You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa firefox

Sigurnosni nedostaci programskog paketa firefox

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-1404
2015-01-30 00:57:39
——————————————————————————–

Name : firefox
Product : Fedora 21
Version : 35.0.1
Release : 3.fc21
URL : http://www.mozilla.org/projects/firefox/
Summary : Mozilla Firefox Web browser
Description :
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance and portability.

——————————————————————————–
Update Information:

New upstream – 35.0.1
Enabled click-to-play for flash by default due to live and exploited 0-day flash vulnerability.
——————————————————————————–
ChangeLog:

* Tue Jan 27 2015 Martin Stransky <stransky@redhat.com> – 35.0.1-3
– Backed out the flash click-to-play setup
* Mon Jan 26 2015 David Tardon <dtardon@redhat.com> – 35.0.1-2
– rebuild for ICU 54.1
* Fri Jan 23 2015 Martin Stransky <stransky@redhat.com> – 35.0.1-1
– New upstream version
* Thu Jan 22 2015 Martin Stransky <stransky@redhat.com> – 35.0-7
– Updated hiDPI patch to upstream version (mozbz#975919)
* Thu Jan 22 2015 Martin Stransky <stransky@redhat.com> – 35.0-6
– Disabled flash by default because of 0day live flash exploit
(see https://isc.sans.edu/diary/Flash+0-Day+Exploit+Used+by+Angler+Exploit+Kit/19213)
* Mon Jan 19 2015 Martin Stransky <stransky@redhat.com> – 35.0-5
– Enable release build config
– Gtk3 – added patch for HiDPI support (mozbz#975919)
* Mon Jan 19 2015 Martin Stransky <stransky@redhat.com> – 35.0-4
– Gtk3 – fixed tabs rendering
* Wed Jan 14 2015 Martin Stransky <stransky@redhat.com> – 35.0-3
– Gtk3 – replaced obsoleted focus properties
– Make start.fedoraproject.org the homepage
* Mon Jan 12 2015 Martin Stransky <stransky@redhat.com> – 35.0-2
– Update to 35.0 Build 3
– Gtk3 – added fix for button/entry box sizes
– Gtk3 – added fix for button/entry focus sizes
– Spec clean-up (by moez.roy@gmail.com)
* Tue Jan 6 2015 Martin Stransky <stransky@redhat.com> – 35.0-1
– Update to 35.0 Build 1
* Mon Jan 5 2015 Martin Stransky <stransky@redhat.com> – 34.0-12
– Fixed rhbz#1014858 – GLib-CRITICAL **: g_slice_set_config:
assertion `sys_page_size == 0′ failed
* Fri Jan 2 2015 Martin Stransky <stransky@redhat.com> – 34.0-11
– Build with system jpeg on rawhide
– Updated ATK patch for gtk3
* Tue Dec 23 2014 Martin Stransky <stransky@redhat.com> – 34.0-9
– Added fix for rhbz#1173156 – Native NTLM authentication
on Linux unsupported
– Added fix for rhbz#1170109 – data corruption bug on armhfp
* Sat Dec 13 2014 Martin Stransky <stransky@redhat.com> – 34.0-8
– Gtk3 – Workaround for Firefox freeze when accessibility is enabled
* Fri Dec 12 2014 Martin Stransky <stransky@redhat.com> – 34.0-7
– Added fix for mozbz#1097592 – Firefox freeze in Gtk3
* Thu Dec 11 2014 Martin Stransky <stransky@redhat.com> – 34.0-6
– Disabled Gtk3 on Fedora 21 and earlier (rhbz#1172926)
* Wed Dec 10 2014 Martin Stransky <stransky@redhat.com> – 34.0-5
– Disabled flash plugin instllation pop-up (mozbz#1108645)
* Mon Dec 8 2014 Jiri Vanek <jvanek@redhat.com> – 34.0-4
– added and applied patch218, java-plugin-url.patch
– fixed url for java plugin installation guide
– resolves rhbz#979985
* Mon Dec 8 2014 Martin Stransky <stransky@redhat.com> – 34.0-3
– Gtk3 flash plugin fix (rhbz#1171457)
– Gtk3 theme fixes
* Wed Dec 3 2014 Jan Horak <jhorak@redhat.com> – 34.0-2
– Fix for mozbz#1097550 – wrong default dictionary
* Mon Dec 1 2014 Martin Stransky <stransky@redhat.com> – 34.0-1
– Update to 34.0 build 2
——————————————————————————–
References:

[ 1 ] Bug #1185241 – Enable click-to-play for flash-plugin play due to 0-day vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=1185241
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update firefox’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorMarko Stanec
Cert idNCERT-REF-2015-02-0003-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa requests

Otkriveni su sigurnosni nedostaci u programskom paketu requests. Otkriveni nedostaci potencijalnim napadačima omogućuju otkrivanje osjetljivih informacija iz "Proxy-Authorization" i "Authorization"...

Close