26968 (bmo#1551615, bmo#1607762, bmo#1656697,
      bmo#1657739, bmo#1660236, bmo#1667912, bmo#1671479,
      bmo#1671923)
      Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5
    * CVE-2020-26969 (bmo#1623920, bmo#1651705, bmo#1667872,
      bmo#1668876)
      Memory safety bugs fixed in Firefox 83
  - requires
    NSS >= 3.58
    nodejs >= 10.22.1
  - removed obsolete mozilla-ppc-altivec_static_inline.patch
  - disable LTO on TW because of ICEs in gcc
* Mon Nov 09 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 82.0.3
    MSFA 2020-49
    * CVE-2020-26950 (bmo#1675905)
      Write side effects in MCallGetProperty opcode not accounted for
* Mon Nov 02 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 82.0.2
    * few bugfixes for introduced regressions
* Sun Nov 01 2020 Kirill Kirillov <kkirill@opensuse.org>
  - Enable GNOME search provider
* Thu Oct 15 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 82.0
    * https://www.mozilla.org/en-US/firefox/82.0/releasenotes/
    MFSA 2020-45 (bsc#1177872)
    * CVE-2020-15969 (bmo#1666570)
      Use-after-free in usersctp
    * CVE-2020-15254 (bmo#1668514)
      Undefined behavior in bounded channel of crossbeam rust crate
    * CVE-2020-15680 (bmo#1658881)
      Presence of external protocol handlers could be determined
      through image tags
    * CVE-2020-15681 (bmo#1666568)
      Multiple WASM threads may have overwritten each others' stub
      table entries
    * CVE-2020-15682 (bmo#1636654)
      The domain associated with the prompt to open an external
      protocol could be spoofed to display the incorrect origin
    * CVE-2020-15683 (bmo#1576843, bmo#1656987, bmo#1660954,
      bmo#1662760, bmo#1663439, bmo#1666140)
      Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4
    * CVE-2020-15684 (bmo#1653764, bmo#1661402, bmo#1662259,
      bmo#1664257)
      Memory safety bugs fixed in Firefox 82
  - requires
    * NSPR 4.29
    * NSS 3.57
* Thu Oct 01 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 81.0.1
    * https://www.mozilla.org/en-US/firefox/81.0.1/releasenotes/
  - remove obsolete python2 build requires
* Wed Sep 30 2020 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Increase disk requirements in _constraints to match current needs
* Fri Sep 18 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 81.0
    * https://www.mozilla.org/en-US/firefox/81.0/releasenotes
    MFSA 2020-42 (bsc#1176756)
    * CVE-2020-15675 (bmo#1654211)
      Use-After-Free in WebGL
    * CVE-2020-15677 (bmo#1641487)
      Download origin spoofing via redirect
    * CVE-2020-15676 (bmo#1646140)
      XSS when pasting attacker-controlled data into a
      contenteditable element
    * CVE-2020-15678 (bmo#1660211)
      When recursing through layers while scrolling, an iterator
      may have become invalid, resulting in a potential use-after-
      free scenario
    * CVE-2020-15673 (bmo#1648493, bmo#1660800)
      Memory safety bugs fixed in Firefox 81 and Firefox ESR 78.3
    * CVE-2020-15674 (bmo#1656063, bmo#1656064, bmo#1656067, bmo#1660293)
      Memory safety bugs fixed in Firefox 81
  - requires
    NSPR 4.28
    NSS 3.56
  - removed obsolete patches
    * mozilla-system-nspr.patch
    * mozilla-bmo1661715.patch
    * mozilla-silence-no-return-type.patch
  - skip post-build-checks for 15.0 and 15.1
  - add revert-795c8762b16b.patch to fix LTO builds with gcc
    (related to bmo#1644409)
  - require python3-curses as workaround to fix i586 build
* Thu Sep 17 2020 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Use %limit_build macro again for aarch64 and armv7, instead of
    the new memoryperjob _constraints to use more workers
* Sat Sep 05 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - add mozilla-bmo1661715.patch to fix Flash plugin
* Wed Sep 02 2020 Manfred Hollstein <manfred.h@gmx.net>
  - Mozilla Firefox 80.0.1: Bug fixes:
    * Fixed a performance regression when encountering new intermediate
      CA certificates (bmo#1661543)
    * Fixed crashes possibly related to GPU resets (bmo#1627616)
    * Fixed rendering on some sites using WebGL (bmo#1659225)
    * Fixed the zoom-in keyboard shortcut on Japanese language builds
      (bmo#1661895)
    * Fixed download issues related to extensions and cookies
      (bmo#1655190)
  - added mozilla-silence-no-return-type.patch
* Tue Aug 25 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - more whitelisting (/dev/random) for sandbox in relation to FIPS
    (bsc#1174284)
  - improve langpack builds to use dedicated objdirs and make it
    parallel again
* Sat Aug 22 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 80.0
    MFSA 2020-36 (bsc#1175686)
    * CVE-2020-15663 (bmo#1643199)
      Downgrade attack on the Mozilla Maintenance Service could
      have resulted in escalation of privilege
    * CVE-2020-15664 (bmo#1658214)
      Attacker-induced prompt for extension installation
    * CVE-2020-12401 (bmo#1631573)
      Timing-attack on ECDSA signature generation
    * CVE-2020-6829 (bmo#1631583)
      P-384 and P-521 vulnerable to an electro-magnetic side
      channel attack on signature generation
    * CVE-2020-12400 (bmo#1623116)
      P-384 and P-521 vulnerable to a side channel attack on
      modular inversion
    * CVE-2020-15665 (bmo#1651636)
      Address bar not reset when choosing to stay on a page after
      the beforeunload dialog is shown
    * CVE-2020-15666 (bmo#1450853)
      MediaError message property leaks cross-origin response
      status
    * CVE-2020-15667 (bmo#1653371)
      Heap overflow when processing an update file
    * CVE-2020-15668 (bmo#1651520)
      Data Race when reading certificate information
    * CVE-2020-15670 (bmo#1651001, bmo#1651449, bmo#1653626,
      bmo#1656957)
      Memory safety bugs fixed in Firefox 80 and Firefox ESR 78.2
  - requires
    * NSPR 4.27
    * NSS 3.55
  - added mozilla-system-nspr.patch (bmo#1661096)
  - exclude ga-IE locale as it's failing to build
  - rollback parallelize locale build because it breaks bookmarks
    (boo#1167976)
  - preserve original default bookmark file during langpack build
    (boo#1167976)
  - add some ccache output during build
* Thu Aug 20 2020 Martin Liška <mliska@suse.cz>
  - Use new memoryperjob _constraints instead of %limit_build macro.
* Mon Aug 10 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - use ccache for build
  - replace versioned RPM deps with requires_ge
  - parallelize locale build
* Thu Aug 06 2020 Yunhe Guo <i@guoyunhe.me>
  - Change *.appdata.xml location to latest AppStream standard
* Thu Jul 23 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 79.0
    MFSA 2020-30 (bsc#1174538)
    * CVE-2020-15652 (bmo#1634872)
      Potential leak of redirect targets when loading scripts in a worker
    * CVE-2020-6514 (bmo#1642792)
      WebRTC data channel leaks internal address to peer
    * CVE-2020-15655 (bmo#1645204)
      Extension APIs could be used to bypass Same-Origin Policy
    * CVE-2020-15653 (bmo#1521542)
      Bypassing iframe sandbox when allowing popups
    * CVE-2020-6463 (bmo#1635293)
      Use-after-free in ANGLE gl::Texture::onUnbindAsSamplerTexture
    * CVE-2020-15656 (bmo#1647293)
      Type confusion for special arguments in IonMonkey
    * CVE-2020-15658 (bmo#1637745)
      Overriding file type when saving to disk
    * CVE-2020-15657 (bmo#1644954)
      DLL hijacking due to incorrect loading path
    * CVE-2020-15654 (bmo#1648333)
      Custom cursor can overlay user interface
    * CVE-2020-15659 (bmo#1550133, bmo#1633880, bmo#1638856,
      bmo#1643613, bmo#1644839, bmo#1645835, bmo#1646006, bmo#1646220,
      bmo#1646787, bmo#1649347, bmo#1650811, bmo#1651678)
      Memory safety bugs fixed in Firefox 79
  - updated dependency requirements:
    * mozilla-nspr >= 4.26
    * mozilla-nss >= 3.54
    * rust >= 1.43
    * rust-cbindgen >= 0.14.3
  - removed obsolete patch
    mozilla-bmo1463035.patch
* Tue Jul 21 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - fixed syntax issue in desktop file (boo#1174360)
* Fri Jul 17 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Add mozilla-libavcodec58_91.patch to link against updated
    soversion of libavcodec (58.91) with ffmpeg >= 4.3.
    (patch provided by Atri Bhattacharya <badshah400@gmail.com>
  - enable MOZ_USE_XINPUT2 for TW (again) (boo#1173320)
    (Plasma 5.19.3 is now in TW)
* Sat Jul 11 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 78.0.2
    * Fixed an accessibility regression in reader mode (bmo#1650922)
    * Made the address bar more resilient to data corruption in the
      user profile (bmo#1649981)
    * Fixed a regression opening certain external applications (bmo#1650162)
    MFSA 2020-28
    * CVE pending (bmo#1644076)
      X-Frame-Options bypass using object or embed tags
  - added desktop file actions
  - do not use XINPUT2 for the moment until Plasma 5.19.3 has landed
    (boo#1173993)
  - rework langpack integration (boo#1173991)
    * ship XPIs instead of directories
    * allow addon sideloading
    * mark signatures for langpacks non-mandatory
    * do not autodisable user profile scopes
  - Google API key is not usable for geolocation service
  - fix pipewire support for TW (boo#1172903)
* Wed Jul 01 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 78.0.1
    * Fixed an issue which could cause installed search engines to not
      be visible when upgrading from a previous release.
  - enable MOZ_USE_XINPUT2 for TW (boo#1173320)
* Sun Jun 28 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 78.0
    * startup notifications now using Gtk instead of libnotify
    * PDF downloads now show an option to open the PDF directly in Firefox
    * Protections Dashboard (about:protections)
    * WebRTC not interrupted by screensaver anymore
    * disabled TLS 1.0 and 1.1 by default
    MFSA 2020-24 (bsc#1173576)
    * CVE-2020-12415 (bmo#1586630)
      AppCache manifest poisoning due to url encoded character processing
    * CVE-2020-12416 (bmo#1639734)
      Use-after-free in WebRTC VideoBroadcaster
    * CVE-2020-12417 (bmo#1640737)
      Memory corruption due to missing sign-extension for ValueTags
      on ARM64
    * CVE-2020-12418 (bmo#1641303)
      Information disclosure due to manipulated URL object
    * CVE-2020-12419 (bmo#1643874)
      Use-after-free in nsGlobalWindowInner
    * CVE-2020-12420 (bmo#1643437)
      Use-After-Free when trying to connect to a STUN server
    * CVE-2020-12402 (bmo#1631597)
      RSA Key Generation vulnerable to side-channel attack
    * CVE-2020-12421 (bmo#1308251)
      Add-On updates did not respect the same certificate trust
      rules as software updates
    * CVE-2020-12422 (bmo#1450353)
      Integer overflow in nsJPEGEncoder::emptyOutputBuffer
    * CVE-2020-12423 (bmo#1642400)
      DLL Hijacking due to searching %PATH% for a library
    * CVE-2020-12424 (bmo#1562600)
      WebRTC permission prompt could have been bypassed by a
      compromised content process
    * CVE-2020-12425 (bmo#1634738)
      Out of bound read in Date.parse()
    * CVE-2020-12426 (bmo#1608068, bmo#1609951, bmo#1631187, bmo#1637682)
      Memory safety bugs fixed in Firefox 78
  - requires
    * NSS >= 3.53.1
    * nodejs >= 10.21
    * Gtk+3 >= 3.14
  - removed obsolete patches
    * mozilla-s390-bigendian.patch
    * mozilla-bmo1634646.patch
  - Add mozilla-pipewire-0-3.patch for openSUSE >= 15.2 to build
    WebRTC with pipewire support to enable screen sharing under
    Wayland; also add BuildRequires: pkgconfig(libpipewire-0.3)
    appropriately (boo#1172903).
  - adding SLE12 compatibility in spec file
  - add patches for s390x
    * mozilla-bmo1602730.patch (bmo#1602730)
    * mozilla-bmo1626236.patch (bmo#1626236)
    * mozilla-bmo998749.patch (bmo#998749)
    * mozilla-s390x-skia-gradient.patch
  - update create-tar.sh
  - Use same _constraints for ppc64 (BE) as ppc64le to avoid oom build failure
* Wed Jun 10 2020 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Exclude armv6, since it is unbuildable since about 3 years
* Wed Jun 03 2020 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 77.0.1
    * Disable automatic selection of DNS over HTTPS providers during
      a test to enable wider deployment in a more controlled way
      (bmo#1642723)
* Fri May 29 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 77.0
    * view and manage web certificates more easily on the new
      about:certificate page
    * improvements in accessibility
    * significant improvements to JavaScript debugging
    MFSA 2020-20 (bsc#1172402)
    * CVE-2020-12399 (bmo#1631576)
      Timing attack on DSA signatures in NSS library
      (fixed with external NSS >= 3.52.1)
    * CVE-2020-12405 (bmo#1631618)
      Use-after-free in SharedWorkerService
    * CVE-2020-12406 (bmo#1639590)
      JavaScript type confusion with NativeTypes
    * CVE-2020-12407 (bmo#1637112)
      WebRender leaking GPU memory when using border-image CSS
      directive
    * CVE-2020-12408 (bmo#1623888)
      URL spoofing when using IP addresses
    * CVE-2020-12409 (bmo#1619305, bmo#1632717)
      Memory safety bugs fixed in Firefox 77 and Firefox ESR 68.9
    * CVE-2020-12411 (bmo#1620972, bmo#1625333)
      Memory safety bugs fixed in Firefox 77
  - requires
    * NSS >= 3.52.1
    * rust-cbindgen >= 1.14.1
    * clang >= 5
  - added mozilla-bmo1634646.patch as part of fixing PGO build
    (still not working)
* Wed May 13 2020 Michel Normand <normand@linux.vnet.ibm.com>
  - change again _constraints for ppc64le use <physicalmemory>
    and increase limit_build in spec file to reduce max_jobs.
* Sat May 09 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 76.0.1
    * Fixed a bug causing some add-ons such as Amazon Assistant to see
      multiple onConnect events, impairing functionality (bmo#1635637)
* Fri May 01 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 76.0
    * Lockwise improvements
    * Improvements in Picture-in-Picture feature
    * Support Audio Worklets
    MFSA-2020-16 (bsc#1171186)
    * CVE-2020-12387 (bmo#1545345)
      Use-after-free during worker shutdown
    * CVE-2020-12388 (bmo#1618911)
      Sandbox escape with improperly guarded Access Tokens
    * CVE-2020-12389 (bmo#1554110)
      Sandbox escape with improperly separated process types
    * CVE-2020-6831 (bmo#1632241)
      Buffer overflow in SCTP chunk input validation
    * CVE-2020-12390 (bmo#1141959)
      Incorrect serialization of nsIPrincipal.origin for IPv6 addresses
    * CVE-2020-12391 (bmo#1457100)
      Content-Security-Policy bypass using object elements
    * CVE-2020-12392 (bmo#1614468)
      Arbitrary local file access with 'Copy as cURL'
    * CVE-2020-12393 (bmo#1615471)
      Devtools' 'Copy as cURL' feature did not fully escape
      website-controlled data, potentially leading to command injection
    * CVE-2020-12394 (bmo#1628288)
      URL spoofing in location bar when unfocussed
    * CVE-2020-12395 (bmo#1595886, bmo#1611482, bmo#1614704, bmo#1624098,
      bmo#1625749, bmo#1626382, bmo#1628076, bmo#1631508)
      Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8
    * CVE-2020-12396 (bmo#1339601, bmo#1611938, bmo#1620488,
      bmo#1622291, bmo#1627644)
      Memory safety bugs fixed in Firefox 76
  - requires
    * NSS >= 3.51.1
    * nasm >= 2.14
  - removed obsolete patch mozilla-bmo1622013.patch
  - fix URI creation for KDE file selector integration (boo#1160331)
* Tue Apr 07 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 75.0
    * https://www.mozilla.org/en-US/firefox/75.0/releasenotes
    MFSA 2020-12 (bsc#1168874)
    * CVE-2020-6821 (bmo#1625404)
      Uninitialized memory could be read when using the WebGL
      copyTexSubImage method
    * CVE-2020-6822 (bmo#1544181)
      Out of bounds write in GMPDecodeData when processing large images
    * CVE-2020-6823 (bmo#1614919)
      Malicious Extension could obtain auth codes from OAuth login flows
    * CVE-2020-6824 (bmo#1621853)
      Generated passwords may be identical on the same site between
      separate private browsing sessions
    * CVE-2020-6825 (bmo#1572541,bmo#1620193,bmo#1620203)
      Memory safety bugs fixed in Firefox 75 and Firefox ESR 68.7
    * CVE-2020-6826 (bmo#1613009,bmo#1613195,bmo#1616734,bmo#1617488,
      bmo#1619229,bmo#1620719,bmo#1624897)
      Memory safety bugs fixed in Firefox 75
  - removed obsolete patch
    mozilla-bmo1609538.patch
  - requires
    * rust >= 1.41
    * rust-cbindgen >= 0.13.1
    * mozilla-nss >= 3.51
    * nodejs10 >= 10.19
  - fix build issue in libvpx for i586 via mozilla-bmo1622013.patch
* Mon Apr 06 2020 Michel Normand <normand@linux.vnet.ibm.com>
  - increase _constraints memory for ppc64le
* Fri Apr 03 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 74.0.1
    MFSA 2020-11 (boo#1168630)
    * CVE-2020-6819 (bmo#1620818)
      Use-after-free while running the nsDocShell destructor
    * CVE-2020-6820 (bmo#1626728)
      Use-after-free when handling a ReadableStream
* Wed Mar 25 2020 Marcus Meissner <meissner@suse.com>
  - mozilla-sandbox-fips.patch: allow /proc/sys/crypto/fips_enabled
    to be read, as openssl 1.1.1 FIPS aborts if it cannot access it
    (bsc#1167132)
* Sat Mar 07 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 74.0
    * https://www.mozilla.org/en-US/firefox/74.0/releasenotes/
    MFSA 2020-08 (bsc#1166238)
    * CVE-2020-6805 (bmo#1610880)
      Use-after-free when removing data about origins
    * CVE-2020-6806 (bmo#1612308)
      BodyStream::OnInputStreamReady was missing protections against
      state confusion
    * CVE-2020-6807 (bmo#1614971)
      Use-after-free in cubeb during stream destruction
    * CVE-2020-6808 (bmo#1247968)
      URL Spoofing via javascript: URL
    * CVE-2020-6809 (bmo#1420296)
      Web Extensions with the all-urls permission could access local
      files
    * CVE-2020-6810 (bmo#1432856)
      Focusing a popup while in fullscreen could have obscured the
      fullscreen notification
    * CVE-2020-6811 (bmo#1607742)
      Devtools' 'Copy as cURL' feature did not fully escape
      website-controlled data, potentially leading to command injection
    * CVE-2019-20503 (bmo#1613765)
      Out of bounds reads in sctp_load_addresses_from_init
    * CVE-2020-6812 (bmo#1616661)
      The names of AirPods with personally identifiable information
      were exposed to websites with camera or microphone permission
    * CVE-2020-6813 (bmo#1605814)
      @import statements in CSS could bypass the Content Security
      Policy nonce feature
    * CVE-2020-6814 (bmo#1592078,bmo#1604847,bmo#1608256,bmo#1612636,
      bmo#1614339)
      Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6
    * CVE-2020-6815 (bmo#1181957,bmo#1557732,bmo#1557739,bmo#1611457,
      bmo#1612431)
      Memory and script safety bugs fixed in Firefox 74
  - requires
    * NSPR 4.25
    * NSS 3.50
    * rust-cbindgen 0.13.0
  - removed obsolete patches
    mozilla-bmo1610814.patch
    mozilla-cubeb-noreturn.patch
  - add mozilla-bmo1609538.patch to fix wayland issues with mutter 3.36
    (bmo#1609538, boo#1166471)
* Wed Feb 26 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - big endian fixes
* Tue Feb 25 2020 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Fix build on aarch64/armv7 with:
    * mozilla-bmo1610814.patch (boo#1164845, bmo#1610814)
* Thu Feb 20 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 73.0.1
    * Resolved problems connecting to the RBC Royal Bank website
      (bmo#1613943)
    * Fixed Firefox unexpectedly exiting when leaving Print Preview mode
      (bmo#1611133)
    * Fixed crashes when playing encrypted content on some Linux systems
      (bmo#1614535, boo#1164646)
  - start in wayland mode when running under wayland session
* Sun Feb 09 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 73.0
    * Added support for setting a default zoom level applicable for all
      web content
    * High-contrast mode has been updated to allow background images
    * Improved audio quality when playing back audio at a faster or
      slower speed
    * Added NextDNS as alternative option for DNS over HTTPS
    MFSA 2020-05 (bsc#1163368)
    * CVE-2020-6796 (bmo#1610426)
      Missing bounds check on shared memory read in the parent process
    * CVE-2020-6797 (bmo#1596668) (MacOS X only)
      Extensions granted downloads.open permission could open arbitrary
      applications on Mac OSX
    * CVE-2020-6798 (bmo#1602944)
      Incorrect parsing of template tag could result in JavaScript injection
    * CVE-2020-6799 (bmo#1606596) (Windows only)
      Arbitrary code execution when opening pdf links from other
      applications, when Firefox is configured as default pdf reader
    * CVE-2020-6800 (bmo#1595786,bmo#1596706,bmo#1598543,bmo#1604851,
      bmo#1608580,bmo#1608785,bmo#1605777)
      Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5
    * CVE-2020-6801 (bmo#1601024,bmo#1601712,bmo#1604836,bmo#1606492)
      Memory safety bugs fixed in Firefox 73
  - updated requirements
    * rust >= 1.39
    * NSS >= 3.49.2
    * rust-cbindgen >= 0.12.0
  - rebased patches
  - removed obsolete patch
    * mozilla-bmo1601707.patch
  - switched to cairo-gtk3-wayland build
    (to fully enable wayland MOZ_ENABLE_WAYLAND=1 needs to be set)
  - disabled elfhack due to failing packager
    https://github.com/openSUSE/firefox-maintenance/issues/28
  - disabled PGO due to build failure
    https://github.com/openSUSE/firefox-maintenance/issues/29
* Tue Jan 28 2020 Stasiek Michalski <stasiek@michalski.cc>
  - Use a symbolic icon from branding internals
  - Pixmaps no longer required for the desktops
* Wed Jan 22 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 72.0.2
    * Various stability fixes
    * Fixed issues opening files with spaces in their path (bmo#1601905)
    * Fixed a hang opening about:logins when a master password is set
      (bmo#1606992)
    * Fixed a web compatibility issue with CSS Shadow Parts which
      shipped in Firefox 72 (bmo#1604989)
    * Fixed inconsistent playback performance for fullscreen 1080p
      videos on some systems (bmo#1608485)
* Tue Jan 21 2020 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Fix build for aarch64/ppc64le (do not update config.sub file
    for libbacktrace)
* Wed Jan 08 2020 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 72.0.1
    MFSA 2020-03 (bsc#1160498)
    * CVE-2019-17026 (bmo#1607443)
      IonMonkey type confusion with StoreElementHole and FallibleStoreElement
  - Mozilla Firefox 72.0
    * block fingerprinting scripts by default
    * new notification pop-ups
    * Picture-in-picture video
    MFSA 2020-01 (bsc#1160305)
    * CVE-2019-17016 (bmo#1599181)
      Bypass of @namespace CSS sanitization during pasting
    * CVE-2019-17017 (bmo#1603055)
      Type Confusion in XPCVariant.cpp
    * CVE-2019-17020 (bmo#1597645)
      Content Security Policy not applied to XSL stylesheets applied
      to XML documents
    * CVE-2019-17022 (bmo#1602843)
      CSS sanitization does not escape HTML tags
    * CVE-2019-17023 (bmo#1590001) (fixed in NSS FIXME)
      NSS may negotiate TLS 1.2 or below after a TLS 1.3
      HelloRetryRequest had been sent
    * CVE-2019-17024 (bmo#1507180,bmo#1595470,bmo#1598605,bmo#1601826)
      Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4
    * CVE-2019-17025 (bmo#1328295,bmo#1328300,bmo#1590447,bmo#1590965
      bmo#1595692,bmo#1597321,bmo#1597481)
      Memory safety bugs fixed in Firefox 72
  - update create-tar.sh to skip compare-locales
  - requires NSPR 4.24 and NSS 3.48
  - removed usage of browser-plugins convention for NPAPI plugins
    from start wrapper and changed the RPM macro to the
    /usr/$LIB/mozilla/plugins location (boo#1160302)
* Mon Dec 02 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 71.0
    * Improvements to Lockwise, our integrated password manager
    * More information about Enhanced Tracking Protection in action
    * Native MP3 decoding on Windows, Linux, and macOS
    * Configuration page (about:config) reimplemented in HTML
    * New kiosk mode functionality, which allows maximum screen space
      for customer-facing displays
    MFSA 2019-36
    * CVE-2019-11756 (bmo#1508776)
      Use-after-free of SFTKSession object
    * CVE-2019-17008 (bmo#1546331)
      Use-after-free in worker destruction
    * CVE-2019-13722 (bmo#1580156) (Windows only)
      Stack corruption due to incorrect number of arguments in WebRTC code
    * CVE-2019-17014 (bmo#1322864)
      Dragging and dropping a cross-origin resource, incorrectly loaded
      as an image, could result in information disclosure
    * CVE-2019-17010 (bmo#1581084)
      Use-after-free when performing device orientation checks
    * CVE-2019-17005 (bmo#1584170)
      Buffer overflow in plain text serializer
    * CVE-2019-17011 (bmo#1591334)
      Use-after-free when retrieving a document in antitracking
    * CVE-2019-17012 (bmo#1449736, bmo#1533957, bmo#1560667, bmo#1567209
      bmo#1580288, bmo#1585760, bmo#1592502)
      Memory safety bugs fixed in Firefox 71 and Firefox ESR 68.3
    * CVE-2019-17013 (bmo#1298509, bmo#1472328, bmo#1577439, bmo#1577937
      bmo#1580320, bmo#1584195, bmo#1585106, bmo#1586293, bmo#1593865
      bmo#1594181)
      Memory safety bugs fixed in Firefox 71
  - requires
    NSPR >= 4.23
    NSS >= 3.47.1
    rust/cargo >= 1.37
  - reactivate webrtc for platforms where it was disabled
  - updated create-tar.sh to cover buildid and origin repo information
    - > removed obsolete source-stamp.txt
  - removed obsolete patches
    mozilla-bmo1511604.patch
    mozilla-openaes-decl.patch
  - changed locale building procedure
    * removed obsolete compare-locales.tar.xz
  - added mozilla-bmo1601707.patch to fix gcc/LTO builds
    (bmo#1601707, boo#1158466)
  - added mozilla-bmo849632.patch to fix big endian issues in skia
    used for WebGL
* Fri Nov 01 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 70.0.1
    * Fix for an issue that caused some websites or page elements using
      dynamic JavaScript to fail to load. (bmo#1592136)
    * Title bar no longer shows in full screen view (bmo#1588747)
  - added mozilla-bmo1504834-part4.patch to fix some visual issues on
    big endian platforms
* Sun Oct 20 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 70.0
    * more privacy protections from Enhanced Tracking Protection
    * Firefox Lockwise passwordmanager
    * Improvements to core engine components, for better browsing on more sites
    * Improved privacy and security indicators
    MFSA 2019-34
    * CVE-2018-6156 (bmo#1480088)
      Heap buffer overflow in FEC processing in WebRTC
    * CVE-2019-15903 (bmo#1584907)
      Heap overflow in expat library in XML_GetCurrentLineNumber
    * CVE-2019-11757 (bmo#1577107)
      Use-after-free when creating index updates in IndexedDB
    * CVE-2019-11759 (bmo#1577953)
      Stack buffer overflow in HKDF output
    * CVE-2019-11760 (bmo#1577719)
      Stack buffer overflow in WebRTC networking
    * CVE-2019-11761 (bmo#1561502)
      Unintended access to a privileged JSONView object
    * CVE-2019-11762 (bmo#1582857)
      document.domain-based origin isolation has same-origin-property violation
    * CVE-2019-11763 (bmo#1584216)
      Incorrect HTML parsing results in XSS bypass technique
    * CVE-2019-11765 (bmo#1562582)
      Incorrect permissions could be granted to a website
    * CVE-2019-17000 (bmo#1441468)
      CSP bypass using object tag with data: URI
    * CVE-2019-17001 (bmo#1587976)
      CSP bypass using object tag when script-src 'none' is specified
    * CVE-2019-17002 (bmo#1561056)
      upgrade-insecure-requests was not being honored for links dragged and dropped
    * CVE-2019-11764 (bmo#1558522, bmo#1577061, bmo#1548044, bmo#1571223,
      bmo#1573048, bmo#1578933, bmo#1575217, bmo#1583684, bmo#1586845, bmo#1581950,
      bmo#1583463, bmo#1586599)
      Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2
  - requires
      rust/cargo >= 1.36
      NSPR >= 4.22
      NSS >= 3.46.1
      rust-cbindgen >= 0.9.1
  - removed obsolete patches
      mozilla-bmo1573381.patch
      mozilla-nestegg-big-endian.patch
* Sun Oct 13 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 69.0.3
    * Fixed Yahoo mail users being prompted to download files when
      clicking on emails (bmo#1582848)
  - devel package build can easily be disabled now
* Thu Oct 03 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 69.0.2
    * Fixed a crash when editing files on Office 365 websites (bmo#1579858)
    * Fixed a Linux-only crash when changing the playback speed while
      watching YouTube videos (bmo#1582222)
  - updated supported locale list
  - Allow to build without profile guided optimizations (boo#1040589)
    (contributed by Bernhard Wiedemann)
  - Make build verbose (contributed by Martin Liška)
  - remove obsolete kde.js setting (boo#1151186) and related patch
    firefox-add-kde.js-in-order-to-survive-PGO-build.patch
  - update create-tar.sh to latest revision and adjusted tar_stamps
  - add mozilla-fix-top-level-asm.patch to fix LTO build (w/o PGO)
  - extension preferences moved from branding package to core package
    (packaging but not branding specific)
* Thu Sep 19 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 69.0.1
    * Fixed external programs launching in the background when clicking
      a link from inside Firefox to launch them (bmo#1570845)
    * Usability improvements to the Add-ons Manager for users with
      screen readers (bmo#1567600)
    * Fixed the Captive Portal notification bar not being dismissable
      in some situations after login is complete (bmo#1578633)
    * Fixed the maximum size of fonts in Reader Mode when zoomed (bmo#1578454)
    * Fixed missing stacks in the Developer Tools Performance section
      (bmo#1578354)
    MFSA 2019-31
    * CVE-2019-11754 (bmo#1580506)
      Pointer Lock is enabled with no user notification
  - disable DOH by default
* Thu Sep 05 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 69.0
    * Enhanced Tracking Protection (ETP) for stronger privacy protections
    * Block Autoplay feature is enhanced to give users the option to block
      any video
    * Users in the US or using the en-US browser, can get a new “New Tab”
      page experience connecting to the best of Pocket's content.
    * Support for the Web Authentication HmacSecret extension via
      Windows Hello introduced.
    * Support for receiving multiple video codecs with this release makes
      it easier for WebRTC conferencing services to mix video from
      different clients.
    MFSA 2019-25 (boo#1149324)
    * CVE-2019-11741 (bmo#1539595)
      Isolate addons.mozilla.org and accounts.firefox.com
    * CVE-2019-5849 (bmo#1555838)
      Out-of-bounds read in Skia
    * CVE-2019-11737 (bmo#1388015)
      Content security policy directives ignore port and path if host is a wildcard
    * CVE-2019-11734 (bmo#1352875,bmo#1536227,bmo#1557208,bmo#1560641)
      Memory safety bugs fixed in Firefox 69
    * CVE-2019-11735 (bmo#1561404,bmo#1561484,bmo#1568047,bmo#1561912,
      bmo#1565744,bmo#1568858,bmo#1570358)
      Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1
    * CVE-2019-11740 (bmo#1563133,bmo#1573160)
      Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox ESR 60.9
  - requires
    * rust/cargo >= 1.35
    * rust-cbindgen >= 0.9.0
    * mozilla-nss >= 3.45
  - rebased patches
* Wed Sep 04 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - added a bunch of patches mainly for big endian platforms
    * mozilla-bmo1504834-part1.patch
    * mozilla-bmo1504834-part2.patch
    * mozilla-bmo1504834-part3.patch
    * mozilla-bmo1511604.patch
    * mozilla-bmo1554971.patch
    * mozilla-bmo1573381.patch
    * mozilla-nestegg-big-endian.patch
    * mozilla-bmo1512162.patch
* Fri Aug 30 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 68.1.0
    MFSA 2019-26
    * CVE-2019-11751 (bmo#1572838; Windows only)
      Malicious code execution through command line parameters
    * CVE-2019-11746 (bmo#1564449)
      Use-after-free while manipulating video
    * CVE-2019-11744 (bmo#1562033)
      XSS by breaking out of title and textarea elements using innerHTML
    * CVE-2019-11742 (bmo#1559715)
      Same-origin policy violation with SVG filters and canvas to steal
      cross-origin images
    * CVE-2019-11736 (bmo#1551913, bmo#1552206; Windows only))
      File manipulation and privilege escalation in Mozilla Maintenance Service
    * CVE-2019-11753 (bmo#1574980; Windows only)
      Privilege escalation with Mozilla Maintenance Service in custom
      Firefox installation location
    * CVE-2019-11752 (bmo#1501152)
      Use-after-free while extracting a key value in IndexedDB
    * CVE-2019-9812 (bmo#1538008, bmo#1538015)
      Sandbox escape through Firefox Sync
    * CVE-2019-11743 (bmo#1560495)
      Cross-origin access to unload event attributes
    * CVE-2019-11748 (bmo#1564588)
      Persistence of WebRTC permissions in a third party context
    * CVE-2019-11749 (bmo#1565374)
      Camera information available without prompting using getUserMedia
    * CVE-2019-11750 (bmo#1568397)
      Type confusion in Spidermonkey
    * CVE-2019-11738 (bmo#1452037)
      Content security policy bypass through hash-based sources in directives
    * CVE-2019-11747 (bmo#1564481)
      'Forget about this site' removes sites from pre-loaded HSTS list
    * CVE-2019-11735i (bmo#1561404,bmo#1561484,bmo#1568047,bmo#1561912,
      bmo#1565744,bmo#1568858,bmo#1570358)
      Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1
    * CVE-2019-11740 (bmo#1563133,bmo#1573160)
      Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox ESR 60.9
  - switched package to ESR branch
  - added mozilla-bmo1568145.patch to make builds reproducible
  - removed upstreamed patch mozilla-gcc-internal-compiler-error.patch
* Sun Aug 18 2019 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Firefox 68.0.2:
    * Fixed a bug causing some special characters to be cut off from
      the end of the search terms when searching from the URL bar
      (bmo#1560228)
    * Allow fonts to be loaded via file:// URLs when opening a page
      locally (bmo#1565942)
    * Printing emails from the Outlook web app no longer prints only
      the header and footer (bmo#1567105)
    * Fixed a bug causing some images not to be displayed on reload,
      including on Google Maps (bmo# 1565542)
    * Fixed an error when starting external applications configured
      as URI handlers (bmo#1567614)
    MFSA 2019-24 (boo#1145665)
    * CVE-2019-11733: Stored passwords in 'Saved Logins' can be
      copied without master password entry (bmo#1565780)
  - drop fix-build-after-y2038-changes-in-glibc.patch, upstream
* Fri Aug 16 2019 Jonathan Brielmaier <jbrielmaier@suse.de>
  - Fix crash when typing in the URL bar on ppc64le (bmo#1512162).
    The upstream patch doesn't resolve the issue on TW, but compiling
    with -O1 does. Do this until we have a proper fix.
* Thu Aug 01 2019 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Update build constraints to fix arm builds
* Fri Jul 19 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 68.0.1
    * Fixed missing Full Screen button when watching videos in full
      screen mode on HBO GO (bmo#1562837)
    * Fixed a bug causing incorrect messages to appear for some
      locales when sites try to request the use of the Storage
      Access API (bmo#1558503)
    * Users in Russian regions may have their default search engine
      changed (bmo#1565315)
    * Built-in search engines in some locales do not function
      correctly (bmo#1565779)
    * SupportMenu policy doesn't always work (bmo#1553290)
    * Allow the privacy.file_unique_origin pref to be controlled by
      policy (bmo#1563759)
* Thu Jul 11 2019 Jiri Slaby <jslaby@suse.com>
  - add fix-build-after-y2038-changes-in-glibc.patch
* Wed Jul 10 2019 Bernhard Wiedemann <bwiedemann@suse.com>
  - Generate langpacks sequentially to avoid file corruption
    from racy file writes (boo#1137970)
* Mon Jul 08 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 68.0
    * Dark mode in reader view
    * Improved extension security and discovery
    * Cryptomining and fingerprinting protections are added to strict
      content blocking settings in Privacy & Security preferences
    * Camera and microphone access now require an HTTPS connection
    MFSA 2019-21 (bsc#1140868)
    * CVE-2019-9811 (bmo#1538007, bmo#1539598, bmo#1563327)
      Sandbox escape via installation of malicious languagepack
    * CVE-2019-11711 (bmo#1552541)
      Script injection within domain through inner window reuse
    * CVE-2019-11712 (bmo#1543804)
      Cross-origin POST requests can be made with NPAPI plugins by
      following 308 redirects
    * CVE-2019-11713 (bmo#1528481)
      Use-after-free with HTTP/2 cached stream
    * CVE-2019-11714 (bmo#1542593)
      NeckoChild can trigger crash when accessed off of main thread
    * CVE-2019-11729 (bmo#1515342)
      Empty or malformed p256-ECDH public keys may trigger a segmentation fault
    * CVE-2019-11715 (bmo#1555523)
      HTML parsing error can contribute to content XSS
    * CVE-2019-11716 (bmo#1552632)
      globalThis not enumerable until accessed
    * CVE-2019-11717 (bmo#1548306)
      Caret character improperly escaped in origins
    * CVE-2019-11718 (bmo#1408349)
      Activity Stream writes unsanitized content to innerHTML
    * CVE-2019-11719 (bmo#1540541)
      Out-of-bounds read when importing curve25519 private key
    * CVE-2019-11720 (bmo#1556230)
      Character encoding XSS vulnerability
    * CVE-2019-11721 (bmo#1256009)
      Domain spoofing through unicode latin 'kra' character
    * CVE-2019-11730 (bmo#1558299)
      Same-origin policy treats all files in a directory as having the
      same-origin
    * CVE-2019-11723 (bmo#1528335)
      Cookie leakage during add-on fetching across private browsing boundaries
    * CVE-2019-11724 (bmo#1512511)
      Retired site input.mozilla.org has remote troubleshooting permissions
    * CVE-2019-11725 (bmo#1483510)
      Websocket resources bypass safebrowsing protections
    * CVE-2019-11727 (bmo#1552208)
      PKCS#1 v1.5 signatures can be used for TLS 1.3
    * CVE-2019-11728 (bmo#1552993)
      Port scanning through Alt-Svc header
    * CVE-2019-11710 (bmo#1549768, bmo#1548611, bmo#1533842, bmo#1537692,
      bmo#1540590, bmo#1551907, bmo#1510345, bmo#1535482, bmo#1535848,
      bmo#1547472, bmo#1547760, bmo#1507696, bmo#1544180)
      Memory safety bugs fixed in Firefox 68
    * CVE-2019-11709 (bmo#1547266, bmo#1540759, bmo#1548822, bmo#1550498
      bmo#1515052, bmo#1539219, bmo#1547757, bmo#1550498, bmo#1533522)
      Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8
  - requires
    * NSS 3.44.1
    * rust/cargo 1.34
    * rust-cbindgen 0.8.7
  - rebased patches
    * mozilla-aarch64-startup-crash.patch
    * mozilla-kde.patch
    * mozilla-nongnome-proxies.patch
    * firefox-kde.patch
  - use new create-tar.sh and add tar_stamps for package definitions
  - added patches imported from SLE flavour
    * mozilla-gcc-internal-compiler-error.patch
    * mozilla-bmo1005535.patch
    * mozilla-ppc-altivec_static_inline.patch
    * mozilla-reduce-rust-debuginfo.patch
    * mozilla-s390-bigendian.patch
    * mozilla-s390-context.patch
* Tue Jul 02 2019 Martin Liška <mliska@suse.cz>
  - Enable PGO for x86_64.
    * added firefox-add-kde.js-in-order-to-survive-PGO-build.patch
* Thu Jun 20 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 67.0.4
    MFSA 2019-19 (boo#1138872)
    * CVE-2019-11708 (bmo#1559858)
      sandbox escape using Prompt:Open
* Tue Jun 18 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 67.0.3
    MFSA 2019-18 (boo#1138614)
    * CVE-2019-11707 (bmo#1544386)
      Type confusion in Array.pop
* Wed Jun 12 2019 Manfred Hollstein <manfred.h@gmx.net>
  - Mozilla Firefox 67.0.2
    * Fixed: Fix JavaScript error ("TypeError: data is null in
      PrivacyFilter.jsm") in console which may significantly degrade
      sessionstore reliability and performance (bmo#1553413)
    * Fixed: Proxy authentication dialog box repeatedly pops up
      asking to authenticate after upgrading to Firefox 67 (bmo#1548804)
    * Fixed: Pearson MyCloud breaks if FIDO U2F is not Chrome's
      implementation (bmo#1551282)
    * Fixed: Starting in safe mode on Linux or macOS causes Firefox
      to think on the subsequent launch that the profile is too
      recent to be used with this version of Firefox (bmo#1556612)
    * Fixed: Linux distribution users can't easily install/use
      additional/different languages using the built-in preferences
      UI (bmo#1554744)
    * Fixed: Developer tools users can't copy the href/src content
      from various HTML tags via the context menu in the Inspector
      markup view (bmo#1552275)
    * Fixed: Custom home page is broken with clearing data on shutdown
      settings applied (bmo#1554167)
    * Fixed: Performance-regression for eclipse RAP based applications
      (bmo#1555962)
    * Fixed: macOS 10.15 crash fix (bmo#1556076)
    * Fixed: Can't start two downloads in parallel via <a download>
      anymore (bmo#1542912)
* Thu Jun 06 2019 Manfred Hollstein <manfred.h@gmx.net>
  - Mozilla Firefox 67.0.1
    * enable enhanced tracking protection by default for new users
    * upgrade of Facebook container to version 2.0
    * new version of Firefox Lockwise (password management)
    * new version of Firefox Monitor
    * Firefox Send improvements
* Sun May 19 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 67.0
    * Firefox 67 will be able to run different Firefox installs side by side
      https://blog.nightly.mozilla.org/2019/01/14/moving-to-a-profile-per-install-architecture/
    * Tabs can now be pinned from the Page Actions menu in the address bar
    * Users can block known cryptominers and fingerprinters in the
      Custom settings or their Content Blocking preferences
    * The Import Data from Another Browser feature is now also available
      from the File menu
    * Firefox will now protect you against running older versions which
      can lead to data corruption and stability issues
    * Easier access to your list of saved logins from the main menu and
      login autocomplete
    * We’ve added a toolbar menu for your Firefox Account to provide more
      transparency for when you are synced, sharing data across devices
      and with Firefox. Personalize the appearance of the menu with your
      own avatar
    * Enable FIDO U2F API, and permit registrations for Google Accounts
    * Enabled AV1 support on Linux
    MFSA 2019-13 (boo#1135824)
    * CVE-2019-9815 (bmo#1546544)
      Disable hyperthreading on content JavaScript threads on macOS
    * CVE-2019-9816 (bmo#1536768)
      Type confusion with object groups and UnboxedObjects
    * CVE-2019-9817 (bmo#1540221)
      Stealing of cross-domain images using canvas
    * CVE-2019-9818 (bmo#1542581) (Windows only)
      Use-after-free in crash generation server
    * CVE-2019-9819 (bmo#1532553)
      Compartment mismatch with fetch API
    * CVE-2019-9820 (bmo#1536405)
      Use-after-free of ChromeEventHandler by DocShell
    * CVE-2019-9821 (bmo#1539125)
      Use-after-free in AssertWorkerThread
    * CVE-2019-11691 (bmo#1542465)
      Use-after-free in XMLHttpRequest
    * CVE-2019-11692 (bmo#1544670)
      Use-after-free removing listeners in the event listener manager
    * CVE-2019-11693 (bmo#1532525)
      Buffer overflow in WebGL bufferdata on Linux
    * CVE-2019-7317 (bmo#1542829)
      Use-after-free in png_image_free of libpng library
    * CVE-2019-11694 (bmo#1534196) (Windows only)
      Uninitialized memory memory leakage in Windows sandbox
    * CVE-2019-11695 (bmo#1445844)
      Custom cursor can render over user interface outside of web content
    * CVE-2019-11696 (bmo#1392955)
      Java web start .JNLP files are not recognized as executable files
      for download prompts
    * CVE-2019-11697 (bmo#1440079)
      Pressing key combinations can bypass installation prompt delays and
      install extensions
    * CVE-2019-11698 (bmo#1543191)
      Theft of user history data through drag and drop of hyperlinks
      to and from bookmarks
    * CVE-2019-11700 (bmo#1549833) (Windows only)
      res: protocol can be used to open known local files
    * CVE-2019-11699 (bmo#1528939)
      Incorrect domain name highlighting during page navigation
    * CVE-2019-11701 (bmo#1518627)
      webcal: protocol default handler loads vulnerable web page
    * CVE-2019-9814 (bmo#1527592, bmo#1534536, bmo#1520132, bmo#1543159,
      bmo#1539393, bmo#1459932, bmo#1459182, bmo#1516425)
      Memory safety bugs fixed in Firefox 67
    * CVE-2019-9800 (bmo#1540166, bmo#1534593, bmo#1546327, bmo#1540136,
      bmo#1538736, bmo#1538042, bmo#1535612, bmo#1499719, bmo#1499108,
      bmo#1538619, bmo#1535194, bmo#1516325, bmo#1542324, bmo#1542097,
      bmo#1532465, bmo#1533554, bmo#1541580)
      Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7
  - requires
    * rust/cargo >= 1.32
    * mozilla-nspr >= 4.21
    * mozilla-nss >= 3.43
    * rust-cbindgen >= 0.8.2
  - rebased patches
  - KDE integration for default browser detection is broken in this revision
* Fri May 17 2019 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Fix armv7 build with:
    * mozilla-disable-wasm-emulate-arm-unaligned-fp-access.patch
* Fri May 10 2019 Manfred Hollstein <manfred.h@gmx.net>
  - Mozilla Firefox 66.0.5
    * Fixed: Further improvements to re-enable web extensions which
      had been disabled for users with a master password set (bmo#1549249)
* Sun May 05 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 66.0.4 (boo#1134126)
    * fix extension certificate chain
      https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-firefox/
* Thu Apr 11 2019 Manfred Hollstein <manfred.h@gmx.net>
  - Mozilla Firefox 66.0.3
    * Fixed: Address bar on tablets running Windows 10 now behaves
      correctly (bmo#1498973)
    * Fixed: Performance issues with some HTML5 games (bmo#1537609)
    * Fixed a bug with keypress events in IBM cloud applications
      (bmo#1538970)
    * Fix for keypress events in some Microsoft cloud applications
      (bmo#1539618)
    * Changed: Updated Baidu search plugin
* Thu Mar 28 2019 Manfred Hollstein <manfred.h@gmx.net>
  - Mozilla Firefox 66.0.2
    * Fixed Web compatibility issues with Office 365, iCloud and
      IBM WebMail caused by recent changes to the handling of
      keyboard events (bmo#1538966)
    * Crash fixes (bmo#1521370, bmo#1539118)
* Thu Mar 28 2019 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Add patch to fix aarch64 build:
    * mozilla-fix-aarch64-libopus.patch (bmo#1539737)
* Fri Mar 22 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 66.0.1
    MFSA 2019-09 (bsc#1130262)
    * CVE-2019-9810 (bmo#1537924)
      IonMonkey MArraySlice has incorrect alias information
    * CVE-2019-9813 (bmo#1538006)
      Ionmonkey type confusion with __proto__ mutations
* Sun Mar 17 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 66.0
    * Increased content processes to 8
    * Added capability to search through open tabs from the tab overflow menu
    * New backend for the storage.local WebExtensions API, providing
      I/O performance improvements when the extension updates a small
      subset of the stored data
    * WebExtension keyboard shortcuts can now be managed or overridden
      from about:addons
    * Improved scrolling behavior: Firefox will now attempt to keep content
      from jumping around while a page is loading by supporting scroll
      anchoring
    * New about:privatebrowsing with search
    * A certificate error page now notifies the user of the name of the
      certificate issuer that breaks HTTPs connections on intercepted
      connections to help troubleshooting possible anti-virus software
      issues.
    * Fixed an performance issue some Linux users experienced with the
      Downloads panel (bmo#1517101)
    * Firefox now blocks all autoplay media with sound by default. Users
      can add individual sites to an exceptions list or turn the blocking
      off.
    * System title bar is hidden by default to match Gnome guideline
    MFSA 2019-07 (bsc#1129821)
    * CVE-2019-9790 (bmo#1525145)
      Use-after-free when removing in-use DOM elements
    * CVE-2019-9791 (bmo#1530958)
      Type inference is incorrect for constructors entered through on-stack
      replacement with IonMonkey
    * CVE-2019-9792 (bmo#1532599)
      IonMonkey leaks JS_OPTIMIZED_OUT magic value to script
    * CVE-2019-9793 (bmo#1528829)
      Improper bounds checks when Spectre mitigations are disabled
    * CVE-2019-9794 (bmo#1530103) (Windows only)
      Command line arguments not discarded during execution
    * CVE-2019-9795 (bmo#1514682)
      Type-confusion in IonMonkey JIT compiler
    * CVE-2019-9796 (bmo#1531277)
      Use-after-free with SMIL animation controller
    * CVE-2019-9797 (bmo#1528909)
      Cross-origin theft of images with createImageBitmap
    * CVE-2019-9798 (bmo#1527534) (Android only)
      Library is loaded from world writable APITRACE_LIB location
    * CVE-2019-9799 (bmo#1505678)
      Information disclosure via IPC channel messages
    * CVE-2019-9801 (bmo#1527717) (Windows only)
      Windows programs that are not 'URL Handlers' are exposed to web content
    * CVE-2019-9802 (bmo#1415508)
      Chrome process information leak
    * CVE-2019-9803 (bmo#1515863, bmo#1437009)
      Upgrade-Insecure-Requests incorrectly enforced for same-origin navigation
    * CVE-2019-9804 (bmo#1518026) (MacOS only)
      Code execution through 'Copy as cURL' in Firefox Developer Tools on macOS
    * CVE-2019-9805 (bmo#1521360)
      Potential use of uninitialized memory in Prio
    * CVE-2019-9806 (bmo#1525267)
      Denial of service through successive FTP authorization prompts
    * CVE-2019-9807 (bmo#1362050)
      Text sent through FTP connection can be incorporated into alert messages
    * CVE-2019-9809 (bmo#1282430, bmo#1523249)
      Denial of service through FTP modal alert error messages
    * CVE-2019-9808 (bmo#1434634)
      WebRTC permissions can display incorrect origin with data: and blob: URLs
    * CVE-2019-9789 bmo#1520483, bmo#1522987, bmo#1528199, bmo#1519337,
      bmo#1525549, bmo#1516179, bmo#1518524, bmo#1518331, bmo#1526579,
      bmo#1512567, bmo#1524335, bmo#1448505, bmo#1518821
      Memory safety bugs fixed in Firefox 66
    * CVE-2019-9788 bmo#1518001, bmo#1521304, bmo#1521214, bmo#1506665,
      bmo#1516834, bmo#1518774, bmo#1524755, bmo#1523362, bmo#1524214, bmo#1529203
      Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6
  - updated build/runtime requirements
    * mozilla-nss >= 3.42.1
    * cargo/rust >= 1.31
    * rust-cbindgen >= 0.6.8
    * nasm >= 2.13 (new)
  - removed obsolete patch
    * mozilla-bmo256180.patch
* Tue Mar 05 2019 Stephan Kulow <coolo@suse.com>
  - Do not hardcode nodejs8 but leave the prefer to the distribution
    (Tumbleweed staging wants to switch to nodejs10)
* Fri Feb 15 2019 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Update _constraints to avoid 'no space left' error seen on aarch64
* Wed Feb 13 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 65.0.1
    * Fixed accidental requests to addons.mozilla.org when an addon
      recommendation doorhanger is shown (bmo#1526387)
    * Improved playback of interactive Netflix videos (bmo#1524500)
    * Fixed incorrect sizing of the "Clear Recent History" window in
      some situations (bmo#1523696)
    * Fixed audio & video delays while making WebRTC calls
      (bmo#1521577, bmo#1523817)
    * Fixed video sizing problems during some WebRTC calls (bmo#1520200)
    * Fixed looping CONNECT requests when using WebSockets over HTTP/2
      from behind a proxy server (bmo#1523427)
    * Fixed the "Enter" key not working on password entry fields for
      certain Linux distributions (bmo#1523635)
    MFSA 2019-04 (bsc#1125330)
    * CVE-2018-18356 bmo#1525817
      Use-after-free in Skia
    * CVE-2019-5785 bmo#1525433
      Integer overflow in Skia
    * CVE-2018-18511 bmo#1526218
      Cross-origin theft of images with ImageBitmapRenderingContext
* Wed Feb 13 2019 Martin Liška <mliska@suse.cz>
  - Enable LTO only for latest new toolchain (boo#1125038) for x86_64
    (with increased memory constraints)
* Sat Jan 26 2019 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Firefox 65.0
    * Enhanced tracking protection
    * allow switching of UI locales within preferences
    * support for the WebP image format
    * "top"-like about:performance
    MFSA 2019-01 (bsc#1122983)
    * CVE-2018-18500 bmo#1510114
      Use-after-free parsing HTML5 stream
    * CVE-2018-18503 bmo#1509442
      Memory corruption with Audio Buffer
    * CVE-2018-18504 bmo#1496413
      Memory corruption and out-of-bounds read of texture client
    * CVE-2018-18505 bmo#1497749
      Privilege escalation through IPC channel messages
    * CVE-2018-18506 bmo#1503393
      Proxy Auto-Configuration file can define localhost access to be proxied
    * CVE-2018-18502 bmo#1499426 bmo#1480090 bmo#1472990 bmo#1514762
      bmo#1501482 bmo#1505887 bmo#1508102 bmo#1508618 bmo#1511580
      bmo#1493497 bmo#1510145 bmo#1516289 bmo#1506798 bmo#1512758
      Memory safety bugs fixed in Firefox 65
    * CVE-2018-18501 bmo#1512450 bmo#1517542 bmo#1513201 bmo#1460619
      bmo#1502871 bmo#1516738 bmo#1516514
      Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5
  - requires
    NSS 3.41
    rust/carge 1.30
    rust-cbindgen 0.6.7
  - rebased patches
  - remove workaround for build memory consumption on i586; other
    mitigations meanwhile introduced (mainly parallelity) will be
    sufficient
    mozilla-reduce-files-per-UnifiedBindings.patch
* Tue Jan 15 2019 Martin Liška <mliska@suse.cz>
  - Increase disk constraint.
* Mon Jan 14 2019 Martin Liška <mliska@suse.cz>
  - Remove -v from mach build in order to work-around bmo#1500436.
* Fri Jan 11 2019 Martin Liška <mliska@suse.cz>
  - Set %clang_build to false on all architectures
  - Do not use -fno-delete-null-pointer-checks and -fno-strict-aliasing:
    it should not be needed anymore
  - Do not overwrite enable-optimize and when possible
    enable --enable-debug-symbols.
  - Add -v to mach in order to make build verbose.
* Wed Jan 09 2019 astieger@suse.com
  - Mozilla Firefox 64.0.2:
    * Update the Japanese translation for missing strings (bmo#1513259)
    * Properly restore column sizes in developer tools inspector (bmo#1503175)
    * Fixed video stuttering on Youtube (bmo#1513511)
    * Fix updates for some lightweight themes (bmo#1508777)
* Tue Dec 18 2018 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Enable build_hardened for all architectures
  - Switch back aarch64 to clang as '-fPIC' fixes bmo#1513605
  - Remove obolete '--enable-pie' as -pie is always enabled for
    gcc and clang
* Wed Dec 12 2018 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Switch aarch64 builds back to gcc, not clang (bmo#1513605)
  - Switch %arm builds back to gcc, not clang to avoid OOM
  - Fix build flags when clang is not used
  - Fix flags for clang ppc64 builds
* Tue Dec 11 2018 Wolfgang Rosenauer <wr@rosenauer.org>
  - update to Firefox 64.0
    * Better recommendations: You may see suggestions in regular browsing
      mode for new and relevant Firefox features, services, and extensions
      based on how you use the web (for US users only)
    * Enhanced tab management: You can now select multiple tabs from the
      tab bar and close, move, bookmark, or pin them quickly and easily
    * Easier performance management: The new Task Manager page found at
      about:performance lets you see how much energy each open tab consumes
      and provides access to close tabs to conserve power
    * Improved performance for Mac and Linux users, by enabling link time
      optimization (Clang LTO).
    * Added option to remove add-ons using the context menu on their
      toolbar buttons
    * RSS feed preview and live bookmarks are available only via add-ons
    * TLS certificates issued by Symantec are no longer trusted by Firefox.
      Website operators are strongly encouraged to replace any remaining
      Symantec TLS certificates as soon as possible
    MFSA 2018-29 (bsc#1119105)
    * CVE-2018-12407 bmo#1505973
      Buffer overflow with ANGLE library when using VertexBuffer11 module
    * CVE-2018-17466 bmo#1488295
      Buffer overflow and out-of-bounds read in ANGLE library with
      TextureStorage11
    * CVE-2018-18492 bmo#1499861
      Use-after-free with select element
    * CVE-2018-18493 bmo#1504452
      Buffer overflow in accelerated 2D canvas with Skia
    * CVE-2018-18494 bmo#1487964
      Same-origin policy violation using location attribute and
      performance.getEntries to steal cross-origin URLs
    * CVE-2018-18495 bmo#1427585
      WebExtension content scripts can be loaded in about: pages
    * CVE-2018-18496 bmo#1422231 (Windows only)
      Embedded feed preview page can be abused for clickjacking
    * CVE-2018-18497 bmo#1488180
      WebExtensions can load arbitrary URLs through pipe separators
    * CVE-2018-18498 bmo#1500011
      Integer overflow when calculating buffer sizes for images
    * CVE-2018-12406 bmo#1456947 bmo#1475669 bmo#1504816 bmo#1502886
      bmo#1500064 bmo#1500310 bmo#1500696 bmo#1498765 bmo#1499198 bmo#1434490
      bmo#1481745 bmo#1458129
      Memory safety bugs fixed in Firefox 64
    * CVE-2018-12405 bmo#1494752 bmo#1503326 bmo#1505181 bmo#1500759
      bmo#1504365 bmo#1506640 bmo#1503082 bmo#1502013 bmo#1510471
      Memory safety bugs fixed in Firefox 64 and Firefox ESR 60.4
  - requires
    * rust/cargo >= 1.29
    * mozilla-nss >= 3.40.1
    * rust-cbindgen >= 0.6.4
  - rebased patches
  - removed obsolete patch
    * mozilla-bmo1491289.patch
  - now uses clang primarily for compilation
* Wed Nov 28 2018 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Remove --disable-elf-hack when not available: on aarch64 and ppc64*
* Mon Nov 26 2018 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Clean-up %arm build
* Sun Nov 18 2018 manfred.h@gmx.net
  - update to Firefox 63.0.3
    * Games using WebGL (created in Unity) get stuck after very short
      time of gameplay (bmo#1502748)
    * Slow page loading for some users with specific proxy configurations
      (bmo#1495024)
    * Disable HTTP response throttling by default for causing bugs with
      videos in background tabs (bmo#1503354)
    * Opening magnet links no longer works (bmo#1498934)
    * Crash fixes (bmo#1498510, bmo#1503424)
  - removed mozilla-newer-cbindgen.patch; no longer needed
* Thu Nov 08 2018 wr@rosenauer.org
  - update to Firefox 63.0.1
    * Snippets are not loaded due to missing element (bmo#1503047)
    * Print preview always shows 30& scale when it is actually
      Shrink To Fit (bmo#1501952)
    * Dialog displayed when closing multiple windows shows unreplaced
      %1$S placeholder in Japanese and potentially other locales
      (bmo#1500823)
* Mon Oct 29 2018 wr@rosenauer.org
  - update to Firefox 63.0
    * WebExtensions now run in their own process on Linux
    * The Ctrl+Tab shortcut now displays thumbnail previews of your
      tabs and cycles through tabs in recently used order. This new
      default behavior is activated only in new profiles and can be
      changed in preferences.
    * Added support for Web Components custom elements and shadow DOM
    MFSA 2018-26 (bsc#1112852)
    * CVE-2018-12391 (bmo#1478843) (Android-only)
      HTTP Live Stream audio data is accessible cross-origin
    * CVE-2018-12392 (bmo#1492823)
      Crash with nested event loops
    * CVE-2018-12393 (bmo#1495011) (only affects non-64-bit archs)
      Integer overflow during Unicode conversion while loading JavaScript
    * CVE-2018-12395 (bmo#1467523)
      WebExtension bypass of domain restrictions through header rewriting
    * CVE-2018-12396 (bmo#1483602)
      WebExtension content scripts can execute in disallowed contexts
    * CVE-2018-12397 (bmo#1487478)
      Missing warning prompt when WebExtension requests local file access
    * CVE-2018-12398 (bmo#1460538, bmo#1488061)
      CSP bypass through stylesheet injection in resource URIs
    * CVE-2018-12399 (bmo#1490276)
      Spoofing of protocol registration notification bar
    * CVE-2018-12400 (bmo#1448305) (Android only)
      Favicons are cached in private browsing mode on Firefox for Android
    * CVE-2018-12401 (bmo#1422456)
      DOS attack through special resource URI parsing
    * CVE-2018-12402 (bmo#1469916)
      SameSite cookies leak when pages are explicitly saved
    * CVE-2018-12403 (bmo#1484753)
      Mixed content warning is not displayed when HTTPS page loads a favicon over HTTP
    * CVE-2018-12388 (bmo#1472639, bmo#1485698, bmo#1301547, bmo#1471427,
      bmo#1379411, bmo#1482122, bmo#1486314, bmo#1487167)
      Memory safety bugs fixed in Firefox 63
    * CVE-2018-12390 (bmo#1487098, bmo#1487660, bmo#1490234, bmo#1496159,
      bmo#1443748, bmo#1496340, bmo#1483905, bmo#1493347, bmo#1488803,
      bmo#1498701, bmo#1498482, bmo#1442010, bmo#1495245, bmo#1483699,
      bmo#1469486, bmo#1484905, bmo#1490561, bmo#1492524, bmo#1481844)
      Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3
  - requires NSPR 4.20, NSS 3.39 and Rust 1.28
  - latest rust does not provide rust-std so stop requiring it
  - requires rust-cbindgen >= 0.6.2 to build
  - requires nodejs >= 8.11 to build
  - added mozilla-bmo1491289.patch to fix system NSS build (bmo#1491289)
  - added mozilla-cubeb-noreturn.patch to fix non-return function
  - added mozilla-newer-cbindgen.patch to fix build with cbindgen 0.6.7
  - disable elfhack for TW and newer due to build errors
  - removed obsolete patches
    * mozilla-no-return.patch
    * mozilla-no-stdcxx-check.patch
* Thu Oct 25 2018 guillaume.gardet@opensuse.org
  - Update _constraints for armv6/7
* Thu Oct 25 2018 guillaume.gardet@opensuse.org
  - Add patch to fix build on armv7:
    * mozilla-bmo1463035.patch
* Tue Oct 02 2018 astieger@suse.com
  - Mozilla Firefox 62.0.3:
    MFSA 2018-24
    * CVE-2018-12386 (bsc#1110506, bmo#1493900)
      Type confusion in JavaScript allowed remote code execution
    * CVE-2018-12387 (bsc#1110507, bmo#1493903)
      Array.prototype.push stack pointer vulnerability may enable
      exploits in the sandboxed content process
* Sat Sep 22 2018 astieger@suse.com
  - Mozilla Firefox 62.0.2:
    MFSA 2018-22
    * CVE-2018-12385 (boo#1109363, bmo#1490585)
      Crash in TransportSecurityInfo due to cached data
    * Unvisited bookmarks can once again be autofilled in the address
      bar
    * Fix WebGL rendering issues
    * Fix fallback on startup when a language pack is missing
    * Avoid crash when sharing a profile with newer (as yet
      unreleased) versions of Firefox
    * Do not undo removal of search engines when using a language
      pack
    * Fixed rendering of some web sites
    * Restored compatibility with some sites using deprecated TLS
      settings
  - disable rust debug symbols to fix build on %ix86
* Mon Sep 03 2018 wr@rosenauer.org
  - update to Firefox 62.0
    * Firefox Home (the default New Tab) now allows users to display
      up to 4 rows of top sites, Pocket stories, and highlights
    * "Reopen in Container" tab menu option appears for users with
      Containers that lets them choose to reopen a tab in a different
      container
    * In advance of removing all trust for Symantec-issued certificates
      in Firefox 63, a preference was added that allows users to distrust
      certificates issued by Symantec. To use this preference, go to
      about:config in the address bar and set the preference
      "security.pki.distrust_ca_policy" to 2.
    * Support for CSS Shapes, allowing for richer web page layouts.
      This goes hand in hand with a brand new Shape Path Editor in the
      CSS inspector.
    * CSS Variable Fonts (OpenType Font Variations) support, which makes
      it possible to create beautiful typography with a single font file
    * Added Canadian English (en-CA) locale
    MFSA 2018-20 (bsc#1107343)
    * CVE-2018-12377 (bmo#1470260)
      Use-after-free in refresh driver timers
    * CVE-2018-12378 (bmo#1459383)
      Use-after-free in IndexedDB
    * CVE-2018-12379 (bmo#1473113) (updater is disabled for us)
      Out-of-bounds write with malicious MAR file
    * CVE-2017-16541 (bmo#1412081)
      Proxy bypass using automount and autofs
    * CVE-2018-12381 (bmo#1435319)
      Dragging and dropping Outlook email message results in page navigation
    * CVE-2018-12382 (bmo#1479311) (Android only)
      Addressbar spoofing with javascript URI on Firefox for Android
    * CVE-2018-12383 (bmo#1475775)
      Setting a master password post-Firefox 58 does not delete
      unencrypted previously stored passwords
    * CVE-2018-12375
      Memory safety bugs fixed in Firefox 62
    * CVE-2018-12376
      Memory safety bugs fixed in Firefox 62 and Firefox ESR 60.2
  - requires NSS >= 3.38
  - removed obsolete patch
    mozilla-bmo1464766.patch
* Thu Aug 09 2018 wr@rosenauer.org
  - update to Firefox 61.0.2
    * Improved website rendering with the Retained Display List feature
      enabled (bmo#1474402)
    * Fixed broken DevTools panels with certain extensions installed
      (bmo#1474379)
    * Fixed a crash for users with some accessibility tools enabled
      (bmo#1474007)
* Mon Jul 09 2018 astieger@suse.com
  - Mozilla Firefox 61.0.1:
    * Fix missing content on the New Tab Page and the Home section of
      the Preferences page (bmo#1471375)
    * Fixed loss of bookmarks under rare circumstances when upgrading
      from Firefox 60 (bmo#1472127)
    * Improved playback of Twitch 1080p video streams (bmo#1469257)
    * Web pages no longer lose focus when a browser popup window is
      opened (bmo#1471415)
    * Re-allowed downloading files from FTP sites via the "Save Link
      As" option when linked from HTTP pages (bmo#1470295)
    * Fixed extensions being unable to override the default homepage
      in certain situations (bmo#1466846)
* Sat Jun 23 2018 wr@rosenauer.org
  - update to Firefox 61.0
    * Performance enhancements
    * Various improvements for dark theme support will provide a more
      consistent experience across the entire Firefox UI
    * OpenSearch plugins offered by web pages can now be added from the
      page action menu for easier installation
    * Improved support for allowing WebExtensions to manage and hide tabs
    MFSA 2018-15 (bsc#1098998)
    * CVE-2018-12359 (bmo#1459162)
      Buffer overflow using computed size of canvas element
    * CVE-2018-12360 (bmo#1459693)
      Use-after-free when using focus()
    * CVE-2018-12361 (bmo#1463244)
      Integer overflow in SwizzleData
    * CVE-2018-12358 (bmo#1467852)
      Same-origin bypass using service worker and redirection
    * CVE-2018-12362 (bmo#1452375)
      Integer overflow in SSSE3 scaler
    * CVE-2018-5156 (bmo#1453127)
      Media recorder segmentation fault when track type is changed during capture
    * CVE-2018-12363 (bmo#1464784)
      Use-after-free when appending DOM nodes
    * CVE-2018-12364 (bmo#1436241)
      CSRF attacks through 307 redirects and NPAPI plugins
    * CVE-2018-12365 (bmo#1459206)
      Compromised IPC child process can list local filenames
    * CVE-2018-12371 (bmo#1465686)
      Integer overflow in Skia library during edge builder allocation
    * CVE-2018-12366 (bmo#1464039)
      Invalid data handling during QCMS transformations
    * CVE-2018-12367 (bmo#1462891)
      Timing attack mitigation of PerformanceNavigationTiming
    * CVE-2018-12369 (bmo#1454909)
      WebExtension security permission checks bypassed by embedded experiments
    * CVE-2018-12370 (bmo#1456652)
      SameSite cookie protections bypassed when exiting Reader View
    * CVE-2018-5186 (bmo#1464872,bmo#1463329,bmo#1419373,bmo#1412882,
      bmo#1413033,bmo#1444673,bmo#1454448,bmo#1453505,bmo#1438671)
      Memory safety bugs fixed in Firefox 61
    * CVE-2018-5187 (bmo#1461324,bmo#1414829,bmo#1395246,bmo#1467938,
      bmo#1461619,bmo#1425930,bmo#1438556,bmo#1454285,bmo#1459568,
      bmo#1463884)
      Memory safety bugs fixed in Firefox 60 and Firefox ESR 60.1
    * CVE-2018-5188 (bmo#1456189,bmo#1456975,bmo#1465898,bmo#1392739,
      bmo#1451297,bmo#1464063,bmo#1437842,bmo#1442722,bmo#1452576,
      bmo#1450688,bmo#1458264,bmo#1458270,bmo#1465108,bmo#1464829,
      bmo#1464079,bmo#1463494,bmo#1458048)
      Memory safety bugs fixed in Firefox 60, Firefox ESR 60.1, and Firefox ESR 52.9
  - requires NSS 3.37.3
  - requires python >= 3.5 to build
  - removed obsolete patches
    mozilla-i586-DecoderDoctorLogger.patch
    mozilla-i586-domPrefs.patch
    mozilla-fix-skia-aarch64.patch
    mozilla-bmo1375074.patch
    mozilla-enable-csd.patch
  - patch for new no-return warnings (mozilla-no-return.patch)
  - do not disable system installed locales (mozilla-bmo1464766.patch)
* Fri Jun 08 2018 bjorn.lie@gmail.com
  - Add conditional for pkgconfig(gconf-2.0) BuildRequires, and pass
    conditional --disable-gconf to configure: no longer pull in
    obsolete gconf2 for Tumbleweed.
* Thu Jun 07 2018 wr@rosenauer.org
  - update to Firefox 60.0.2
    * requires NSS 3.36.4
    MFSA 2018-14 (bsc#1096449)
    * CVE-2018-6126 (bmo#1462682)
      Heap buffer overflow rasterizing paths in SVG with Skia
* Wed Jun 06 2018 guillaume.gardet@opensuse.org
  - Add upstream patch to fix boo#1093059 instead of '-ffixed-x28'
    workaround:
    * mozilla-bmo1375074.patch
* Sat May 26 2018 wr@rosenauer.org
  - fixed "open with" option under KDE (boo#1094747)
  - workaround crash on startup on aarch64 (boo#1093059)
    (contributed by guillaume.gardet@arm.com)
* Wed May 23 2018 guillaume.gardet@opensuse.org
  - Disable webrtc for aarch64 due to bmo#1434589
  - Add patch to fix skia build on AArch64:
    * mozilla-fix-skia-aarch64.patch
* Thu May 17 2018 wr@rosenauer.org
  - update to Firefox 60.0.1
    * Avoid overly long cycle collector pauses with some add-ons installed
      (bmo#1449033)
    * After unckecking the "Sponsored Stories" option, the New Tab page
      now immediately stops displaying "Sponsored content" cards (bmo#1458906)
    * On touchscreen devices, fixed momentum scrolling on non-zoomable pages
      (bmo#1457743)
    * Use the right default background when opening tabs or windows in
      high contrast mode (bmo#1458956)
    * Restored translations of the Preferences panels when using a
      language pack (bmo#1461590)
* Mon May 14 2018 pcerny@suse.com
  - parellelise locales building
* Mon May 07 2018 wr@rosenauer.org
  - update to Firefox 60.0
    * Added a policy engine that allows customized Firefox deployments
      in enterprise environments, using Windows Group Policy or a
      cross-platform JSON file
    * Applied Quantum CSS to render browser UI
    * Added support for Web Authentication, allowing the use of USB
      tokens for authentication to web sites
    * Locale added: Occitan (oc)
    MFSA 2018-11 (bsc#1092548)
    * CVE-2018-5154 (bmo#1443092)
      Use-after-free with SVG animations and clip paths
    * CVE-2018-5155 (bmo#1448774)
      Use-after-free with SVG animations and text paths
    * CVE-2018-5157 (bmo#1449898)
      Same-origin bypass of PDF Viewer to view protected PDF files
    * CVE-2018-5158 (bmo#1452075)
      Malicious PDF can inject JavaScript into PDF Viewer
    * CVE-2018-5159 (bmo#1441941)
      Integer overflow and out-of-bounds write in Skia
    * CVE-2018-5160 (bmo#1436117)
      Uninitialized memory use by WebRTC encoder
    * CVE-2018-5152 (bmo#1415644, bmo#1427289)
      WebExtensions information leak through webRequest API
    * CVE-2018-5153 (bmo#1436809)
      Out-of-bounds read in mixed content websocket messages
    * CVE-2018-5163 (bmo#1426353)
      Replacing cached data in JavaScript Start-up Bytecode Cache
    * CVE-2018-5164 (bmo#1416045)
      CSP not applied to all multipart content sent with
      multipart/x-mixed-replace
    * CVE-2018-5166 (bmo#1437325)
      WebExtension host permission bypass through filterReponseData
    * CVE-2018-5167 (bmo#1447969)
      Improper linkification of chrome: and javascript: content in
      web console and JavaScript debugger
    * CVE-2018-5168 (bmo#1449548)
      Lightweight themes can be installed without user interaction
    * CVE-2018-5169 (bmo#1319157)
      Dragging and dropping link text onto home button can set home page
      to include chrome pages
    * CVE-2018-5172 (bmo#1436482)
      Pasted script from clipboard can run in the Live Bookmarks page
      or PDF viewer
    * CVE-2018-5173 (bmo#1438025)
      File name spoofing of Downloads panel with Unicode characters
    * CVE-2018-5174 (bmo#1447080) (Windows-only)
      Windows Defender SmartScreen UI runs with less secure behavior
      for downloaded files in Windows 10 April 2018 Update
    * CVE-2018-5175 (bmo#1432358)
      Universal CSP bypass on sites using strict-dynamic in their policies
    * CVE-2018-5176 (bmo#1442840)
      JSON Viewer script injection
    * CVE-2018-5177 (bmo#1451908)
      Buffer overflow in XSLT during number formatting
    * CVE-2018-5165 (bmo#1451452)
      Checkbox for enabling Flash protected mode is inverted in 32-bit
      Firefox
    * CVE-2018-5180 (bmo#1444086)
      heap-use-after-free in mozilla::WebGLContext::DrawElementsInstanced
    * CVE-2018-5181 (bmo#1424107)
      Local file can be displayed in noopener tab through drag and
      drop of hyperlink
    * CVE-2018-5182 (bmo#1435908)
      Local file can be displayed from hyperlink dragged and dropped
      on addressbar
    * CVE-2018-5151
      Memory safety bugs fixed in Firefox 60
    * CVE-2018-5150
      Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8
  - removed obsolete patches
    0001-Bug-1435695-WebRTC-fails-to-build-with-GCC-8-r-dmino.patch
    mozilla-bmo1005535.patch
  - requires NSPR 4.19 and NSS 3.36.1
  - requires rust 1.24 or higher
  - use upstream source archive and detached signature for
    source verification
* Thu May 03 2018 guillaume.gardet@opensuse.org
  - Fix armv7 build by:
    * adding RUSTFLAGS="-Cdebuginfo=0"
    * updating _constraints for %arm
* Wed May 02 2018 wr@rosenauer.org
  - do not try CSD on kwin (boo#1091592)
  - fix build in openSUSE:Leap:42.3:Update, use gcc7
* Tue May 01 2018 astieger@suse.com
  - Mozilla Firefox 59.0.3:
    * fixes for platforms other than GNU/Linux
* Fri Apr 20 2018 mliska@suse.cz
  - Add 0001-Bug-1435695-WebRTC-fails-to-build-with-GCC-8-r-dmino.patch
    in order to fix boo#1090362.
* Mon Apr 02 2018 badshah400@gmail.com
  - Add back mozilla-enable-csd.patch: New rebased version from
    Fedora for version 59.0.x.
* Tue Mar 27 2018 schwab@suse.de
  - Reduce constraints on aarch64
* Tue Mar 27 2018 wr@rosenauer.org
  - update to Firefox 59.0.2
    * Invalid page rendering with hardware acceleration enabled (bmo#1435472)
    * Browser keyboard shortcuts (eg copy Ctrl+C) don't work on sites
      that use those keys with resistFingerprinting enabled (bmo#1433592)
    * High CPU / memory churn caused by third-party software on some
      computers (bmo#1446280)
    * Users who have configured an "automatic proxy configuration URL"
      and want to reload their proxy settings from the URL will find
      the Reload button disabled in the Connection Settings dialog when
      they select Preferences/Options>Network Proxy>Settings... (bmo#1445991)
    * URL Fragment Identifiers Break Service Worker Responses (bmo#1443850)
    * User's trying to cancel a print around the time it completes will
      continue to get intermittent crashes (bmo#1441598)
    MFSA 2018-10 (bsc#1087059)
    * CVE-2018-5148 (bmo#1440717)
      Use-after-free in compositor
  - removed obsolete patch mozilla-bmo1446062.patch
* Wed Mar 21 2018 cgrobertson@suse.com
  - Added patches:
    * mozilla-i586-DecoderDoctorLogger.patch - bmo#1447070
      fixes non-unified build error
    * mozilla-i586-domPrefs.patch - DOMPrefs.h
      fixes 32bit build error
* Fri Mar 16 2018 wr@rosenauer.org
  - update to Firefox 59.0.1 (bsc#1085671)
    MFSA 2018-08
    * CVE-2018-5146 (bmo#1446062)
      Vorbis audio processing out of bounds write
    * CVE-2018-5147 (bmo#1446365)
      Out of bounds memory write in libtremor
      (mozilla-bmo1446062.patch)
* Wed Mar 14 2018 cgrobertson@suse.com
  - Added patch:
    * mozilla-bmo1005535.patch:
      Enable skia_gpu on big endian platforms.
* Sun Mar 11 2018 wr@rosenauer.org
  - update to Firefox 59.0
    * Performance enhancements
    * Drag-and-drop to rearrange Top Sites on the Firefox Home page
    * added features for Firefox Screenshots
    * Enhanced WebExtensions API
    * Improved RTC capabilities
    MFSA 2018-06 (bsc#1085130)
    * CVE-2018-5127 (bmo#1430557)
      Buffer overflow manipulating SVG animatedPathSegList
    * CVE-2018-5128 (bmo#1431336)
      Use-after-free manipulating editor selection ranges
    * CVE-2018-5129 (bmo#1428947)
      Out-of-bounds write with malformed IPC messages
    * CVE-2018-5130 (bmo#1433005)
      Mismatched RTP payload type can trigger memory corruption
    * CVE-2018-5131 (bmo#1440775)
      Fetch API improperly returns cached copies of no-store/no-cache resources
    * CVE-2018-5132 (bmo#1408194)
      WebExtension Find API can search privileged pages
    * CVE-2018-5133 (bmo#1430511, bmo#1430974)
      Value of the app.support.baseURL preference is not properly sanitized
    * CVE-2018-5134 (bmo#1429379)
      WebExtensions may use view-source: URLs to bypass content restrictions
    * CVE-2018-5135 (bmo#1431371)
      WebExtension browserAction can inject scripts into unintended contexts
    * CVE-2018-5136 (bmo#1419166)
      Same-origin policy violation with data: URL shared workers
    * CVE-2018-5137 (bmo#1432870)
      Script content can access legacy extension non-contentaccessible resources
    * CVE-2018-5138 (bmo#1432624) (Android only)
      Android Custom Tab address spoofing through long domain names
    * CVE-2018-5140 (bmo#1424261)
      Moz-icon images accessible to web content through moz-icon: protocol
    * CVE-2018-5141 (bmo#1429093)
      DOS attack through notifications Push API
    * CVE-2018-5142 (bmo#1366357)
      Media Capture and Streams API permissions display incorrect origin
      with data: and blob: URLs
    * CVE-2018-5143 (bmo#1422643)
      Self-XSS pasting javascript: URL with embedded tab into addressbar
    * CVE-2018-5126
      Memory safety bugs fixed in Firefox 59
    * CVE-2018-5125
      Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7
  - requires NSPR 4.18 and NSS 3.35
  - requires rust >= 1.22.1
  - removed obsolete patches:
    mozilla-alsa-sandbox.patch
    mozilla-enable-csd.patch
    firefox-no-default-ualocale.patch
  - removed l10n_changesets.txt since same information is now in
    Firefox source tree (updated create-tar.sh now requires jq)
* Fri Feb 09 2018 astieger@suse.com
  - Mozilla Firefox 58.0.2:
    * Blocklisted graphics drivers related to off main thread painting
      crashes
    * Fix tab crash during printing
    * Fix clicking links and scrolling emails on Microsoft Hotmail
      and Outlook (OWA) webmail
* Fri Feb 09 2018 wr@rosenauer.org
  - correct requires and provides handling (boo#1076907)
* Tue Feb 06 2018 fstrba@suse.com
  - Added patch:
    * mozilla-alsa-sandbox.patch: Fix bmo#1430274, ALSA sound (still
      or again?) not working in Firefox 58 due to sandboxing.
* Mon Jan 29 2018 wr@rosenauer.org
  - update to Firefox 58.0.1
    MFSA 2018-05
    * Arbitrary code execution through unsanitized browser UI (bmo#1432966)
  - use correct language packs
  - readd mozilla-enable-csd.patch as it only lands for FF59 upstream
  - allow larger number of nested elements (mozilla-bmo256180.patch)
* Tue Jan 23 2018 wr@rosenauer.org
  - update to Firefox 58.0 (bsc#1077291)
    * Added Nepali (ne-NP) locale
    * Added support for form autofill for credit card
    * Optimize page load by caching JavaScript internal representation
    MFSA 2018-02
    * CVE-2018-5091 (bmo#1423086)
      Use-after-free with DTMF timers
    * CVE-2018-5092 (bmo#1418074)
      Use-after-free in Web Workers
    * CVE-2018-5093 (bmo#1415291)
      Buffer overflow in WebAssembly during Memory/Table resizing
    * CVE-2018-5094 (bmo#1415883)
      Buffer overflow in WebAssembly with garbage collection on
      uninitialized memory
    * CVE-2018-5095 (bmo#1418447)
      Integer overflow in Skia library during edge builder allocation
    * CVE-2018-5097 (bmo#1387427)
      Use-after-free when source document is manipulated during XSLT
    * CVE-2018-5098 (bmo#1399400)
      Use-after-free while manipulating form input elements
    * CVE-2018-5099 (bmo#1416878)
      Use-after-free with widget listener
    * CVE-2018-5100 (bmo#1417405)
      Use-after-free when IsPotentiallyScrollable arguments are freed
      from memory
    * CVE-2018-5101 (bmo#1417661)
      Use-after-free with floating first-letter style elements
    * CVE-2018-5102 (bmo#1419363)
      Use-after-free in HTML media elements
    * CVE-2018-5103 (bmo#1423159)
      Use-after-free during mouse event handling
    * CVE-2018-5104 (bmo#1425000)
      Use-after-free during font face manipulation
    * CVE-2018-5105 (bmo#1390882)
      WebExtensions can save and execute files on local file system
      without user prompts
    * CVE-2018-5106 (bmo#1408708)
      Developer Tools can expose style editor information cross-origin
      through service worker
    * CVE-2018-5107 (bmo#1379276)
      Printing process will follow symlinks for local file access
    * CVE-2018-5108 (bmo#1421099)
      Manually entered blob URL can be accessed by subsequent private browsing tabs
    * CVE-2018-5109 (bmo#1405599)
      Audio capture prompts and starts with incorrect origin attribution
    * CVE-2018-5110 (bmo#1423275) (affects only OS X)
      Cursor can be made invisible on OS X
    * CVE-2018-5111 (bmo#1321619)
      URL spoofing in addressbar through drag and drop
    * CVE-2018-5112 (bmo#1425224)
      Extension development tools panel can open a non-relative URL in the panel
    * CVE-2018-5113 (bmo#1425267)
      WebExtensions can load non-HTTPS pages with browser.identity.launchWebAuthFlow
    * CVE-2018-5114 (bmo#1421324)
      The old value of a cookie changed to HttpOnly remains accessible to scripts
    * CVE-2018-5115 (bmo#1409449)
      Background network requests can open HTTP authentication in unrelated foreground tabs
    * CVE-2018-5116 (bmo#1396399)
      WebExtension ActiveTab permission allows cross-origin frame content access
    * CVE-2018-5117 (bmo#1395508)
      URL spoofing with right-to-left text aligned left-to-right
    * CVE-2018-5118 (bmo#1420049)
      Activity Stream images can attempt to load local content through file:
    * CVE-2018-5119 (bmo#1420507)
      Reader view will load cross-origin content in violation of CORS headers
    * CVE-2018-5121 (bmo#1402368) (affects only OS X)
      OS X Tibetan characters render incompletely in the addressbar
    * CVE-2018-5122 (bmo#1413841)
      Potential integer overflow in DoCrypt
    * CVE-2018-5090
      Memory safety bugs fixed in Firefox 58
    * CVE-2018-5089
      Memory safety bugs fixed in Firefox 58 and Firefox ESR 52.6
  - requires NSS 3.34.1
  - requires rust 1.21
  - removed obsolete patches:
    mozilla-bindgen-systemlibs.patch
    mozilla-bmo1360278.patch
    mozilla-bmo1399611-csd.patch
    mozilla-rust-1.23.patch
  - rebased patches
  - updated man-page
* Tue Jan 09 2018 wr@rosenauer.org
  - fixed build with latest rust (mozilla-rust-1.23.patch)
* Thu Jan 04 2018 wr@rosenauer.org
  - update to Firefox 57.0.4
    MFSA 2018-1: Speculative execution side-channel attack ("Spectre")
    (boo#1074723)
* Wed Jan 03 2018 wr@rosenauer.org
  - fixed regression introduced Oct 10th which made Firefox crash
    when cancelling the KDE file dialog (boo#1069962)

Files

/usr/bin/firefox
/usr/lib/firefox
/usr/lib/firefox/application.ini
/usr/lib/firefox/browser
/usr/lib/firefox/browser/chrome
/usr/lib/firefox/browser/chrome/icons
/usr/lib/firefox/browser/chrome/icons/default
/usr/lib/firefox/browser/chrome/icons/default/default128.png
/usr/lib/firefox/browser/chrome/icons/default/default16.png
/usr/lib/firefox/browser/chrome/icons/default/default22.png
/usr/lib/firefox/browser/chrome/icons/default/default24.png
/usr/lib/firefox/browser/chrome/icons/default/default256.png
/usr/lib/firefox/browser/chrome/icons/default/default32.png
/usr/lib/firefox/browser/chrome/icons/default/default48.png
/usr/lib/firefox/browser/chrome/icons/default/default64.png
/usr/lib/firefox/browser/defaults
/usr/lib/firefox/browser/defaults/preferences
/usr/lib/firefox/browser/defaults/preferences/firefox.js
/usr/lib/firefox/browser/features
/usr/lib/firefox/browser/features/doh-rollout@mozilla.org.xpi
/usr/lib/firefox/browser/features/formautofill@mozilla.org.xpi
/usr/lib/firefox/browser/features/pictureinpicture@mozilla.org.xpi
/usr/lib/firefox/browser/features/proxy-failover@mozilla.com.xpi
/usr/lib/firefox/browser/features/screenshots@mozilla.org.xpi
/usr/lib/firefox/browser/features/webcompat-reporter@mozilla.org.xpi
/usr/lib/firefox/browser/features/webcompat@mozilla.org.xpi
/usr/lib/firefox/browser/omni.ja
/usr/lib/firefox/defaults
/usr/lib/firefox/defaults/pref
/usr/lib/firefox/defaults/pref/channel-prefs.js
/usr/lib/firefox/defaults/pref/spellcheck.js
/usr/lib/firefox/dependentlibs.list
/usr/lib/firefox/distribution
/usr/lib/firefox/distribution/extensions
/usr/lib/firefox/firefox
/usr/lib/firefox/firefox-bin
/usr/lib/firefox/firefox.sh
/usr/lib/firefox/fonts
/usr/lib/firefox/fonts/TwemojiMozilla.ttf
/usr/lib/firefox/gmp-clearkey
/usr/lib/firefox/gmp-clearkey/0.1
/usr/lib/firefox/gmp-clearkey/0.1/libclearkey.so
/usr/lib/firefox/gmp-clearkey/0.1/manifest.json
/usr/lib/firefox/liblgpllibs.so
/usr/lib/firefox/libmozavcodec.so
/usr/lib/firefox/libmozavutil.so
/usr/lib/firefox/libmozgtk.so
/usr/lib/firefox/libmozsandbox.so
/usr/lib/firefox/libmozsqlite3.so
/usr/lib/firefox/libmozwayland.so
/usr/lib/firefox/libxul.so
/usr/lib/firefox/omni.ja
/usr/lib/firefox/pingsender
/usr/lib/firefox/platform.ini
/usr/lib/firefox/plugin-container
/usr/lib/mozilla
/usr/lib/mozilla/extensions
/usr/lib/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
/usr/share/applications/firefox.desktop
/usr/share/gnome-shell
/usr/share/gnome-shell/search-providers
/usr/share/gnome-shell/search-providers/firefox-search-provider.ini
/usr/share/icons/hicolor
/usr/share/icons/hicolor/128x128
/usr/share/icons/hicolor/128x128/apps
/usr/share/icons/hicolor/128x128/apps/firefox.png
/usr/share/icons/hicolor/16x16
/usr/share/icons/hicolor/16x16/apps
/usr/share/icons/hicolor/16x16/apps/firefox.png
/usr/share/icons/hicolor/22x22
/usr/share/icons/hicolor/22x22/apps
/usr/share/icons/hicolor/22x22/apps/firefox.png
/usr/share/icons/hicolor/24x24
/usr/share/icons/hicolor/24x24/apps
/usr/share/icons/hicolor/24x24/apps/firefox.png
/usr/share/icons/hicolor/256x256
/usr/share/icons/hicolor/256x256/apps
/usr/share/icons/hicolor/256x256/apps/firefox.png
/usr/share/icons/hicolor/32x32
/usr/share/icons/hicolor/32x32/apps
/usr/share/icons/hicolor/32x32/apps/firefox.png
/usr/share/icons/hicolor/48x48
/usr/share/icons/hicolor/48x48/apps
/usr/share/icons/hicolor/48x48/apps/firefox.png
/usr/share/icons/hicolor/64x64
/usr/share/icons/hicolor/64x64/apps
/usr/share/icons/hicolor/64x64/apps/firefox.png
/usr/share/man/man1/firefox.1.gz
/usr/share/metainfo
/usr/share/metainfo/firefox.appdata.xml
/usr/share/mime/packages/firefox.xml
/usr/share/mozilla
/usr/share/mozilla/extensions
/usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}


Generated by rpm2html 1.8.1

Fabrice Bellet, Wed Apr 24 00:33:34 2024