Synopsis: Critical: firefox security update
Advisory ID:       SLSA-2019:1265-1
Issue Date:        2019-05-24
CVE Numbers:       CVE-2019-7317
                   CVE-2018-18511
                   CVE-2019-5798
                   CVE-2019-11691
                   CVE-2019-11692
                   CVE-2019-11693
                   CVE-2019-11698
                   CVE-2019-9797
                   CVE-2019-9800
                   CVE-2019-9816
                   CVE-2019-9817
                   CVE-2019-9819
                   CVE-2019-9820
--

This update upgrades Firefox to version 60.7.0 ESR.

Security Fix(es):

* Mozilla: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7
(CVE-2019-9800)

* Mozilla: Cross-origin theft of images with createImageBitmap
(CVE-2019-9797)

* Mozilla: Type confusion with object groups and UnboxedObjects
(CVE-2019-9816)

* Mozilla: Stealing of cross-domain images using canvas (CVE-2019-9817)

* Mozilla: Compartment mismatch with fetch API (CVE-2019-9819)

* Mozilla: Use-after-free of ChromeEventHandler by DocShell
(CVE-2019-9820)

* Mozilla: Use-after-free in XMLHttpRequest (CVE-2019-11691)

* Mozilla: Use-after-free removing listeners in the event listener manager
(CVE-2019-11692)

* Mozilla: Buffer overflow in WebGL bufferdata on Linux (CVE-2019-11693)

* mozilla: Cross-origin theft of images with ImageBitmapRenderingContext
(CVE-2018-18511)

* chromium-browser: Out of bounds read in Skia (CVE-2019-5798)

* Mozilla: Theft of user history data through drag and drop of hyperlinks
to and from bookmarks (CVE-2019-11698)

* libpng: use-after-free in png_image_free in png.c (CVE-2019-7317)
--

SL7
  x86_64
    firefox-60.7.0-1.el7_6.x86_64.rpm
    firefox-debuginfo-60.7.0-1.el7_6.x86_64.rpm
    firefox-60.7.0-1.el7_6.i686.rpm
    firefox-debuginfo-60.7.0-1.el7_6.i686.rpm

- Scientific Linux Development Team

SciLinux: SLSA-2019-1265-1 Critical: firefox on SL7.x x86_64

This update upgrades Firefox to version 60.7.0 ESR

Summary

Critical: firefox security update



Security Fixes

* Mozilla: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7 (CVE-2019-9800)
* Mozilla: Cross-origin theft of images with createImageBitmap (CVE-2019-9797)
* Mozilla: Type confusion with object groups and UnboxedObjects (CVE-2019-9816)
* Mozilla: Stealing of cross-domain images using canvas (CVE-2019-9817)
* Mozilla: Compartment mismatch with fetch API (CVE-2019-9819)
* Mozilla: Use-after-free of ChromeEventHandler by DocShell (CVE-2019-9820)
* Mozilla: Use-after-free in XMLHttpRequest (CVE-2019-11691)
* Mozilla: Use-after-free removing listeners in the event listener manager (CVE-2019-11692)
* Mozilla: Buffer overflow in WebGL bufferdata on Linux (CVE-2019-11693)
* mozilla: Cross-origin theft of images with ImageBitmapRenderingContext (CVE-2018-18511)
* chromium-browser: Out of bounds read in Skia (CVE-2019-5798)
* Mozilla: Theft of user history data through drag and drop of hyperlinks to and from bookmarks (CVE-2019-11698)
* libpng: use-after-free in png_image_free in png.c (CVE-2019-7317)
SL7 x86_64 firefox-60.7.0-1.el7_6.x86_64.rpm firefox-debuginfo-60.7.0-1.el7_6.x86_64.rpm firefox-60.7.0-1.el7_6.i686.rpm firefox-debuginfo-60.7.0-1.el7_6.i686.rpm
- Scientific Linux Development Team

Severity
Advisory ID: SLSA-2019:1265-1
Issued Date: : 2019-05-24
CVE Numbers: CVE-2019-7317
CVE-2018-18511
CVE-2019-5798

Related News