#18310 closed enhancement (fixed)

firefox-115.1.0 (was 115.0.3)

Reported by: Bruce Dubbs Owned by: ken@…
Priority: elevated Milestone: 12.0
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (13)

comment:1 by ken@…, 14 months ago

At the moment this seems to only be for esr. There is a link on the Release Notes page, but it 404s.

diffing from 115.0.2esr, the only changes are to the version, milestones, and the commit for the sourcestamp.

comment:2 by Douglas R. Reno, 14 months ago

Milestone: 11.499-Waiting
Summary: firefox-115.0.3firefox-115.0.3 (Wait for next version)

This appears to be Windows specific (and only for people that use certain Antivirus software): https://www.mozilla.org/en-US/firefox/115.0.3esr/releasenotes/

comment:3 by ken@…, 14 months ago

Milestone: 99-Waiting11.4
Owner: changed from blfs-book to ken@…
Summary: firefox-115.0.3 (Wait for next version)firefox-115.1.0 (was 115.0.3)

115.1.0esr is now available.

comment:4 by ken@…, 14 months ago

Status: newassigned

comment:6 by Douglas R. Reno, 14 months ago

I just got the official Mozilla release announcement about two hours ago, the versioning is weird

They are at https://www.mozilla.org/en-US/firefox/115.1esr/releasenotes/

comment:7 by Douglas R. Reno, 14 months ago

There are quite a few high fixes sitting in there

in reply to:  7 comment:8 by ken@…, 14 months ago

Replying to Douglas R. Reno:

There are quite a few high fixes sitting in there

Thanks, for some reason the links that google gives me for 115-series seem to always 404.

comment:9 by ken@…, 14 months ago

https://www.mozilla.org/en-US/security/advisories/mfsa2023-31/

eight items rated as High:

CVE-2023-4045: Offscreen Canvas could have bypassed cross-origin restrictions High

CVE-2023-4046: Incorrect value used during WASM compilation

CVE-2023-4047: Potential permissions request bypass via clickjacking

CVE-2023-4048: Crash in DOMParser due to out-of-memory conditions

CVE-2023-4049: Fix potential race conditions when releasing platform objects

CVE-2023-4050: Stack buffer overflow in StorageManager

CVE-2023-4056: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14

CVE-2023-4057: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1

But the first cannot apply to BLFS because we lack the packages (and static libz.a) needed to use wasm.

comment:10 by ken@…, 14 months ago

Priority: normalelevated

comment:11 by ken@…, 14 months ago

Book updated at sha:f11dce689e 11.3-1213

comment:12 by Bruce Dubbs, 14 months ago

Milestone: 11.412.0

Milestone renamed

comment:13 by ken@…, 14 months ago

Resolution: fixed
Status: assignedclosed

Security Advisory SA 11.3-068 created.

Note: See TracTickets for help on using tickets.