File _patchinfo of Package patchinfo.2738

<patchinfo incident="2738">
  <issue id="984006" tracker="bnc">AArch64: 64k page size was a bad idea</issue>
  <issue id="985659" tracker="bnc">AArch64: Firefox crashes in safe mode</issue>
  <issue id="983549" tracker="bnc">VUL-0: MozillaFirefox 47 / 45.2 ESR security release</issue>
  <issue id="982366" tracker="bnc">Unknown SSL protocol error in connection to &lt;server name&gt;</issue>
  <issue id="983651" tracker="bnc">VUL-0: CVE-2016-2824: MozillaFirefox: Out-of-bounds write with WebGL shader (MFSA 2016-53)</issue>
  <issue id="983643" tracker="bnc">VUL-0: CVE-2016-2831: MozillaFirefox: Entering fullscreen and persistent pointerlock without user permission (MFSA 2016-58)</issue>
  <issue id="983653" tracker="bnc">VUL-0: CVE-2016-2821: MozillaFirefox: Use-after-free deleting tables from a contenteditable document (MFSA 2016-51)</issue>
  <issue id="983652" tracker="bnc">VUL-0: CVE-2016-2822: MozillaFirefox: Addressbar spoofing though the SELECT element (MFSA 2016-52)</issue>
  <issue id="983655" tracker="bnc">VUL-0: CVE-2016-2819: MozillaFirefox: Buffer overflow parsing HTML5 fragments (MFSA 2016-50)</issue>
  <issue id="983646" tracker="bnc">VUL-0: CVE-2016-2828: MozillaFirefox: Use-after-free when textures are used in WebGL operations after recycle pool destruction (MFSA 2016-56)</issue>
  <issue id="983639" tracker="bnc">VUL-0: CVE-2016-2834: mozilla-nss: Memory safety bugs fixed in NSS 3.23 (MFSA 2016-61)</issue>
  <issue id="983638" tracker="bnc">VUL-0: CVE-2016-2815 CVE-2016-2818: MozillaFirefox: Miscellaneous memory safety hazards (rv:45.2) (MFSA 2016-49)</issue>
  <issue id="984126" tracker="bnc">AArch64: mozjs17 crashes when run on 4k kernel (polkitd, firefox)</issue>
  <issue id="CVE-2016-2834" tracker="cve" />
  <issue id="CVE-2016-2824" tracker="cve" />
  <issue id="CVE-2016-2822" tracker="cve" />
  <issue id="CVE-2016-2815" tracker="cve" />
  <issue id="CVE-2016-2821" tracker="cve" />
  <issue id="CVE-2016-2819" tracker="cve" />
  <issue id="CVE-2016-2818" tracker="cve" />
  <issue id="CVE-2016-2828" tracker="cve" />
  <issue id="CVE-2016-2831" tracker="cve" />
  <category>security</category>
  <rating>important</rating>
  <packager>cgrobertson</packager>
  <description>MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss and mozilla-nspr were updated to fix nine security issues.

MozillaFirefox was updated to version 45.2.0 ESR. mozilla-nss was updated to version 3.21.1.

These security issues were fixed:
- CVE-2016-2834: Memory safety bugs in NSS (MFSA 2016-61) (bsc#983639).
- CVE-2016-2824: Out-of-bounds write with WebGL shader (MFSA 2016-53) (bsc#983651).
- CVE-2016-2822: Addressbar spoofing though the SELECT element (MFSA 2016-52) (bsc#983652).
- CVE-2016-2821: Use-after-free deleting tables from a contenteditable document (MFSA 2016-51) (bsc#983653).
- CVE-2016-2819: Buffer overflow parsing HTML5 fragments (MFSA 2016-50) (bsc#983655).
- CVE-2016-2828: Use-after-free when textures are used in WebGL operations after recycle pool destruction (MFSA 2016-56) (bsc#983646).
- CVE-2016-2831: Entering fullscreen and persistent pointerlock without user permission (MFSA 2016-58) (bsc#983643).
- CVE-2016-2815, CVE-2016-2818: Miscellaneous memory safety hazards (MFSA 2016-49) (bsc#983638)
  
These non-security issues were fixed:
- bsc#982366: Unknown SSL protocol error in connections 
- Fix crashes on aarch64
  * Determine page size at runtime (bsc#984006)
  * Allow aarch64 to work in safe mode (bsc#985659)
- Fix crashes on mainframes

All extensions must now be signed by addons.mozilla.org. Please read README.SUSE for more details.
</description>
  <summary>Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss</summary>
</patchinfo>
openSUSE Build Service is sponsored by