Advisories ยป MGASA-2018-0420

Updated firefox packages fix security vulnerabilities

Publication date: 27 Oct 2018
Modification date: 27 Oct 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-12389 , CVE-2018-12390 , CVE-2018-12392 , CVE-2018-12393 , CVE-2018-12395 , CVE-2018-12396 , CVE-2018-12397

Description

Updated firefox packages fix security vulnerabilities:

Mozilla: Memory safety bugs fixed in Firefox ESR 60.3 (CVE-2018-12389).

Mozilla: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3
(CVE-2018-12390).

Mozilla: Crash with nested event loops (CVE-2018-12392).

Mozilla: Integer overflow during Unicode conversion while loading
JavaScript (CVE-2018-12393).

Mozilla: WebExtension bypass of domain restrictions through header
rewriting (CVE-2018-12395).

Mozilla: WebExtension content scripts can execute in disallowed contexts
(CVE-2018-12396).

Mozilla: WebExtension local file permission check bypass (CVE-2018-12397).
                

References

SRPMS

6/core