File _patchinfo of Package patchinfo.16571
<patchinfo incident="16571">
<issue tracker="bnc" id="1176756">VUL-0: CVE-2020-15675,CVE-2020-15677,CVE-2020-15676,CVE-2020-15678,CVE-2020-15673: MozillaFirefox: Update to 78.3.0 ESR / 81.0</issue>
<issue tracker="bnc" id="1174420">Firefox 78 ESR menu is displaced when running Gnome on Wayland</issue>
<issue tracker="bnc" id="1167976">Default install of Tumbleweed; Firefox starts out with Taiwanese bookmarks</issue>
<issue tracker="bnc" id="1173986">MozillaFirefox - langpack build takes long time</issue>
<issue tracker="cve" id="2020-15678"/>
<issue tracker="cve" id="2020-15673"/>
<issue tracker="cve" id="2020-15677"/>
<issue tracker="cve" id="2020-15676"/>
<packager>MSirringhaus</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for MozillaFirefox</summary>
<description>This update for MozillaFirefox fixes the following issues:
-Firefox was updated to 78.3.0 ESR (bsc#1176756, MFSA 2020-43)
- CVE-2020-15677: Download origin spoofing via redirect
- CVE-2020-15676: Fixed an XSS when pasting attacker-controlled data into a
contenteditable element
- CVE-2020-15678: When recursing through layers while scrolling, an iterator
may have become invalid, resulting in a potential use-after-free scenario
- CVE-2020-15673: Fixed memory safety bugs
- Enhance fix for wayland-detection (bsc#1174420)
- Attempt to fix langpack-parallelization by introducing separate
obj-dirs for each lang (bsc#1173986, bsc#1167976)
</description>
</patchinfo>