Updated firefox packages fix security vulnerability
Publication date: 29 Jan 2016Modification date: 29 Jan 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-1930 , CVE-2016-1935
Description
Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox (CVE-2016-1930, CVE-2016-1935).
References
- https://bugs.mageia.org/show_bug.cgi?id=17625
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-01/
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-03/
- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
- https://rhn.redhat.com/errata/RHSA-2016-0071.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1930
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1935
SRPMS
5/core
- firefox-38.6.0-1.mga5
- firefox-l10n-38.6.0-1.mga5