[RHSA-2019:1267] firefox security update

Severity Critical
Affected Packages 4
CVEs 13

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 60.7.0 ESR.

Security Fix(es):

  • Mozilla: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7 (CVE-2019-9800)

  • Mozilla: Cross-origin theft of images with createImageBitmap (CVE-2019-9797)

  • Mozilla: Type confusion with object groups and UnboxedObjects (CVE-2019-9816)

  • Mozilla: Stealing of cross-domain images using canvas (CVE-2019-9817)

  • Mozilla: Compartment mismatch with fetch API (CVE-2019-9819)

  • Mozilla: Use-after-free of ChromeEventHandler by DocShell (CVE-2019-9820)

  • Mozilla: Use-after-free in XMLHttpRequest (CVE-2019-11691)

  • Mozilla: Use-after-free removing listeners in the event listener manager (CVE-2019-11692)

  • Mozilla: Buffer overflow in WebGL bufferdata on Linux (CVE-2019-11693)

  • mozilla: Cross-origin theft of images with ImageBitmapRenderingContext (CVE-2018-18511)

  • chromium-browser: Out of bounds read in Skia (CVE-2019-5798)

  • Mozilla: Theft of user history data through drag and drop of hyperlinks to and from bookmarks (CVE-2019-11698)

  • libpng: use-after-free in png_image_free in png.c (CVE-2019-7317)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

(5 years ago)
(5 years ago)
Copyright 2019 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 1672409 https://bugzilla.redhat.com/1672409
Bugzilla 1676997 https://bugzilla.redhat.com/1676997
Bugzilla 1688200 https://bugzilla.redhat.com/1688200
Bugzilla 1712617 https://bugzilla.redhat.com/1712617
Bugzilla 1712618 https://bugzilla.redhat.com/1712618
Bugzilla 1712619 https://bugzilla.redhat.com/1712619
Bugzilla 1712621 https://bugzilla.redhat.com/1712621
Bugzilla 1712622 https://bugzilla.redhat.com/1712622
Bugzilla 1712623 https://bugzilla.redhat.com/1712623
Bugzilla 1712625 https://bugzilla.redhat.com/1712625
Bugzilla 1712626 https://bugzilla.redhat.com/1712626
Bugzilla 1712628 https://bugzilla.redhat.com/1712628
Bugzilla 1712629 https://bugzilla.redhat.com/1712629
RHSA RHSA-2019:1267 https://access.redhat.com/errata/RHSA-2019:1267
CVE CVE-2018-18511 https://access.redhat.com/security/cve/CVE-2018-18511
CVE CVE-2019-11691 https://access.redhat.com/security/cve/CVE-2019-11691
CVE CVE-2019-11692 https://access.redhat.com/security/cve/CVE-2019-11692
CVE CVE-2019-11693 https://access.redhat.com/security/cve/CVE-2019-11693
CVE CVE-2019-11698 https://access.redhat.com/security/cve/CVE-2019-11698
CVE CVE-2019-5798 https://access.redhat.com/security/cve/CVE-2019-5798
CVE CVE-2019-7317 https://access.redhat.com/security/cve/CVE-2019-7317
CVE CVE-2019-9797 https://access.redhat.com/security/cve/CVE-2019-9797
CVE CVE-2019-9800 https://access.redhat.com/security/cve/CVE-2019-9800
CVE CVE-2019-9816 https://access.redhat.com/security/cve/CVE-2019-9816
CVE CVE-2019-9817 https://access.redhat.com/security/cve/CVE-2019-9817
CVE CVE-2019-9819 https://access.redhat.com/security/cve/CVE-2019-9819
CVE CVE-2019-9820 https://access.redhat.com/security/cve/CVE-2019-9820
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 s390x
Affected pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 ppc64
Affected pkg:rpm/redhat/firefox?arch=i686&distro=redhat-6.10 redhat firefox < 60.7.0-1.el6_10 redhat-6.10 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date