Updated firefox packages fix security vulnerability
Publication date: 27 Jan 2017Modification date: 27 Jan 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-5373 , CVE-2017-5375 , CVE-2017-5376 , CVE-2017-5378 , CVE-2017-5380 , CVE-2017-5383 , CVE-2017-5386 , CVE-2017-5390 , CVE-2017-5396
Description
Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox (CVE-2017-5373, CVE-2017-5375, CVE-2017-5376, CVE-2017-5378, CVE-2017-5380, CVE-2017-5383, CVE-2017-5386, CVE-2017-5390, CVE-2017-5396).
References
- https://bugs.mageia.org/show_bug.cgi?id=20178
- https://www.mozilla.org/en-US/security/advisories/mfsa2017-02/
- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
- https://rhn.redhat.com/errata/RHSA-2017-0190.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5373
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5375
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5376
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5378
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5380
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5383
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5386
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5390
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5396
SRPMS
5/core
- firefox-45.7.0-1.mga5
- firefox-l10n-45.7.0-1.mga5