summaryrefslogtreecommitdiff
path: root/gnu/packages/patches/erlang-man-path.patch
diff options
context:
space:
mode:
authorIan Eure <ian@retrospec.tv>2024-09-23 07:47:05 -0700
committerAndrew Tropin <andrew@trop.in>2024-09-24 11:03:22 +0400
commitaa250f071a89a7a06bbb453325240a9d4a59c2a9 (patch)
tree830317f5833271ad778b97680f30dfc72e03213d /gnu/packages/patches/erlang-man-path.patch
parent35c5a0759355cea007c55594d0575796390c39bb (diff)
gnu: librewolf: Update to 130.0.1-1. [security fixes]
This patch: - Updates LibreWolf to the latest version - Removes the code which disabled encoding_rs.patch from upstream. It’s no longer in the repo, so the code did nothing, and the underlying issue (Guix being stuck with an old Rust version) has been fixed. - Integrates changes from #72265 with some slight tweaks. This should allow LibreWolf to use accelerated video decoding on supported hardware. - Neuters the GenAI chat feature, which direcly integrates with non-free services, by excluding it from the build and locking the preferences which would enable it. Fixes: CVE-2024-8385: WASM type confusion involving ArrayTypes CVE-2024-8381: Type confusion when looking up a property name in a "with" block CVE-2024-8388: Fullscreen notice on Android could be hidden under various panels and OS prompts CVE-2024-8382: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran CVE-2024-8383: Firefox did not ask before openings news: links in an external application CVE-2024-8384: Garbage collection could mis-color cross-compartment objects in OOM conditions CVE-2024-8386: SelectElements could be shown over another site if popups are allowed CVE-2024-8387: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2 CVE-2024-8389: Memory safety bugs fixed in Firefox 130 * gnu/packages/librewolf.scm (librewolf): Update to 130.0.1-1. Change-Id: I764e6e66c5bfdc14a87b7ea59c29780a1f16769a Signed-off-by: Andrew Tropin <andrew@trop.in>
Diffstat (limited to 'gnu/packages/patches/erlang-man-path.patch')
0 files changed, 0 insertions, 0 deletions