[RHSA-2020:2036] firefox security update
Severity
Critical
Affected Packages
4
CVEs
4
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 68.8.0 ESR.
Security Fix(es):
Mozilla: Use-after-free during worker shutdown (CVE-2020-12387)
Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395)
Mozilla: Buffer overflow in SCTP chunk input validation (CVE-2020-6831)
Mozilla: Arbitrary local file access with 'Copy as cURL' (CVE-2020-12392)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-6.10 | < 68.8.0-1.el6_10 |
pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-6.10 | < 68.8.0-1.el6_10 |
pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-6.10 | < 68.8.0-1.el6_10 |
pkg:rpm/redhat/firefox?arch=i686&distro=redhat-6.10 | < 68.8.0-1.el6_10 |
- ID
- RHSA-2020:2036
- Severity
- critical
- URL
- https://access.redhat.com/errata/RHSA-2020:2036
- Published
-
2020-05-06T00:00:00
(4 years ago) - Modified
-
2020-05-06T00:00:00
(4 years ago) - Rights
- Copyright 2020 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2020-1429
- ALPINE:CVE-2020-12387
- ALPINE:CVE-2020-12392
- ALPINE:CVE-2020-12395
- ALPINE:CVE-2020-6831
- ASA-202005-2
- ASA-202005-3
- ASA-202005-7
- DSA-4678-1
- DSA-4683-1
- DSA-4714-1
- ELSA-2020-2031
- ELSA-2020-2036
- ELSA-2020-2037
- ELSA-2020-2046
- ELSA-2020-2049
- ELSA-2020-2050
- GLSA-202005-03
- GLSA-202005-04
- MFSA-2020-16
- MFSA-2020-17
- MFSA-2020-18
- openSUSE-SU-2020:0620-1
- openSUSE-SU-2020:0621-1
- openSUSE-SU-2020:0643-1
- openSUSE-SU-2020:0648-1
- openSUSE-SU-2020:0709-1
- openSUSE-SU-2020:0917-1
- RHSA-2020:2031
- RHSA-2020:2037
- RHSA-2020:2046
- RHSA-2020:2049
- RHSA-2020:2050
- RHSA-2020:2064
- SSA:2020-126-01
- SUSE-SU-2020:1209-1
- SUSE-SU-2020:1218-1
- SUSE-SU-2020:1225-1
- USN-4353-1
- USN-4373-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1831761 | https://bugzilla.redhat.com/1831761 | |
Bugzilla | 1831763 | https://bugzilla.redhat.com/1831763 | |
Bugzilla | 1831764 | https://bugzilla.redhat.com/1831764 | |
Bugzilla | 1831765 | https://bugzilla.redhat.com/1831765 | |
RHSA | RHSA-2020:2036 | https://access.redhat.com/errata/RHSA-2020:2036 | |
CVE | CVE-2020-12387 | https://access.redhat.com/security/cve/CVE-2020-12387 | |
CVE | CVE-2020-12392 | https://access.redhat.com/security/cve/CVE-2020-12392 | |
CVE | CVE-2020-12395 | https://access.redhat.com/security/cve/CVE-2020-12395 | |
CVE | CVE-2020-6831 | https://access.redhat.com/security/cve/CVE-2020-6831 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-6.10 | redhat | firefox | < 68.8.0-1.el6_10 | redhat-6.10 | x86_64 | |
Affected | pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-6.10 | redhat | firefox | < 68.8.0-1.el6_10 | redhat-6.10 | s390x | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-6.10 | redhat | firefox | < 68.8.0-1.el6_10 | redhat-6.10 | ppc64 | |
Affected | pkg:rpm/redhat/firefox?arch=i686&distro=redhat-6.10 | redhat | firefox | < 68.8.0-1.el6_10 | redhat-6.10 | i686 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |