Mageia 2018-0483: firefox security update
Summary
A buffer overflow and out-of-bounds read can occur in TextureStorage11
within the ANGLE graphics library, used for WebGL content. This results
in a potentially exploitable crash (CVE-2018-17466).
A use-after-free vulnerability can occur after deleting a selection
element due to a weak reference to the select element in the options
collection. This results in a potentially exploitable crash
(CVE-2018-18492).
A buffer overflow can occur in the Skia library during buffer offset
calculations with hardware accelerated canvas 2D actions due to the use
of 32-bit calculations instead of 64-bit. This results in a potentially
exploitable crash (CVE-2018-18493).
A same-origin policy violation allowing the theft of cross-origin URL
entries when using the Javascript location property to cause a
redirection to another site using performance.getEntries(). This is a
same-origin policy violation and could allow for data theft
(CVE-2018-19494).
A potential vulnerability leading to an integer overflow...
References
- https://bugs.mageia.org/show_bug.cgi?id=23991
- https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/
- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12405
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17466
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18492
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18493
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18494
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18498
Resolution
MGASA-2018-0483 - Updated firefox packages fix security vulnerabilities
SRPMS
- 6/core/firefox-60.4.0-1.mga6
- 6/core/firefox-l10n-60.4.0-1.mga6