[RHSA-2019:1267] firefox security update

Severity Critical
Affected Packages 4
CVEs 13

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 60.7.0 ESR.

Security Fix(es):

  • Mozilla: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7 (CVE-2019-9800)

  • Mozilla: Cross-origin theft of images with createImageBitmap (CVE-2019-9797)

  • Mozilla: Type confusion with object groups and UnboxedObjects (CVE-2019-9816)

  • Mozilla: Stealing of cross-domain images using canvas (CVE-2019-9817)

  • Mozilla: Compartment mismatch with fetch API (CVE-2019-9819)

  • Mozilla: Use-after-free of ChromeEventHandler by DocShell (CVE-2019-9820)

  • Mozilla: Use-after-free in XMLHttpRequest (CVE-2019-11691)

  • Mozilla: Use-after-free removing listeners in the event listener manager (CVE-2019-11692)

  • Mozilla: Buffer overflow in WebGL bufferdata on Linux (CVE-2019-11693)

  • mozilla: Cross-origin theft of images with ImageBitmapRenderingContext (CVE-2018-18511)

  • chromium-browser: Out of bounds read in Skia (CVE-2019-5798)

  • Mozilla: Theft of user history data through drag and drop of hyperlinks to and from bookmarks (CVE-2019-11698)

  • libpng: use-after-free in png_image_free in png.c (CVE-2019-7317)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

ID
RHSA-2019:1267
Severity
critical
URL
https://access.redhat.com/errata/RHSA-2019:1267
Published
2019-05-23T00:00:00
(5 years ago)
Modified
2019-05-23T00:00:00
(5 years ago)
Rights
Copyright 2019 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 1672409 https://bugzilla.redhat.com/1672409
Bugzilla 1676997 https://bugzilla.redhat.com/1676997
Bugzilla 1688200 https://bugzilla.redhat.com/1688200
Bugzilla 1712617 https://bugzilla.redhat.com/1712617
Bugzilla 1712618 https://bugzilla.redhat.com/1712618
Bugzilla 1712619 https://bugzilla.redhat.com/1712619
Bugzilla 1712621 https://bugzilla.redhat.com/1712621
Bugzilla 1712622 https://bugzilla.redhat.com/1712622
Bugzilla 1712623 https://bugzilla.redhat.com/1712623
Bugzilla 1712625 https://bugzilla.redhat.com/1712625
Bugzilla 1712626 https://bugzilla.redhat.com/1712626
Bugzilla 1712628 https://bugzilla.redhat.com/1712628
Bugzilla 1712629 https://bugzilla.redhat.com/1712629
RHSA RHSA-2019:1267 https://access.redhat.com/errata/RHSA-2019:1267
CVE CVE-2018-18511 https://access.redhat.com/security/cve/CVE-2018-18511
CVE CVE-2019-11691 https://access.redhat.com/security/cve/CVE-2019-11691
CVE CVE-2019-11692 https://access.redhat.com/security/cve/CVE-2019-11692
CVE CVE-2019-11693 https://access.redhat.com/security/cve/CVE-2019-11693
CVE CVE-2019-11698 https://access.redhat.com/security/cve/CVE-2019-11698
CVE CVE-2019-5798 https://access.redhat.com/security/cve/CVE-2019-5798
CVE CVE-2019-7317 https://access.redhat.com/security/cve/CVE-2019-7317
CVE CVE-2019-9797 https://access.redhat.com/security/cve/CVE-2019-9797
CVE CVE-2019-9800 https://access.redhat.com/security/cve/CVE-2019-9800
CVE CVE-2019-9816 https://access.redhat.com/security/cve/CVE-2019-9816
CVE CVE-2019-9817 https://access.redhat.com/security/cve/CVE-2019-9817
CVE CVE-2019-9819 https://access.redhat.com/security/cve/CVE-2019-9819
CVE CVE-2019-9820 https://access.redhat.com/security/cve/CVE-2019-9820
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 s390x
Affected pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 ppc64
Affected pkg:rpm/redhat/firefox?arch=i686&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...