Page 18 of 18

Re: MX 17/18 Repository: The Pale Moon Browser Thread

Posted: Wed Nov 10, 2021 5:58 pm
by Stevo
OK...all versions of 29.4.2, the new release, have built now, and we'll soon have the usual gtk2 version in main and the gtk3 version in the test repo for amd64 and i386 architectures.

Re: MX 17/18 Repository: The Pale Moon Browser Thread

Posted: Fri Jan 21, 2022 3:52 pm
by Stevo
29.4.4 GTK 2 packages are now in the main repository, with the GTK 3 versions in testing to allow the user to install either one.


* This is a security update:
- Improved application library loading security. DiD
- Fixed an issue in JavaScript serialization. DiD
- Fixed a potential out-of-bounds issue in IndexedDB. DiD
- Fixed a potential issue in widget data handling code. DiD
- Fixed potentially exploitable crashes in handling truncated/corrupt media
files or streams.
- Fixed an issue in the DOM FileReader code.
- Updated NSS to 3.52.3 to address a security issue.
- Fixed the following security issues: CVE-2022-22736, CVE-2022-22741,
CVE-2021-4140, CVE-2022-22746, CVE-2022-22744 and CVE-2022-22747.

Re: MX 17/18 Repository: The Pale Moon Browser Thread

Posted: Tue Mar 29, 2022 2:25 pm
by app4soft
Stevo wrote: Fri Jan 21, 2022 3:52 pm 29.4.4 GTK 2 packages are now in the main repository, with the GTK 3 versions in testing to allow the user to install either one.
Pale Moon 29.4.5.1 just released.

Please, Stevo, package it for MX-21 (GTK2/GTK3)
  • Release Notes: https://www.palemoon.org/releasenotes.shtml

    Code: Select all

    v29.4.5.1 (2022-03-29)
    This is a bugfix update to address performance issues due to caching.
    
    v29.4.5 (2022-03-23)
    This is a security update.
    
    Changes/fixes:
    
        Fixed several application crash scenarios. DiD
        Fixed a number of thread locking/mutex issues. DiD
        Fixed a leak of content types due to inconsistent error reporting. (CVE-2022-22760)
        Fixed an issue with iframe sandboxing not being properly applied. (CVE-2022-22759)
        Fixed a potential leak of bookmarks from the exported bookmarks file if it included a malicious bookmarklet.
        Fixed an issue with drag-and-drop. (CVE-2022-22756)
        Fixed a potential crash due to truncated WAV files.
        Fixed a memory safety issue with XSLT. (CVE-2022-26485)

Re: MX 17/18 Repository: The Pale Moon Browser Thread

Posted: Tue Mar 29, 2022 6:55 pm
by Stevo
Yeah, 29.4.5.1 x86 builds are uploaded for main--armhf packages take much longer to build.

I spent much time on the 29.4.5 packages only to have to pull them from the repo due to the bug.