#19792 closed enhancement (fixed)
firefox-115.11.0
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.2 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version
Change History (5)
comment:1 by , 2 years ago
| Priority: | normal → elevated |
|---|
comment:2 by , 2 years ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 2 years ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 5e1176ac87ff68373b966a4c7e2f3c025bde0134
I'll file a SA and put the release notes in tomorrow.
comment:4 by , 2 years ago
Release notes:
- Various security fixes and other quality improvements.
Security Fixes:
- CVE-2024-4367: Arbitrary JavaScript execution in PDF.js (High)
- CVE-2024-4767: IndexedDB files retained in private browsing mode (Moderate)
- CVE-2024-4768: Potential permissions request bypass via clickjacking (Moderate)
- CVE-2024-4769: Cross-origin responses could be distinguished between script and non-script content-types (Moderate)
- CVE-2024-4770: Use-after-free could occur when printing to PDF (Moderate)
- CVE-2024-4777: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (Moderate)
Note:
See TracTickets
for help on using tickets.

Elevating due to security issues