#12242 closed enhancement (fixed)
firefox-68.0
Reported by: | Owned by: | ||
---|---|---|---|
Priority: | high | Milestone: | 9.0 |
Component: | BOOK | Version: | SVN |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
Release is nominally Tuesday (which it now is, in my TZ), but the source has been there for a few hours.
Apart from needing a newer rust, changes to shipped versions include harfbuzz-2.4.0, icu-64.2 (although it still only seems to test for >= 63.1 in the system version when I looked), libpng-1.6.37, nss-3.44.1, sqlite-3.28.0. In external deps, cbindgen needs to be >= 0.8.7.
The options to enable|disable gconf have been removed.
Until the Release Notes appear, no idea what mozilla regard as the significant changes, nor if there are any new CVE fixes.
Change History (4)
comment:1 by , 6 years ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 6 years ago
comment:4 by , 6 years ago
Priority: | normal → high |
---|
And lo, a list of vulnerabilities did appear.
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/
Various CVEs rated as moderate - I think the moderate vulnerabilities include the item mentioned above, but there are also high risk and critical fixes.
From the Release Notes: (comments in parenthesis are min)
This is also the start of the next Extended Support Release (esr)
Fixed