Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package mozjs102 for openSUSE:Factory checked in at 2022-12-15 19:24:25 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/mozjs102 (Old) and /work/SRC/openSUSE:Factory/.mozjs102.new.1835 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "mozjs102" Thu Dec 15 19:24:25 2022 rev:6 rq:1042963 version:102.6.0 Changes: -------- --- /work/SRC/openSUSE:Factory/mozjs102/mozjs102.changes 2022-11-22 16:09:37.449859739 +0100 +++ /work/SRC/openSUSE:Factory/.mozjs102.new.1835/mozjs102.changes 2022-12-15 19:24:34.639841968 +0100 @@ -1,0 +2,17 @@ +Wed Dec 14 10:31:25 UTC 2022 - Bjørn Lie <bjorn....@gmail.com> + +- Update to version 102.6.0: + + Various stability, functionality, and security fixes. + + CVE-2022-46880: Use-after-free in WebGL. + + CVE-2022-46872: Arbitrary file read from a compromised content + process. + + CVE-2022-46881: Memory corruption in WebGL. + + CVE-2022-46874: Drag and Dropped Filenames could have been + truncated to malicious extensions. + + CVE-2022-46875: Download Protections were bypassed by .atloc + and .ftploc files on Mac OS. + + CVE-2022-46882: Use-after-free in WebGL. + + CVE-2022-46878: Memory safety bugs fixed in Firefox 108 and + Firefox ESR 102.6. + +------------------------------------------------------------------- Old: ---- firefox-102.5.0esr.source.tar.xz firefox-102.5.0esr.source.tar.xz.asc New: ---- firefox-102.6.0esr.source.tar.xz firefox-102.6.0esr.source.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ mozjs102.spec ++++++ --- /var/tmp/diff_new_pack.iRF2A1/_old 2022-12-15 19:24:38.983866684 +0100 +++ /var/tmp/diff_new_pack.iRF2A1/_new 2022-12-15 19:24:38.995866752 +0100 @@ -39,7 +39,7 @@ %global big_endian 1 %endif Name: mozjs%{major} -Version: 102.5.0 +Version: 102.6.0 Release: 1%{?dist} Summary: SpiderMonkey JavaScript library License: MPL-2.0 ++++++ firefox-102.5.0esr.source.tar.xz -> firefox-102.6.0esr.source.tar.xz ++++++ /work/SRC/openSUSE:Factory/mozjs102/firefox-102.5.0esr.source.tar.xz /work/SRC/openSUSE:Factory/.mozjs102.new.1835/firefox-102.6.0esr.source.tar.xz differ: char 15, line 1