[RHSA-2015:1207] firefox security update

Severity Critical
Affected Packages 6
CVEs 17

Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2015-2724, CVE-2015-2725, CVE-2015-2722, CVE-2015-2727,
CVE-2015-2728, CVE-2015-2729, CVE-2015-2731, CVE-2015-2733, CVE-2015-2734,
CVE-2015-2735, CVE-2015-2736, CVE-2015-2737, CVE-2015-2738, CVE-2015-2739,

It was found that Firefox skipped key-pinning checks when handling an error
that could be overridden by the user (for example an expired certificate
error). This flaw allowed a user to override a pinned certificate, which is
an action the user should not be able to perform. (CVE-2015-2741)

A flaw was discovered in Mozilla's PDF.js PDF file viewer. When combined
with another vulnerability, it could allow execution of arbitrary code with
the privileges of the user running Firefox. (CVE-2015-2743)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bob Clary, Christian Holler, Bobby Holley, Andrew
McCreight, Terrence Cole, Steve Fink, Mats Palmgren, Wes Kocher, Andreas
Pehrson, Jann Horn, Paul Bandha, Holger Fuhrmannek, Herre, Looben Yan,
Ronald Crane, and Jonas Jenwald as the original reporters of these issues.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 38.1 ESR, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.

Source # ID Name URL
Bugzilla 1236947 https://bugzilla.redhat.com/1236947
Bugzilla 1236950 https://bugzilla.redhat.com/1236950
Bugzilla 1236951 https://bugzilla.redhat.com/1236951
Bugzilla 1236952 https://bugzilla.redhat.com/1236952
Bugzilla 1236953 https://bugzilla.redhat.com/1236953
Bugzilla 1236955 https://bugzilla.redhat.com/1236955
Bugzilla 1236956 https://bugzilla.redhat.com/1236956
Bugzilla 1236963 https://bugzilla.redhat.com/1236963
Bugzilla 1236964 https://bugzilla.redhat.com/1236964
RHSA RHSA-2015:1207 https://access.redhat.com/errata/RHSA-2015:1207
CVE CVE-2015-2722 https://access.redhat.com/security/cve/CVE-2015-2722
CVE CVE-2015-2724 https://access.redhat.com/security/cve/CVE-2015-2724
CVE CVE-2015-2725 https://access.redhat.com/security/cve/CVE-2015-2725
CVE CVE-2015-2727 https://access.redhat.com/security/cve/CVE-2015-2727
CVE CVE-2015-2728 https://access.redhat.com/security/cve/CVE-2015-2728
CVE CVE-2015-2729 https://access.redhat.com/security/cve/CVE-2015-2729
CVE CVE-2015-2731 https://access.redhat.com/security/cve/CVE-2015-2731
CVE CVE-2015-2733 https://access.redhat.com/security/cve/CVE-2015-2733
CVE CVE-2015-2734 https://access.redhat.com/security/cve/CVE-2015-2734
CVE CVE-2015-2735 https://access.redhat.com/security/cve/CVE-2015-2735
CVE CVE-2015-2736 https://access.redhat.com/security/cve/CVE-2015-2736
CVE CVE-2015-2737 https://access.redhat.com/security/cve/CVE-2015-2737
CVE CVE-2015-2738 https://access.redhat.com/security/cve/CVE-2015-2738
CVE CVE-2015-2739 https://access.redhat.com/security/cve/CVE-2015-2739
CVE CVE-2015-2740 https://access.redhat.com/security/cve/CVE-2015-2740
CVE CVE-2015-2741 https://access.redhat.com/security/cve/CVE-2015-2741
CVE CVE-2015-2743 https://access.redhat.com/security/cve/CVE-2015-2743
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-6.6 redhat firefox < 38.1.0-1.el6_6 redhat-6.6 x86_64
Affected pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-6.6 redhat firefox < 38.1.0-1.el6_6 redhat-6.6 s390x
Affected pkg:rpm/redhat/firefox?arch=s390&distro=redhat-6.6 redhat firefox < 38.1.0-1.el6_6 redhat-6.6 s390
Affected pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-6.6 redhat firefox < 38.1.0-1.el6_6 redhat-6.6 ppc64
Affected pkg:rpm/redhat/firefox?arch=ppc&distro=redhat-6.6 redhat firefox < 38.1.0-1.el6_6 redhat-6.6 ppc
Affected pkg:rpm/redhat/firefox?arch=i686&distro=redhat-6.6 redhat firefox < 38.1.0-1.el6_6 redhat-6.6 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date