pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/www/firefox140
Module Name: pkgsrc
Committed By: gutteridge
Date: Tue Sep 29 13:19:11 UTC 2026
Modified Files:
pkgsrc/www/firefox140: Makefile distinfo
Log Message:
firefox140: update to 140.17
Mozilla Foundation Security Advisory 2026-99
Security Vulnerabilities fixed in Firefox ESR 140.17
Announced
September 29, 2026
Impact
high
Products
Firefox ESR
Fixed in
Firefox ESR 140.17
Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component
Reporter
Mozilla
Impact
high
References
Bug 2047721
#CVE-2026-100757: Use-after-free in the Widget component
Reporter
Mohamed Mbarek
Impact
high
References
Bug 2049352
#CVE-2026-100758: Sandbox escape in the DOM: Navigation component
Reporter
Mozilla
Impact
high
References
Bug 2049792
#CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component
Reporter
Mozilla
Impact
high
References
Bug 2054736
#CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component
Reporter
Yaqoub Aldurayhim
Impact
high
References
Bug 2059404
#CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component
Reporter
Mozilla
Impact
high
References
Bug 2061245
#CVE-2026-100766: Information disclosure in the Networking: JAR component
Reporter
Mozilla
Impact
high
References
Bug 2061526
#CVE-2026-100767: Use-after-free in the Networking: Cache component
Reporter
Mozilla
Impact
high
References
Bug 2063680
#CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly component
Reporter
Tomer Fichman
Impact
high
References
Bug 2067190
#CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component
Reporter
Mozilla
Impact
high
References
Bug 2068322
#CVE-2026-100771: Undefined behavior in the DOM: Streams component
Reporter
Mozilla
Impact
high
References
Bug 2068336
#CVE-2026-100772: Use-after-free in the DOM: Core & HTML component
Reporter
Mozilla
Impact
high
References
Bug 2068340
#CVE-2026-100773: Use-after-free in the Storage: IndexedDB component
Reporter
Mozilla
Impact
high
References
Bug 2068346
#CVE-2026-100774: Use-after-free in the DOM: Core & HTML component
Reporter
Mozilla
Impact
high
References
Bug 2068351
#CVE-2026-100775: Sandbox escape in the Graphics component
Reporter
Mozilla
Impact
high
References
Bug 2068367
#CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly component
Reporter
Mozilla
Impact
high
References
Bug 2068374
#CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component
Reporter
Mozilla
Impact
high
References
Bug 2068375
#CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component
Reporter
Mozilla
Impact
high
References
Bug 2068406
#CVE-2026-100779: Use-after-free in the XSLT component
Reporter
Mozilla
Impact
high
References
Bug 2068417
#CVE-2026-100780: Use-after-free in the DOM: Core & HTML component
Reporter
Mozilla
Impact
high
References
Bug 2068422
#CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
Reporter
Mozilla
Impact
high
References
Bug 2068434
#CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component
Reporter
Mozilla
Impact
high
References
Bug 2068456
#CVE-2026-100783: Uninitialized memory in the Audio/Video component
Reporter
5up3rh3i
Impact
high
References
Bug 2069804
#CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component
Reporter
5up3rh3i
Impact
high
References
Bug 2070264
#CVE-2026-100785: Use-after-free in the DOM: Core & HTML component
Reporter
Mozilla
Impact
high
References
Bug 2071064
#CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component
Reporter
Mozilla
Impact
high
References
Bug 2071067
#CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly component
Reporter
Mozilla
Impact
high
References
Bug 2072413
#CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component
Reporter
Mozilla
Impact
high
References
Bug 2072429
#CVE-2026-100790: Use-after-free in the XSLT component
Reporter
Mozilla
Impact
high
References
Bug 2072432
#CVE-2026-100791: Use-after-free in the DOM: Core & HTML component
Reporter
Mozilla
Impact
high
References
Bug 2072433
#CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component
Reporter
Mozilla
Impact
high
References
Bug 2072467
#CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly component
Reporter
Amy Burnett of OpenAI
Impact
high
References
Bug 2073266
#CVE-2026-100794: Sandbox escape due to incorrect boundary conditions in the Internationalization component
Reporter
Mozilla
Impact
moderate
References
Bug 2028871
#CVE-2026-96869: Information disclosure in the Networking component
Reporter
Carlo Di Dato
Impact
moderate
References
Bug 2041248
#CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component
Reporter
Mozilla
Impact
moderate
References
Bug 2050542
#CVE-2026-100801: Privilege escalation in the DLL Services component
Reporter
Mozilla
Impact
moderate
References
Bug 2057112
#CVE-2026-100803: Same-origin policy bypass in the WebExtensions component
Reporter
Yaqoub Aldurayhim
Impact
moderate
References
Bug 2057988
#CVE-2026-100807: Privilege escalation in the DOM: Service Workers component
Reporter
Khanh Nguyen
Impact
moderate
References
Bug 2062740
#CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core & HTML component
Reporter
Yaqoub Aldurayhim
Impact
moderate
References
Bug 2067973
#CVE-2026-100818: Sandbox escape due to use-after-free in the Widget: Gtk component
Reporter
Mozilla
Impact
moderate
References
Bug 2069399
#CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component
Reporter
Mozilla
Impact
moderate
References
Bug 2071069
#CVE-2026-100820: Privilege escalation in the Address Bar component
Reporter
Tran Quac
Impact
moderate
References
Bug 2071645
#CVE-2026-100821: Site isolation issue in the Panning and Zooming component
Reporter
Nguyen Thanh Nguyen
Impact
moderate
References
Bug 2071784
To generate a diff of this commit:
cvs rdiff -u -r1.27 -r1.28 pkgsrc/www/firefox140/Makefile
cvs rdiff -u -r1.22 -r1.23 pkgsrc/www/firefox140/distinfo
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/www/firefox140/Makefile
diff -u pkgsrc/www/firefox140/Makefile:1.27 pkgsrc/www/firefox140/Makefile:1.28
--- pkgsrc/www/firefox140/Makefile:1.27 Tue Sep 29 06:08:04 2026
+++ pkgsrc/www/firefox140/Makefile Tue Sep 29 13:19:11 2026
@@ -1,12 +1,11 @@
-# $NetBSD: Makefile,v 1.27 2026/09/29 06:08:04 wiz Exp $
+# $NetBSD: Makefile,v 1.28 2026/09/29 13:19:11 gutteridge Exp $
FIREFOX_VER= ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH= 140.16
+MOZ_BRANCH= 140.17
MOZ_BRANCH_MINOR= .0esr
DISTNAME= firefox-${FIREFOX_VER}.source
PKGNAME= ${DISTNAME:S/.source//:S/b/beta/:S/esr//:S/firefox-/firefox140-/}
-PKGREVISION= 2
CATEGORIES= www
MASTER_SITES+= ${MASTER_SITE_MOZILLA:=firefox/releases/${FIREFOX_VER}/source/}
MASTER_SITES+= ${MASTER_SITE_MOZILLA_ALL:=firefox/releases/${FIREFOX_VER}/source/}
Index: pkgsrc/www/firefox140/distinfo
diff -u pkgsrc/www/firefox140/distinfo:1.22 pkgsrc/www/firefox140/distinfo:1.23
--- pkgsrc/www/firefox140/distinfo:1.22 Tue Sep 15 13:16:58 2026
+++ pkgsrc/www/firefox140/distinfo Tue Sep 29 13:19:11 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.22 2026/09/15 13:16:58 gutteridge Exp $
+$NetBSD: distinfo,v 1.23 2026/09/29 13:19:11 gutteridge Exp $
-BLAKE2s (firefox-140.16.0esr.source.tar.xz) = 787602619860678dbde4ff0ebe59db1f2a0920835b9fe6a523ac8ff7947b04d2
-SHA512 (firefox-140.16.0esr.source.tar.xz) = fabf5b481594a9a860b6ae379d2ee89ba291b807c94334ee15bad1fe862edb47c22e890d892e33d6a6ec57fce4ab12aa9c9c6fa4a501b881ecc6211ac04bd9a0
-Size (firefox-140.16.0esr.source.tar.xz) = 632581380 bytes
+BLAKE2s (firefox-140.17.0esr.source.tar.xz) = 8450cae92597fc4860dbfa42e145c587dd5022c8e2d427d1da8f480d3ff50031
+SHA512 (firefox-140.17.0esr.source.tar.xz) = c569f4f1ecbadec4c24ab60af6c8ff03f6c1292e7b2446edca7cc6f5575bd8d98e3ee9efb9877eba98bdb15354a4c4260515f8c6fd9aa9d198b26722f60ae5f4
+Size (firefox-140.17.0esr.source.tar.xz) = 637640276 bytes
BLAKE2s (nodejs-output-140.0.4.tgz) = 7ebb5993c8c9d7d5492afdb9fa7fef74fec7753fb0b14673817f24faf4a7fca4
SHA512 (nodejs-output-140.0.4.tgz) = e421b0b6be8b5b8dfda705eefcf4573a1270df9012dca5eac9ba0ac2af2bcc47dd66b1057106f8c2336a10bdcc39b9f852041dd33da9e7a8929d981dbb4e1fb4
Size (nodejs-output-140.0.4.tgz) = 245385 bytes
Home |
Main Index |
Thread Index |
Old Index