Mageia 2019-0116: firefox security update
Summary
Proxy Auto-Configuration file can define localhost access to be proxied
(CVE-2018-18506).
Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6
(CVE-2019-9788).
Use-after-free when removing in-use DOM elements (CVE-2019-9790).
Type inference is incorrect for constructors entered through on-stack
replacement with IonMonkey (CVE-2019-9791).
IonMonkey leaks JS_OPTIMIZED_OUT magic value to script (CVE-2019-9792).
Improper bounds checks when Spectre mitigations are disabled
(CVE-2019-9793).
Type-confusion in IonMonkey JIT compiler (CVE-2019-9795).
Use-after-free with SMIL animation controller (CVE-2019-9796).
References
- https://bugs.mageia.org/show_bug.cgi?id=24534
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/
- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
- https://access.redhat.com/errata/RHSA-2019:0622
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18506
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9788
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9790
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9791
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9792
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9793
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9795
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9796
Resolution
MGASA-2019-0116 - Updated firefox packages fix security vulnerability
SRPMS
- 6/core/firefox-60.6.0-2.mga6
- 6/core/firefox-l10n-60.6.0-1.mga6
- 6/core/nspr-4.21-1.mga6
- 6/core/rootcerts-20190306.00-1.mga6
- 6/core/nss-3.36.7-1.1.mga6