File _patchinfo of Package patchinfo.8563

<patchinfo incident="8563">
  <issue tracker="bnc" id="1098998">VUL-0: MozillaFirefox: 52.9esr/60.1.0esr/61 release</issue>
  <issue tracker="bnc" id="1020631">configure script can not detect the correct icu version with sed 4.3</issue>
  <issue tracker="bnc" id="1077291">VUL-0: MozillaFirefox: 58 / 52.6.0 ESR release</issue>
  <issue tracker="bnc" id="1062195">seamonkey 2.49.1 translation common / -other package doesn't contain files</issue>
  <issue tracker="bnc" id="1076907">package MozillaFirefox does not provide mimehandler(text/html)</issue>
  <issue tracker="cve" id="2018-12362"/>
  <issue tracker="cve" id="2018-12363"/>
  <issue tracker="cve" id="2018-12360"/>
  <issue tracker="cve" id="2018-12366"/>
  <issue tracker="cve" id="2018-12364"/>
  <issue tracker="cve" id="2018-12365"/>
  <issue tracker="cve" id="2018-12359"/>
  <issue tracker="cve" id="2018-5188"/>
  <issue tracker="cve" id="2018-5156"/>
  <category>security</category>
  <rating>important</rating>
  <packager>wrosenauer</packager>
  <description>This update for seamonkey fixes the following issues:

Mozilla Seamonkey was updated to 2.49.4:

Now uses Gecko 52.9.1esr (boo#1098998).

Security issues fixed with MFSA 2018-16 (boo#1098998):

* CVE-2018-12359: Buffer overflow using computed size of canvas element
* CVE-2018-12360: Use-after-free when using focus()
* CVE-2018-12362: Integer overflow in SSSE3 scaler
* CVE-2018-5156: Media recorder segmentation fault when track type is changed during capture
* CVE-2018-12363: Use-after-free when appending DOM nodes
* CVE-2018-12364: CSRF attacks through 307 redirects and NPAPI plugins
* CVE-2018-12365: Compromised IPC child process can list local filenames
* CVE-2018-12366: Invalid data handling during QCMS transformations
* CVE-2018-5188: Memory safety bugs fixed in Firefox 60, Firefox ESR 60.1, and Firefox ESR 52.9

Localizations finally included again (boo#1062195)

Updated summary and description to more accurately
reflect what SeaMonkey is, giving less prominence to the long-
discontinued Mozilla Application Suite that many users may no
longer be familiar with

Update to Seamonkey 2.49.2

* Gecko 52.6esr (including security relevant fixes) (boo#1077291)
* fix issue in Composer
* With some themes, the menulist- and history-dropmarker didn't show
* Scrollbars didn't show the buttons
* WebRTC has been disabled by default. It needs an add-on to enable it per site
* The active title bar was not visually emphasized

Correct requires and provides handling (boo#1076907)
</description>
  <summary>Security update for seamonkey</summary>
</patchinfo>
openSUSE Build Service is sponsored by