MGASA-2018-0420 - Updated firefox packages fix security vulnerabilities

Publication date: 27 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0420.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-12389,
     CVE-2018-12390,
     CVE-2018-12392,
     CVE-2018-12393,
     CVE-2018-12395,
     CVE-2018-12396,
     CVE-2018-12397

Updated firefox packages fix security vulnerabilities:

Mozilla: Memory safety bugs fixed in Firefox ESR 60.3 (CVE-2018-12389).

Mozilla: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3
(CVE-2018-12390).

Mozilla: Crash with nested event loops (CVE-2018-12392).

Mozilla: Integer overflow during Unicode conversion while loading
JavaScript (CVE-2018-12393).

Mozilla: WebExtension bypass of domain restrictions through header
rewriting (CVE-2018-12395).

Mozilla: WebExtension content scripts can execute in disallowed contexts
(CVE-2018-12396).

Mozilla: WebExtension local file permission check bypass (CVE-2018-12397).

References:
- https://bugs.mageia.org/show_bug.cgi?id=23751
- https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/
- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
- https://access.redhat.com/errata/RHSA-2018:3005
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12389
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12390
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12392
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12393
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12395
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12396
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12397

SRPMS:
- 6/core/firefox-60.3.0-1.mga6
- 6/core/firefox-l10n-60.3.0-1.mga6
- 6/core/nspr-4.20-1.mga6
- 6/core/nss-3.36.5-1.2.mga6
- 6/core/rootcerts-20181001.00-1.mga6

Mageia 2018-0420: firefox security update

Updated firefox packages fix security vulnerabilities: Mozilla: Memory safety bugs fixed in Firefox ESR 60.3 (CVE-2018-12389)

Summary

Updated firefox packages fix security vulnerabilities:
Mozilla: Memory safety bugs fixed in Firefox ESR 60.3 (CVE-2018-12389).
Mozilla: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3 (CVE-2018-12390).
Mozilla: Crash with nested event loops (CVE-2018-12392).
Mozilla: Integer overflow during Unicode conversion while loading JavaScript (CVE-2018-12393).
Mozilla: WebExtension bypass of domain restrictions through header rewriting (CVE-2018-12395).
Mozilla: WebExtension content scripts can execute in disallowed contexts (CVE-2018-12396).
Mozilla: WebExtension local file permission check bypass (CVE-2018-12397).

References

- https://bugs.mageia.org/show_bug.cgi?id=23751

- https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/

- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/

- https://access.redhat.com/errata/RHSA-2018:3005

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12389

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12390

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12392

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12393

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12395

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12396

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12397

Resolution

MGASA-2018-0420 - Updated firefox packages fix security vulnerabilities

SRPMS

- 6/core/firefox-60.3.0-1.mga6

- 6/core/firefox-l10n-60.3.0-1.mga6

- 6/core/nspr-4.20-1.mga6

- 6/core/nss-3.36.5-1.2.mga6

- 6/core/rootcerts-20181001.00-1.mga6

Severity
Publication date: 27 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0420.html
Type: security
CVE: CVE-2018-12389, CVE-2018-12390, CVE-2018-12392, CVE-2018-12393, CVE-2018-12395, CVE-2018-12396, CVE-2018-12397

Related News