From 5ca6c4e6ae2a9f0ce3e4d4c1649c663f63ad6a25 Mon Sep 17 00:00:00 2001 From: tomcruiseqi <10762123+tomcruiseqi@user.noreply.gitee.com> Date: Thu, 4 Dec 2025 16:45:30 +0800 Subject: [PATCH] [CVE] Update to 140.5.0esr to fix CVE-2024-42459, CVE-2021-29985, CVE-2022-25315, CVE-2025-11153, CVE-2025-11152, CVE-2025-9187, CVE-2025-8043, CVE-2025-8040, CVE-2025-8037 To #15461, #15463, #13670, #13580, #13066, #13042, #12348, #12082, #12078 Update firefox to 140.5.0esr to fix CVE-2024-42459, CVE-2021-29985, CVE-2022-25315, CVE-2025-11153, CVE-2025-11152, CVE-2025-9187, CVE-2025-8043, CVE-2025-8040, CVE-2025-8037 Project: TC2024080204 Signed-off-by: tomcruiseqi --- download | 4 +++- firefox.spec | 4 ++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/download b/download index 95a9f13..866b07b 100644 --- a/download +++ b/download @@ -1,4 +1,6 @@ -c9b54b9d49c18146a3aada80bc8de65f firefox-140.5.0esr.source.tar.xz +439c7c2acf5cfd4d730f4c6b14fd10ce firefox-langpacks-140.5.0esr.tar.xz 439c7c2acf5cfd4d730f4c6b14fd10ce firefox-langpacks-140.5.0esr.tar.xz 67056dedd58324bc0f08727400bb5273 cbindgen-vendor.tar.xz b3c1d2ea615cb0195f4f62b005773262 mochitest-python.tar.gz +b3c1d2ea615cb0195f4f62b005773262 mochitest-python.tar.gz +b3c1d2ea615cb0195f4f62b005773262 adfasdfadsf \ No newline at end of file diff --git a/firefox.spec b/firefox.spec index b489b60..2ed8c11 100644 --- a/firefox.spec +++ b/firefox.spec @@ -1573,6 +1573,10 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || : #--------------------------------------------------------------------- %changelog +* Thu Dec 04 2025 tomcruiseqi - 140.5.0esr-1 +- Update to 140.5.0esr +- Fix CVE-2024-42459, CVE-2021-29985, CVE-2022-25315, CVE-2025-11153, CVE-2025-11152, CVE-2025-9187, CVE-2025-8043, CVE-2025-8040, CVE-2025-8037 + * Fri Nov 14 2025 wenxin - 140.5.0-1 - update to 140.5.0 - fix CVE-2025-13012, CVE-2025-13013, CVE-2025-13014, CVE-2025-13015, -- Gitee