Gentoo Archives: gentoo-commits

From: "Ian Stakenvicius (axs)" <axs@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] gentoo-x86 commit in www-client/firefox-bin/files: all-gentoo-1-cve-2015-4000.js
Date: Sun, 31 May 2015 14:20:13
Message-Id: 20150531142009.54402A18@oystercatcher.gentoo.org
1 axs 15/05/31 14:20:09
2
3 Added: all-gentoo-1-cve-2015-4000.js
4 Log:
5 disabled ssl3.dhe_* in prefs to prevent Logjam, bug 550288
6
7 (Portage version: 2.2.18/cvs/Linux x86_64, signed Manifest commit with key 2B6559ED)
8
9 Revision Changes Path
10 1.1 www-client/firefox-bin/files/all-gentoo-1-cve-2015-4000.js
11
12 file : http://sources.gentoo.org/viewvc.cgi/gentoo-x86/www-client/firefox-bin/files/all-gentoo-1-cve-2015-4000.js?rev=1.1&view=markup
13 plain: http://sources.gentoo.org/viewvc.cgi/gentoo-x86/www-client/firefox-bin/files/all-gentoo-1-cve-2015-4000.js?rev=1.1&content-type=text/plain
14
15 Index: all-gentoo-1-cve-2015-4000.js
16 ===================================================================
17 // Ensure preference cann't be changed by users
18 lockPref("app.update.auto", false);
19 lockPref("app.update.enabled", false);
20 lockPref("intl.locale.matchOS", true);
21 // Allow user to change based on needs
22 defaultPref("browser.display.use_system_colors", true);
23 defaultPref("spellchecker.dictionary_path", "/usr/share/myspell");
24 defaultPref("browser.shell.checkDefaultBrowser", false);
25 // Preferences that should be reset every session
26 pref("browser.EULA.override", true);
27 // CVE-2015-4000 - prevent Logjam attack vector
28 lockPref("security.ssl3.dhe_rsa_aes_128_sha", false);
29 lockPref("security.ssl3.dhe_rsa_aes_256_sha", false);