Advisories ยป MGASA-2014-0137

Updated nss, firefox and thunderbird packages fix security vulnerabilities

Publication date: 20 Mar 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-1492 , CVE-2014-1493 , CVE-2014-1497 , CVE-2014-1505 , CVE-2014-1508 , CVE-2014-1509 , CVE-2014-1510 , CVE-2014-1511 , CVE-2014-1512 , CVE-2014-1513 , CVE-2014-1514

Description

In the NSS library before version 3.16, in a wildcard certificate, the
wildcard character was embedded within the U-label of an internationalized
domain name, which is not in accordance with RFC 6125 (CVE-2014-1492).

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox or Thunderbird to crash
or, potentially, execute arbitrary code with the privileges of the user
running it (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514).

Several information disclosure flaws were found in the way Firefox and
Thunderbird processed malformed web content. An attacker could use these
flaws to gain access to sensitive information such as cross-domain content
or protected memory addresses or, potentially, cause Firefox or Thunderbird
to crash (CVE-2014-1497, CVE-2014-1508, CVE-2014-1505).

A memory corruption flaw was found in the way Firefox and Thunderbird
rendered certain PDF files. An attacker able to trick a user into installing
a malicious extension could use this flaw to crash Firefox or, potentially,
execute arbitrary code with the privileges of the user running Firefox or
Thunderbird (CVE-2014-1509).
                

References

SRPMS

4/core

3/core