Updated firefox packages fix security vulnerability
Publication date: 09 Jan 2020Modification date: 09 Jan 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-17016 , CVE-2019-17017 , CVE-2019-17022 , CVE-2019-17024 , CVE-2019-17026
Description
When pasting a <style> tag from the clipboard into a rich text editor, the CSS
sanitizer incorrectly rewrites a @namespace rule. This could allow for
injection into certain types of websites resulting in data exfiltration
(CVE-2019-17016).
Due to a missing case handling object types, a type confusion vulnerability
could occur, resulting in a crash. We presume that with enough effort that it
could be exploited to run arbitrary code (CVE-2019-17017).
When pasting a <style> tag from the clipboard into a rich text editor, the CSS
sanitizer does not escape < and > characters. Because the resulting string is
pasted directly into the text node of the element this does not result in a
direct injection into the webpage; however, if a webpage subsequently copies
the node's innerHTML, assigning it to another innerHTML, this would result in
an XSS vulnerability. Two WYSIWYG editors were identified with this behavior,
more may exist (CVE-2019-17022).
Mozilla developers reported memory safety bugs present in Firefox ESR 68.3.
Some of these bugs showed evidence of memory corruption and we presume that
with enough effort some of these could have been exploited to run arbitrary
code (CVE-2019-17024).
Incorrect alias information in IonMonkey JIT compiler for setting array
elements could lead to a type confusion. We are aware of targeted attacks in
the wild abusing this flaw (CVE-2019-17026).
References
- https://bugs.mageia.org/show_bug.cgi?id=26027
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-02/
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.48_release_notes
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.49_release_notes
- https://www.mozilla.org/en-US/firefox/68.4.0/releasenotes/
- https://www.mozilla.org/en-US/firefox/68.4.1/releasenotes/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17016
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17017
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17022
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17024
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17026
SRPMS
7/core
- firefox-68.4.1-1.mga7
- firefox-l10n-68.4.1-1.mga7
- nss-3.49.0-1.mga7