pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/firefox153



Module Name:    pkgsrc
Committed By:   gutteridge
Date:           Tue Sep  1 16:09:24 UTC 2026

Modified Files:
        pkgsrc/www/firefox153: Makefile distinfo

Log Message:
firefox153: update to 153.2

Mozilla Foundation Security Advisory 2026-85
Security Vulnerabilities fixed in Firefox ESR 153.2

Announced
    September 1, 2026
Impact
    high
Products
    Firefox ESR
Fixed in

        Firefox ESR 153.2

#CVE-2026-75874: Sandbox escape in the Remote Settings Client component

Reporter
    crixer
Impact
    high

References

    Bug 2039972

#CVE-2026-84118: Use-after-free in the JavaScript: GC component

Reporter
    x0e
Impact
    high

References

    Bug 2057457

#CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2057817

#CVE-2026-84120: Use-after-free in the Audio/Video component

Reporter
    Ukyo Akai
Impact
    high

References

    Bug 2058911

#CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2059018

#CVE-2026-84122: Use-after-free in the Audio/Video component

Reporter
    Hyeonjun Ahn
Impact
    high

References

    Bug 2059965

#CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2060047

#CVE-2026-84124: Use-after-free in the DOM: Core & HTML component

Reporter
    Hyeonjun Ahn
Impact
    high

References

    Bug 2061110

#CVE-2026-84125: Use-after-free in the DOM: Core & HTML component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2063871

#CVE-2026-74952: Privilege escalation in the Application Update component

Reporter
    Tomoya Nakanishi
Impact
    moderate

References

    Bug 2021757

#CVE-2026-84129: Site isolation issue in the DOM: Navigation component

Reporter
    Yaqoub Aldurayhim
Impact
    moderate

References

    Bug 2055028

#CVE-2026-84130: Information disclosure in the Graphics: WebGPU component

Reporter
    5up3rh3i
Impact
    moderate

References

    Bug 2057834

#CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component

Reporter
    navapon
Impact
    moderate

References

    Bug 2060008

#CVE-2026-84132: Information disclosure in the Networking: HTTP component

Reporter
    Shu Takahashi
Impact
    moderate

References

    Bug 2063020

#CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component

Reporter
    pakhunov.anton.n
Impact
    low

References

    Bug 2032388

#CVE-2026-84134: Other issue in the Profile Backup component

Reporter
    5up3rh3i
Impact
    low

References

    Bug 2044882

#CVE-2026-84136: Other issue in the DOM: Navigation component

Reporter
    Apentota
Impact
    low

References

    Bug 2048699

#CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component

Reporter
    Riski Muhammad Ivan
Impact
    low

References

    Bug 2051146

#CVE-2026-84139: Clickjacking issue in the DOM: Events component

Reporter
    Long Nguyen
Impact
    low

References

    Bug 2060153

#CVE-2026-84140: Site isolation issue in the DOM: Navigation component

Reporter
    Mohamed Mbarek
Impact
    low

References

    Bug 2063780

#CVE-2026-84141: Integer overflow in the Graphics: ImageLib component

Reporter
    nguyentuanhung1149
Impact
    low

References

    Bug 2063994

#CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15

Reporter
    Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
Impact
    high

Description

Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Firefox ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that 
with enough effort some of these could have been exploited.
References

    High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
    Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
    Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15

#CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2

Reporter
    Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
Impact
    high

Description

Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort 
some of these could have been exploited.
References

    High Severity internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
    Moderate Severity internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
    Low Severity internally found bugs fixed in Firefox 155 and Firefox ESR 153.2

#CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40

Reporter
    Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
Impact
    high

Description

Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. Some of these bugs showed evidence of memory corruption or another security-relevant defect 
and we presume that with enough effort some of these could have been exploited.
References

    High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
    Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
    Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40


To generate a diff of this commit:
cvs rdiff -u -r1.1 -r1.2 pkgsrc/www/firefox153/Makefile \
    pkgsrc/www/firefox153/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/www/firefox153/Makefile
diff -u pkgsrc/www/firefox153/Makefile:1.1 pkgsrc/www/firefox153/Makefile:1.2
--- pkgsrc/www/firefox153/Makefile:1.1  Thu Aug 27 01:23:15 2026
+++ pkgsrc/www/firefox153/Makefile      Tue Sep  1 16:09:24 2026
@@ -1,7 +1,7 @@
-# $NetBSD: Makefile,v 1.1 2026/08/27 01:23:15 gutteridge Exp $
+# $NetBSD: Makefile,v 1.2 2026/09/01 16:09:24 gutteridge Exp $
 
 FIREFOX_VER=           ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH=            153.1
+MOZ_BRANCH=            153.2
 MOZ_BRANCH_MINOR=      .0esr
 
 DISTNAME=      firefox-${FIREFOX_VER}.source
Index: pkgsrc/www/firefox153/distinfo
diff -u pkgsrc/www/firefox153/distinfo:1.1 pkgsrc/www/firefox153/distinfo:1.2
--- pkgsrc/www/firefox153/distinfo:1.1  Thu Aug 27 01:23:15 2026
+++ pkgsrc/www/firefox153/distinfo      Tue Sep  1 16:09:24 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.1 2026/08/27 01:23:15 gutteridge Exp $
+$NetBSD: distinfo,v 1.2 2026/09/01 16:09:24 gutteridge Exp $
 
-BLAKE2s (firefox-153.1.0esr.source.tar.xz) = ca9970e33602b727db1a1453ecb9541197d467f28afbe7b449f0498bfd722635
-SHA512 (firefox-153.1.0esr.source.tar.xz) = 0e5be18878a1bb8575d4ff03b499a092663fcd1779a05b59b82a8b663a3d7047cf3d6f971faeb3d1262f83b23022a703a2033e8ea38bcbd9c85f44bdd35d86c1
-Size (firefox-153.1.0esr.source.tar.xz) = 801285696 bytes
+BLAKE2s (firefox-153.2.0esr.source.tar.xz) = 3457f7e0f25e3a1f39403d5b0bed9ed1b933ce3f4b098b3d8ef55417a58c42df
+SHA512 (firefox-153.2.0esr.source.tar.xz) = a8cd4784bb52ca89c0fe37404e894c044f6145c62e9fcdeffe621fde81ae4602078be575e26c90d83e5e47f26675d3ee897cd6a20027d09d4ba7d0e785ce39bc
+Size (firefox-153.2.0esr.source.tar.xz) = 807705672 bytes
 BLAKE2s (nodejs-output-153.0.tgz) = 55a9ae8d1b743f57148a3b763bce2bc9afe2bd902f5b5d6a07a3e597c569aca1
 SHA512 (nodejs-output-153.0.tgz) = 2513c4c47c9bb619a1702a36b8ec316a6c48d6b641656abf86ff33c5ae9e146721947b26a3a1af8295a005daeffb0c77e5f82f36ca9a717decc6850b3518c275
 Size (nodejs-output-153.0.tgz) = 247910 bytes



Home | Main Index | Thread Index | Old Index