pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/www/firefox140
Module Name: pkgsrc
Committed By: gutteridge
Date: Wed Aug 19 02:36:12 UTC 2026
Modified Files:
pkgsrc/www/firefox140: Makefile distinfo
Log Message:
firefox140: update to 140.14
Mozilla Foundation Security Advisory 2026-76
Security Vulnerabilities fixed in Firefox ESR 140.14
Announced
August 18, 2026
Impact
high
Products
Firefox ESR
Fixed in
Firefox ESR 140.14
#CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
Reporter
satyamasd
Impact
high
References
Bug 2050584
#CVE-2026-74935: Privilege escalation in the DOM: Networking component
Reporter
Yaqoub Aldurayhim
Impact
high
References
Bug 2051013
#CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
Reporter
Amy Burnett of OpenAI
Impact
high
References
Bug 2052688
#CVE-2026-74939: Privilege escalation in the DOM: Navigation component
Reporter
choeseyeong
Impact
high
References
Bug 2054416
#CVE-2026-74940: Use-after-free in the Graphics: Text component
Reporter
kiyong
Impact
high
References
Bug 2054842
#CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
Reporter
Jacolon Walker
Impact
high
References
Bug 2055056
#CVE-2026-74942: Privilege escalation in the Remote Settings Client component
Reporter
Gal Ankonina
Impact
high
References
Bug 2056571
#CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
Reporter
Abdulaziz Alasaiqah
Impact
high
References
Bug 2057308
#CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
Reporter
Amy Burnett of OpenAI
Impact
high
References
Bug 2057778
#CVE-2026-74945: Information disclosure in the Graphics: Text component
Reporter
Abdulaziz Alasaiqah
Impact
high
References
Bug 2057808
#CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Reporter
locust1b
Impact
high
References
Bug 2059997
#CVE-2026-74948: Information disclosure in the Graphics component
Reporter
Yaqoub Aldurayhim
Impact
high
References
Bug 2060106
#CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component
Reporter
r00tdaddy
Impact
high
References
Bug 2060245
#CVE-2026-74953: Privilege escalation in the Networking: Cookies component
Reporter
Satoki Tsuji
Impact
moderate
References
Bug 2022382
#CVE-2026-74957: Mitigation bypass in the Safe Browsing component
Reporter
Tomoya Nakanishi
Impact
moderate
References
Bug 2041906
#CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
Reporter
David Bors at Snyk Security Labs
Impact
moderate
References
Bug 2047853
#CVE-2026-74960: Site isolation issue in the WebExtensions component
Reporter
Khanh Nguyen
Impact
moderate
References
Bug 2049148
#CVE-2026-74962: Site isolation issue in the Networking: Cookies component
Reporter
Yaqoub Aldurayhim
Impact
moderate
References
Bug 2050425
#CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
Reporter
5up3rh3i
Impact
moderate
References
Bug 2050482
#CVE-2026-74964: Integer overflow in the Graphics component
Reporter
5up3rh3i
Impact
moderate
References
Bug 2053327
#CVE-2026-74965: Privilege escalation in the Shell Integration component
Reporter
Khanh Nguyen
Impact
moderate
References
Bug 2053455
#CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
Reporter
The Mozilla Fuzzing Team
Impact
moderate
References
Bug 2055697
#CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
Reporter
Hyeonjun Ahn
Impact
moderate
References
Bug 2056065
#CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
Reporter
avlidienbrunn
Impact
moderate
References
Bug 2057204
#CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
Reporter
Kagami Rosylight
Impact
moderate
References
Bug 2059053
#CVE-2026-74973: Race condition, use-after-free in the Graphics component
Reporter
r00tdaddy
Impact
moderate
References
Bug 2060357
#CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
Reporter
The Mozilla Fuzzing Team
Impact
moderate
References
Bug 2061794
#CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
Reporter
anbu
Impact
low
References
Bug 1952164
#CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
Reporter
5up3rh3i
Impact
low
References
Bug 2051897
#CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Reporter
Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description
Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that
with enough effort some of these could have been exploited.
References
High Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Moderate Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Low Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
#CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Reporter
Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description
Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect
and we presume that with enough effort some of these could have been exploited.
References
High Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Moderate Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
To generate a diff of this commit:
cvs rdiff -u -r1.21 -r1.22 pkgsrc/www/firefox140/Makefile
cvs rdiff -u -r1.19 -r1.20 pkgsrc/www/firefox140/distinfo
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/www/firefox140/Makefile
diff -u pkgsrc/www/firefox140/Makefile:1.21 pkgsrc/www/firefox140/Makefile:1.22
--- pkgsrc/www/firefox140/Makefile:1.21 Tue Jul 21 16:30:32 2026
+++ pkgsrc/www/firefox140/Makefile Wed Aug 19 02:36:12 2026
@@ -1,7 +1,7 @@
-# $NetBSD: Makefile,v 1.21 2026/07/21 16:30:32 gutteridge Exp $
+# $NetBSD: Makefile,v 1.22 2026/08/19 02:36:12 gutteridge Exp $
FIREFOX_VER= ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH= 140.13
+MOZ_BRANCH= 140.14
MOZ_BRANCH_MINOR= .0esr
DISTNAME= firefox-${FIREFOX_VER}.source
Index: pkgsrc/www/firefox140/distinfo
diff -u pkgsrc/www/firefox140/distinfo:1.19 pkgsrc/www/firefox140/distinfo:1.20
--- pkgsrc/www/firefox140/distinfo:1.19 Tue Jul 21 16:30:32 2026
+++ pkgsrc/www/firefox140/distinfo Wed Aug 19 02:36:12 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.19 2026/07/21 16:30:32 gutteridge Exp $
+$NetBSD: distinfo,v 1.20 2026/08/19 02:36:12 gutteridge Exp $
-BLAKE2s (firefox-140.13.0esr.source.tar.xz) = ea85681fc369dc74f8637b1182840a2c3be8dc94bfbb5666e7bf53f46625cf9e
-SHA512 (firefox-140.13.0esr.source.tar.xz) = 937a4103d71c5e1e4bf051821729f6ea70b5c18d444930a487695cc23d74712a0134047248f6ac02305e01becb705426a55b9d89739f02a01eda01ecf5bc27f1
-Size (firefox-140.13.0esr.source.tar.xz) = 644768324 bytes
+BLAKE2s (firefox-140.14.0esr.source.tar.xz) = 6e444488cfb0cd6c0ec8dbcc7328916fcf2b9ef09ec327886a7116cd3a7c54cb
+SHA512 (firefox-140.14.0esr.source.tar.xz) = 0609cca9bfaecbff56cdf13458534bd8cfa43f139056867d3b6394a767281599ee600f83165ad25565ced59b552592aa84431357458ccecfbe5bf104dca501c7
+Size (firefox-140.14.0esr.source.tar.xz) = 643083928 bytes
BLAKE2s (nodejs-output-140.0.4.tgz) = 7ebb5993c8c9d7d5492afdb9fa7fef74fec7753fb0b14673817f24faf4a7fca4
SHA512 (nodejs-output-140.0.4.tgz) = e421b0b6be8b5b8dfda705eefcf4573a1270df9012dca5eac9ba0ac2af2bcc47dd66b1057106f8c2336a10bdcc39b9f852041dd33da9e7a8929d981dbb4e1fb4
Size (nodejs-output-140.0.4.tgz) = 245385 bytes
Home |
Main Index |
Thread Index |
Old Index