Updated firefox packages fix security vulnerabilities
Publication date: 17 May 2018Modification date: 17 May 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-5150 , CVE-2018-5153 , CVE-2018-5154 , CVE-2018-5155 , CVE-2018-5157 , CVE-2018-5158 , CVE-2018-5159 , CVE-2018-5168 , CVE-2018-5178
Description
Updated firefox packages fix security vulnerabilities:
Mozilla: Memory safety bugs fixed in Firefox ESR 52.8 (CVE-2018-5150).
Mozilla: Backport critical security fixes in Skia (CVE-2018-5183).
Mozilla: Use-after-free with SVG animations and clip paths (CVE-2018-5154).
Mozilla: Use-after-free with SVG animations and text paths (CVE-2018-5155).
Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files
(CVE-2018-5157).
Mozilla: Malicious PDF can inject JavaScript into PDF Viewer
(CVE-2018-5158).
Mozilla: Integer overflow and out-of-bounds write in Skia (CVE-2018-5159).
Mozilla: Lightweight themes can be installed without user interaction
(CVE-2018-5168).
Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through
legacy extension (CVE-2018-5178).
Rootcerts has been updated to 20180411.
References
- https://bugs.mageia.org/show_bug.cgi?id=23031
- https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/
- https://www.mozilla.org/security/known-vulnerabilities/firefox-esr/
- https://access.redhat.com/errata/RHSA-2018:1415
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5150
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5153
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5154
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5155
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5157
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5158
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5159
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5168
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5178
SRPMS
6/core
- firefox-52.8.0-1.mga6
- firefox-l10n-52.8.0-1.mga6
- nss-3.28.6-1.4.mga6
- rootcerts-20180411.00-1.mga6