all messages for Guix-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
From: Ian Eure <ian@retrospec.tv>
To: 71832@debbugs.gnu.org
Cc: Ian Eure <ian@retrospec.tv>, guix-security@gnu.org
Subject: [bug#71832] [PATCH v6 0/3] [SECURITY] Update LibreWolf to 129.0.1-1; add nss-rapid
Date: Sat, 17 Aug 2024 12:32:37 -0700	[thread overview]
Message-ID: <20240817193240.27089-1-ian@retrospec.tv> (raw)
In-Reply-To: <20240629035716.21504-1-ian@retrospec.tv>

vs. the previous versions of this patch series, v6:

- Updates LibreWolf to 129.0.1-1, the latest upstream.
- Updates nss-rapid, to version 3.103, the latest upstream.
- Adds the skr locale to all-mozilla-locales.
- Backs out improvements not directly related to updating the browser version, to make review easier.

In addition to the CVEs fixed in 128.0, this includes fixes for[1]:

    CVE-2024-7518: Fullscreen notification dialog can be obscured by document content
    CVE-2024-7519: Out of bounds memory access in graphics shared memory handling
    CVE-2024-7520: Type confusion in WebAssembly
    CVE-2024-7521: Incomplete WebAssembly exception handing
    CVE-2024-7522: Out of bounds read in editor component
    CVE-2024-7523: Document content could partially obscure security prompts
    CVE-2024-7524: CSP strict-dynamic bypass using web-compatibility shims
    CVE-2024-7525: Missing permission check when creating a StreamFilter
    CVE-2024-7526: Uninitialized memory used by WebGL
    CVE-2024-7527: Use-after-free in JavaScript garbage collection
    CVE-2024-7528: Use-after-free in IndexedDB
    CVE-2024-7529: Document content could partially obscure security prompts
    CVE-2024-7530: Use-after-free in JavaScript code coverage collection
    CVE-2024-7531: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge

[1]: https://www.mozilla.org/en-US/security/advisories/mfsa2024-33/

Ian Eure (3):
  gnu: gnuzilla: Add skr to all-mozilla-locales.
  gnu: Add nss-rapid.
  gnu: librewolf: Update to 129.0.1-1.

 gnu/packages/gnuzilla.scm  |  1 +
 gnu/packages/librewolf.scm | 12 +++----
 gnu/packages/nss.scm       | 67 ++++++++++++++++++++++++++++++++++++++
 3 files changed, 74 insertions(+), 6 deletions(-)

--
2.45.2




  parent reply	other threads:[~2024-08-17 19:33 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-06-29  3:57 [bug#71832] [PATCH 0/2] Add nss-latest; updte Librewolf to 127.0.2-2 Ian Eure
2024-06-29  3:59 ` [bug#71832] [PATCH 1/2] gnu: Add nss-latest Ian Eure
2024-06-29  3:59   ` [bug#71832] [PATCH 2/2] gnu: librewolf: Update to 127.0.2-1 Ian Eure
2024-06-29 17:22 ` [bug#71832] [PATCH v2 0/2] Add nss-latest; update Librewolf to 127.0.2-2 Ian Eure
2024-06-29 17:22   ` [bug#71832] [PATCH v2 1/2] gnu: Add nss-latest Ian Eure
2024-06-29 17:22   ` [bug#71832] [PATCH v2 2/2] gnu: librewolf: Update to 127.0.2-1 Ian Eure
2024-07-02  0:21 ` [bug#71832] [PATCH v3 0/2] Add nss-rapid; updte Librewolf to 127.0.2-2 Ian Eure
2024-07-02  0:21   ` [bug#71832] [PATCH v3 1/2] gnu: Add nss-rapid Ian Eure
2024-07-02  0:21   ` [bug#71832] [PATCH v3 2/2] gnu: librewolf: Update to 127.0.2-1 Ian Eure
2024-07-08  8:55 ` [bug#71832] Closing one bug Andreas Enge
2024-07-01 19:53   ` [bug#71882] [PATCH] gnu: librewolf: Fix building on aarch64-linux Remco van 't Veer
     [not found]     ` <handler.71882.D71882.172042897930179.notifdone@debbugs.gnu.org>
2024-07-08 10:16       ` [bug#71882] closed (Closing one bug) Remco van 't Veer
2024-07-17  3:06 ` [bug#71832] [PATCH v4 0/3] Add nss-rapid; update Librewolf to 128.0-2 Ian Eure
2024-07-17  3:06   ` [bug#71832] [PATCH v4 1/3] gnu: Add nss-rapid Ian Eure
2024-07-17  3:06   ` [bug#71832] [PATCH v4 2/3] gnu: gnuzilla: Add skr to all-mozilla-locales Ian Eure
2024-07-17  3:06   ` [bug#71832] [PATCH v4 3/3] gnu: librewolf: Update to 128.0-2 Ian Eure
2024-07-21 16:17 ` [bug#71832] [PATCH 0/2] Add nss-latest; updte Librewolf to 127.0.2-2 Ian Eure
2024-07-31  3:54 ` [bug#71832] [PATCH v5 0/3] [SECURITY] Add nss-rapid; update Librewolf to 128.0.3-1 Ian Eure
2024-07-31  3:54   ` [bug#71832] [PATCH v5 1/3] gnu: Add nss-rapid Ian Eure
2024-07-31  3:55   ` [bug#71832] [PATCH v5 2/3] gnu: gnuzilla: Add skr to all-mozilla-locales Ian Eure
2024-07-31  3:55   ` [bug#71832] [PATCH v5 3/3] gnu: librewolf: Update to 128.0.3-1 Ian Eure
2024-08-17 19:32 ` Ian Eure [this message]
2024-08-17 19:32   ` [bug#71832] [PATCH v6 1/3] gnu: gnuzilla: Add skr to all-mozilla-locales Ian Eure
2024-08-17 19:32   ` [bug#71832] [PATCH v6 2/3] gnu: Add nss-rapid Ian Eure
2024-08-17 22:46     ` Vagrant Cascadian
2024-08-17 23:33       ` Vagrant Cascadian
2024-08-17 23:51         ` Ian Eure
2024-08-18  2:00           ` Vagrant Cascadian
2024-08-18  3:38     ` Vagrant Cascadian
2024-08-18  3:48       ` Ian Eure
2024-08-17 19:32   ` [bug#71832] [PATCH v6 3/3] gnu: librewolf: Update to 129.0.1-1 Ian Eure
2024-08-18  3:46   ` [bug#71832] [PATCH v6 0/3] [SECURITY] Update LibreWolf to 129.0.1-1; add nss-rapid Vagrant Cascadian
2024-08-20  5:46     ` bug#71832: " Vagrant Cascadian

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240817193240.27089-1-ian@retrospec.tv \
    --to=ian@retrospec.tv \
    --cc=71832@debbugs.gnu.org \
    --cc=guix-security@gnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/guix.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.