[RHSA-2019:1267] firefox security update
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 60.7.0 ESR.
Security Fix(es):
Mozilla: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7 (CVE-2019-9800)
Mozilla: Cross-origin theft of images with createImageBitmap (CVE-2019-9797)
Mozilla: Type confusion with object groups and UnboxedObjects (CVE-2019-9816)
Mozilla: Stealing of cross-domain images using canvas (CVE-2019-9817)
Mozilla: Compartment mismatch with fetch API (CVE-2019-9819)
Mozilla: Use-after-free of ChromeEventHandler by DocShell (CVE-2019-9820)
Mozilla: Use-after-free in XMLHttpRequest (CVE-2019-11691)
Mozilla: Use-after-free removing listeners in the event listener manager (CVE-2019-11692)
Mozilla: Buffer overflow in WebGL bufferdata on Linux (CVE-2019-11693)
mozilla: Cross-origin theft of images with ImageBitmapRenderingContext (CVE-2018-18511)
chromium-browser: Out of bounds read in Skia (CVE-2019-5798)
Mozilla: Theft of user history data through drag and drop of hyperlinks to and from bookmarks (CVE-2019-11698)
libpng: use-after-free in png_image_free in png.c (CVE-2019-7317)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-6.10 | < 60.7.0-1.el6_10 |
pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-6.10 | < 60.7.0-1.el6_10 |
pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-6.10 | < 60.7.0-1.el6_10 |
pkg:rpm/redhat/firefox?arch=i686&distro=redhat-6.10 | < 60.7.0-1.el6_10 |
- ID
- RHSA-2019:1267
- Severity
- critical
- URL
- https://access.redhat.com/errata/RHSA-2019:1267
- Published
-
2019-05-23T00:00:00
(5 years ago) - Modified
-
2019-05-23T00:00:00
(5 years ago) - Rights
- Copyright 2019 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2019-1229
- ALAS2-2019-1246
- ALPINE:CVE-2018-18511
- ALPINE:CVE-2019-11691
- ALPINE:CVE-2019-11692
- ALPINE:CVE-2019-11693
- ALPINE:CVE-2019-11698
- ALPINE:CVE-2019-5798
- ALPINE:CVE-2019-7317
- ALPINE:CVE-2019-9797
- ALPINE:CVE-2019-9800
- ALPINE:CVE-2019-9816
- ALPINE:CVE-2019-9817
- ALPINE:CVE-2019-9819
- ALPINE:CVE-2019-9820
- ASA-201902-16
- ASA-201903-11
- ASA-201903-8
- ASA-201904-10
- ASA-201905-8
- ASA-201905-9
- DSA-4421-1
- DSA-4435-1
- DSA-4448-1
- DSA-4451-1
- ELSA-2019-1265
- ELSA-2019-1267
- ELSA-2019-1269
- ELSA-2019-1308
- ELSA-2019-1309
- ELSA-2019-1310
- FEDORA-2019-05a780936d
- FEDORA-2019-335c3ad86a
- FEDORA-2019-561eae4626
- FREEBSD:05DA6B56-3E66-4306-9EA3-89FAFE939726
- FREEBSD:18211552-F650-4D86-BA4F-E6D5CBFCDBEB
- FREEBSD:44B6DFBF-4EF7-4D52-AD52-2B1B05D81272
- GLSA-201903-23
- GLSA-201908-02
- MFSA-2019-04
- MFSA-2019-07
- MFSA-2019-13
- MFSA-2019-14
- MFSA-2019-15
- openSUSE-SU-2019:1062-1
- openSUSE-SU-2019:1530-1
- openSUSE-SU-2019:1534-1
- openSUSE-SU-2019:1664-1
- openSUSE-SU-2019:1666-1
- openSUSE-SU-2019:1912-1
- openSUSE-SU-2019:1916-1
- RHSA-2019:0708
- RHSA-2019:1265
- RHSA-2019:1269
- RHSA-2019:1308
- RHSA-2019:1309
- RHSA-2019:1310
- RHSA-2019:2494
- RHSA-2019:2495
- RHSA-2019:2585
- RHSA-2019:2590
- RHSA-2019:2592
- SSA:2019-107-01
- SSA:2019-141-01
- SUSE-SU-2019:1388-1
- SUSE-SU-2019:1398-1
- SUSE-SU-2019:1398-2
- SUSE-SU-2019:1405-1
- SUSE-SU-2019:1458-1
- SUSE-SU-2019:2002-1
- SUSE-SU-2019:2021-1
- SUSE-SU-2019:2028-1
- SUSE-SU-2019:2036-1
- SUSE-SU-2019:2036-2
- SUSE-SU-2019:2291-1
- SUSE-SU-2019:2336-1
- SUSE-SU-2019:2371-1
- SUSE-SU-2019:3060-2
- USN-3896-1
- USN-3918-1
- USN-3918-2
- USN-3962-1
- USN-3991-1
- USN-3997-1
- USN-4080-1
- USN-4083-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-6.10 | redhat | firefox | < 60.7.0-1.el6_10 | redhat-6.10 | x86_64 | |
Affected | pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-6.10 | redhat | firefox | < 60.7.0-1.el6_10 | redhat-6.10 | s390x | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-6.10 | redhat | firefox | < 60.7.0-1.el6_10 | redhat-6.10 | ppc64 | |
Affected | pkg:rpm/redhat/firefox?arch=i686&distro=redhat-6.10 | redhat | firefox | < 60.7.0-1.el6_10 | redhat-6.10 | i686 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |