GNU bug report logs - #76189
[PATCH] gnu: librewolf: Update to 135.0-1 [security fixes].

Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.

Package: guix-patches; Reported by: Ian Eure <ian@HIDDEN>; Keywords: patch; Done: Ian Eure <ian@HIDDEN>; Maintainer for guix-patches is guix-patches@HIDDEN.
bug closed, send any further explanations to 76189 <at> debbugs.gnu.org and Ian Eure <ian@HIDDEN> Request was from Ian Eure <ian@HIDDEN> to control <at> debbugs.gnu.org. Full text available.

Message received at submit <at> debbugs.gnu.org:


Received: (at submit) by debbugs.gnu.org; 11 Feb 2025 01:56:26 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Mon Feb 10 20:56:26 2025
Received: from localhost ([127.0.0.1]:53160 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1thfVh-0008RB-RI
	for submit <at> debbugs.gnu.org; Mon, 10 Feb 2025 20:56:26 -0500
Received: from lists.gnu.org ([2001:470:142::17]:57604)
 by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.84_2) (envelope-from <ian@HIDDEN>) id 1thfVc-0008Qq-86
 for submit <at> debbugs.gnu.org; Mon, 10 Feb 2025 20:56:22 -0500
Received: from eggs.gnu.org ([2001:470:142:3::10])
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ian@HIDDEN>) id 1thfVV-0002T9-8B
 for guix-patches@HIDDEN; Mon, 10 Feb 2025 20:56:13 -0500
Received: from fhigh-a8-smtp.messagingengine.com ([103.168.172.159])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ian@HIDDEN>) id 1thfVR-0005ZO-O8
 for guix-patches@HIDDEN; Mon, 10 Feb 2025 20:56:13 -0500
Received: from phl-compute-01.internal (phl-compute-01.phl.internal
 [10.202.2.41])
 by mailfhigh.phl.internal (Postfix) with ESMTP id 8E987114022F;
 Mon, 10 Feb 2025 20:56:07 -0500 (EST)
Received: from phl-mailfrontend-02 ([10.202.2.163])
 by phl-compute-01.internal (MEProxy); Mon, 10 Feb 2025 20:56:07 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h=
 cc:cc:content-transfer-encoding:content-type:date:date:from:from
 :in-reply-to:message-id:mime-version:reply-to:subject:subject:to
 :to; s=fm2; t=1739238967; x=1739325367; bh=jbA5fkJAl/tEhzrfaYCRb
 OGy+H6DpFnPVaiHIuQBkJg=; b=isLqLsJ1f+Md3dCSjPE8K+ZDwrQhM2hMu/Fdf
 QxFanazEgrLhz62wF7/PoWWycY/vNYjoDpPgQQQqTLClePKcms4ugnb1SJ9dv/e/
 LnSyMKpvmVTX02F8gVqOWKQhtKBsDQPo/s6AKskDBlp03Ifsr+jdkIvS9B5BoSko
 HQ/2wn7Rl9CvO3Y4m1L5aKSFvkTMpJi1/VCkOEp66unmHRNjYQvlJc8TMKPyrGSa
 XfVrcMLLAkaUE97BuIwl7TeYaDJlNA3pGPjQ31HsCNrYE130CG7TJbwN5Ctlt4Bm
 TcGAEZ+9VqMIk/yTp+zkpjbz/YmDSW7aoLGoUh+9fx1wITziQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:cc:content-transfer-encoding
 :content-type:date:date:feedback-id:feedback-id:from:from
 :in-reply-to:message-id:mime-version:reply-to:subject:subject:to
 :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t=
 1739238967; x=1739325367; bh=jbA5fkJAl/tEhzrfaYCRbOGy+H6DpFnPVai
 HIuQBkJg=; b=yzPK2duj7X7hHfnANYvXlCbEf04QMbP2Rv1d+49V4I+fLPGLt8a
 eTAGdVtIm3dY+gQnX1AH1ojNl1tDKe8jnCqfFRonLE/H5sOOWRfNunH2ztDvbgBX
 4nzD1Sm+zJofy3TowB8j1zhTUQVfPlXqtQfQJM+bbXq9QVLiHW0pkz81lISJOIs5
 xiKc38rOylsYQEBIJN0XayH+vdvlFKgscNBfK0DwwQlh7prc6T6z5VVunlfhqIVh
 0hJQYAmVEmMWQ16bUVXEzRso62KzbToIe3i505UJ+lDSyeQBe6G1aarkBeVoZkU8
 LZWc/VZo2dXS6TwybMTzYivMtayVl45sWkQ==
X-ME-Sender: <xms:N66qZ81fho6RKQXdfo2uGdVprfKIaVXdl7NQN2wK7hgZ-VEvi1VkOg>
 <xme:N66qZ3EUO8h4aaCXsFkiw85KK0zv5bSuA4uuzK4LtsHmnbHSrszCO8Xh-0pTxfD6O
 t5uA3yi1UsfFdxrJg>
X-ME-Received: <xmr:N66qZ06SESMgLLg6JNkqtvqtFuyO1FuzfPd2gz9Gx2zxoKdgeTUUqu70mvVQCQI6nBkwBPTkirbvvw9jwPwb5Y3PVSfx6M6mHMYTD8gVNeP8zS1SEOrYjg>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefvddrtddtgdefleejvdcutefuodetggdotefrod
 ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp
 uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhephffvve
 fufffkofgggfestdekredtredttdenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhes
 rhgvthhrohhsphgvtgdrthhvqeenucggtffrrghtthgvrhhnpefgvdejhfelhfeftdeile
 elfedvhfefffetfeeuteelgfdvleffleevgfefueekjeenucffohhmrghinhepmhhoiihi
 lhhlrgdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh
 hrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvhdpnhgspghrtghpthhtohepvddpmhho
 uggvpehsmhhtphhouhhtpdhrtghpthhtohepghhuihigqdhprghttghhvghssehgnhhurd
 horhhgpdhrtghpthhtohepihgrnhesrhgvthhrohhsphgvtgdrthhv
X-ME-Proxy: <xmx:N66qZ13LuIBNUMasTB5PLHcKOdua_yjnijES1YvYfk2ifu6ctDEEdQ>
 <xmx:N66qZ_HoYzHVz6WiSM0y2JwIifmnDfF4KTZaMCdBsjXkxN3itKS8JQ>
 <xmx:N66qZ-9Q5Qc7wTLf0P1gujEx42OzlnlMbRhsHmUKFzXbDcziFAsPeA>
 <xmx:N66qZ0nBS7Q776OuVBUaLB_PoNtburFrSFSOp5j4AmuHoT9O2dKGlA>
 <xmx:N66qZ0TDLoLm8v7lyGhW5bCJEzqhgSj1_iCDrPB-QJ-I51wNKBHr08Oc>
Feedback-ID: id9014242:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon,
 10 Feb 2025 20:56:06 -0500 (EST)
From: Ian Eure <ian@HIDDEN>
To: guix-patches@HIDDEN
Subject: [PATCH] gnu: librewolf: Update to 135.0-1 [security fixes].
Date: Mon, 10 Feb 2025 17:55:34 -0800
Message-ID: <20250211015602.4658-1-ian@HIDDEN>
X-Mailer: git-send-email 2.48.1
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Received-SPF: pass client-ip=103.168.172.159; envelope-from=ian@HIDDEN;
 helo=fhigh-a8-smtp.messagingengine.com
X-Spam_score_int: -27
X-Spam_score: -2.8
X-Spam_bar: --
X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001,
 RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_PASS=-0.001,
 SPF_PASS=-0.001 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: 0.7 (/)
X-Debbugs-Envelope-To: submit
Cc: Ian Eure <ian@HIDDEN>
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -0.3 (/)

New upstream version.  Contains fixes for:

CVE-2025-1009: Use-after-free in XSLT
CVE-2025-1010: Use-after-free in Custom Highlight
CVE-2025-1018: Fullscreen notification is not displayed when
               fullscreen is re-requested
CVE-2025-1011: A bug in WebAssembly code generation could result in a
               crash
CVE-2025-1012: Use-after-free during concurrent delazification
CVE-2025-1019: Fullscreen notification not properly displayed
CVE-2025-1013: Potential opening of private browsing tabs in normal
               browsing windows
CVE-2025-1014: Certificate length was not properly checked
CVE-2025-1016: Memory safety bugs fixed in Firefox 135, Thunderbird
               135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird
               115.20, and Thunderbird 128.7
CVE-2025-1017: Memory safety bugs fixed in Firefox 135, Thunderbird
               135, Firefox ESR 128.7, and Thunderbird 128.7
CVE-2025-1020: Memory safety bugs fixed in Firefox 135 and Thunderbird
               135

* gnu/packages/librewolf.scm (librewolf): Update to 135.0-1.

Change-Id: I7054fc9df31d59bb0d42e02b1f359cf3e6c1a43d
---
 gnu/packages/librewolf.scm | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/gnu/packages/librewolf.scm b/gnu/packages/librewolf.scm
index 59c7e3a4a3..e5e91fb91e 100644
--- a/gnu/packages/librewolf.scm
+++ b/gnu/packages/librewolf.scm
@@ -200,22 +200,23 @@ (define* (make-librewolf-source #:key version firefox-hash librewolf-hash l10n)
 ;;; but since in Guix only the latest packaged Rust is officially supported,
 ;;; it is a tradeoff worth making.
 ;;; 0: https://firefox-source-docs.mozilla.org/writing-rust-code/update-policy.html
-(define rust-librewolf rust-1.81)
+;; 135.0 wants 1.83, but it's not available in Guix yet.
+(define rust-librewolf rust-1.82)
 
 ;; Update this id with every update to its release date.
 ;; It's used for cache validation and therefore can lead to strange bugs.
 ;; ex: date '+%Y%m%d%H%M%S'
-(define %librewolf-build-id "20250121184331")
+(define %librewolf-build-id "20250209210057")
 
 (define-public librewolf
   (package
     (name "librewolf")
-    (version "134.0.2-1")
+    (version "135.0-1")
     (source
      (make-librewolf-source
       #:version version
-      #:firefox-hash "09yxacfcklgjqbqvcac32llwmlb16d9jhfp2mif9qs7s2gzvfvkc"
-      #:librewolf-hash "1qa3crgazfvmsqx8dm0k78yk9cb11w1lf74x6x8ixjq5ifsdh1ws"
+      #:firefox-hash "0q5r2q6q56kyzl5pknrir9bzlhmzbvv9hi5gi4852izgcali4zl2"
+      #:librewolf-hash "0fg4vji5xb17pgvq7jnfz4dq08gi0rl998xhj37hfm5zxs19y8jk"
       #:l10n firefox-l10n))
     (build-system gnu-build-system)
     (arguments
-- 
2.48.1





Acknowledgement sent to Ian Eure <ian@HIDDEN>:
New bug report received and forwarded. Copy sent to guix-patches@HIDDEN. Full text available.
Report forwarded to guix-patches@HIDDEN:
bug#76189; Package guix-patches. Full text available.
Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.
Last modified: Sat, 15 Feb 2025 00:15:02 UTC

GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997 nCipher Corporation Ltd, 1994-97 Ian Jackson.