[GLSA-201811-04] Mozilla Firefox: Multiple vulnerabilities

Severity Normal
Affected Packages 2
Unaffected Packages 2
CVEs 7

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

Background
Mozilla Firefox is a popular open-source web browser from the Mozilla
Project.

Description
Multiple vulnerabilities have been discovered in Mozilla Firefox. Please
review the CVE identifiers referenced below for details.

Impact
A remote attacker could entice a user to view a specially crafted web
page, possibly resulting in the execution of arbitrary code with the
privileges of the process, cause a Denial of Service condition, bypass
access restriction, access otherwise protected information.

Workaround
There is no known workaround at this time.

Resolution
All Mozilla Firefox users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-60.3.0"

All Mozilla Firefox binary users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-bin-60.3.0"

Source # ID Name URL
CVE CVE-2018-12389 CVE-2018-12389 https://nvd.nist.gov/vuln/detail/CVE-2018-12389
CVE CVE-2018-12390 CVE-2018-12390 https://nvd.nist.gov/vuln/detail/CVE-2018-12390
CVE CVE-2018-12392 CVE-2018-12392 https://nvd.nist.gov/vuln/detail/CVE-2018-12392
CVE CVE-2018-12393 CVE-2018-12393 https://nvd.nist.gov/vuln/detail/CVE-2018-12393
CVE CVE-2018-12395 CVE-2018-12395 https://nvd.nist.gov/vuln/detail/CVE-2018-12395
CVE CVE-2018-12396 CVE-2018-12396 https://nvd.nist.gov/vuln/detail/CVE-2018-12396
CVE CVE-2018-12397 CVE-2018-12397 https://nvd.nist.gov/vuln/detail/CVE-2018-12397
Vendor Mozilla Foundation Security Advisory 2018-27 https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/
Bugzilla 669430 Bugzilla #669430 https://bugs.gentoo.org/show_bug.cgi?id=669430
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/www-client/firefox?distro=gentoo www-client firefox < 60.3.0 gentoo
Unaffected pkg:ebuild/www-client/firefox?distro=gentoo www-client firefox >= 60.3.0 gentoo
Affected pkg:ebuild/www-client/firefox-bin?distro=gentoo www-client firefox-bin < 60.3.0 gentoo
Unaffected pkg:ebuild/www-client/firefox-bin?distro=gentoo www-client firefox-bin >= 60.3.0 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...