Mageia 2020-0274: firefox security update
Summary
Updated nss and firefox packages fix security vulnerabilities:
NSS has shown timing differences when performing DSA signatures, which
was exploitable and could eventually leak private keys (CVE-2020-12399).
Side channel vulnerabilities during RSA key generation in NSS
(CVE-2020-12402).
When browsing a malicious page, a race condition in our
SharedWorkerService could occur and lead to a potentially exploitable
crash due to a use-after-free (CVE-2020-12405).
Mozilla developer Iain Ireland discovered a missing type check during
unboxed objects removal, resulting in a crash due to type confusion with
NativeTypes. We presume that with enough effort that it could be exploited
to run arbitrary code (CVE-2020-12406).
Mozilla developers Tom Tung and Karl Tomlinson reported memory safety bugs
present in Firefox ESR 68.8. Some of these bugs showed evidence of memory
corruption and we presume that with enough effort some of these could have
been exploited to run arbitrary code (CVE-2020-12410).
...
References
- https://bugs.mageia.org/show_bug.cgi?id=26890
- https://groups.google.com/forum/#!topic/mozilla.dev.tech.nspr/YDlWqMPNR9Y
- - https://www.mozilla.org/en-US/security/advisories/mfsa2020-21/
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-25/
- https://www.debian.org/lts/security/2020/dla-2266
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12417
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12418
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12419
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12420
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12421
Resolution
MGASA-2020-0274 - Updated firefox packages fix security vulnerability
SRPMS
- 7/core/nspr-4.26-1.mga7
- 7/core/rootcerts-20200612.00-1.mga7
- 7/core/nss-3.52.1-1.1.mga7
- 7/core/firefox-68.10.0-1.mga7
- 7/core/firefox-l10n-68.10.0-1.mga7