Updated firefox packages fix security vulnerabilities
Publication date: 09 Jun 2016Modification date: 09 Jun 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-2818 , CVE-2016-2819 , CVE-2016-2821 , CVE-2016-2822 , CVE-2016-2828 , CVE-2016-2831
Description
Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox (CVE-2016-2818, CVE-2016-2819, CVE-2016-2821, CVE-2016-2822, CVE-2016-2828, CVE-2016-2831). This update provides the next stable branch of Firefox, version 45.2.0.
References
- https://bugs.mageia.org/show_bug.cgi?id=18654
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-49/
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-50/
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-51/
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-52/
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-56/
- https://www.mozilla.org/en-US/security/advisories/mfsa2016-58/
- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
- https://www.mozilla.org/en-US/firefox/45.2.0/releasenotes/
- https://rhn.redhat.com/errata/RHSA-2016-1217.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2818
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2819
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2821
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2822
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2828
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2831
SRPMS
5/core
- nss-3.24.0-1.mga5
- firefox-45.2.0-1.mga5
- firefox-l10n-45.2.0-1.mga5