[RHSA-2020:5561] firefox security update
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 78.6.0 ESR.
Security Fix(es):
chromium-browser: Uninitialized Use in V8 (CVE-2020-16042)
Mozilla: Heap buffer overflow in WebGL (CVE-2020-26971)
Mozilla: CSS Sanitizer performed incorrect sanitization (CVE-2020-26973)
Mozilla: Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free (CVE-2020-26974)
Mozilla: Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6 (CVE-2020-35113)
Mozilla: Internal network hosts could have been probed by a malicious webpage (CVE-2020-26978)
Mozilla: The proxy.onRequest API did not catch view-source URLs (CVE-2020-35111)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-7.9 | < 78.6.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-7.9 | < 78.6.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-7.9 | < 78.6.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-7.9 | < 78.6.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=i686&distro=redhat-7.9 | < 78.6.0-1.el7_9 |
- ID
- RHSA-2020:5561
- Severity
- important
- URL
- https://access.redhat.com/errata/RHSA-2020:5561
- Published
-
2020-12-16T00:00:00
(3 years ago) - Modified
-
2020-12-16T00:00:00
(3 years ago) - Rights
- Copyright 2020 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2021-1586
- ALPINE:CVE-2020-16042
- ALPINE:CVE-2020-26971
- ALPINE:CVE-2020-26973
- ALPINE:CVE-2020-26974
- ALPINE:CVE-2020-26978
- ALPINE:CVE-2020-35111
- ALPINE:CVE-2020-35113
- ASA-202012-14
- ASA-202012-23
- ASA-202012-25
- DSA-4813-1
- DSA-4815-1
- DSA-4824-1
- ELSA-2020-5618
- ELSA-2020-5624
- FEDORA-2020-5b9c42f1b9
- FEDORA-2020-f43efd09e8
- FREEBSD:01FFD06A-36ED-11EB-B655-3065EC8FD3EC
- GLSA-202012-05
- GLSA-202012-20
- MFSA-2020-54
- MFSA-2020-55
- MFSA-2020-56
- openSUSE-SU-2020:2181-1
- openSUSE-SU-2020:2213-1
- openSUSE-SU-2020:2216-1
- openSUSE-SU-2020:2229-1
- openSUSE-SU-2020:2317-1
- openSUSE-SU-2020:2318-1
- openSUSE-SU-2020:2324-1
- openSUSE-SU-2020:2325-1
- openSUSE-SU-2020:2359-1
- openSUSE-SU-2020:2360-1
- RHSA-2020:5562
- RHSA-2020:5618
- RHSA-2020:5624
- SUSE-SU-2020:3900-1
- SUSE-SU-2020:3901-1
- SUSE-SU-2020:3902-1
- SUSE-SU-2020:3903-1
- SUSE-SU-2020:3935-1
- USN-4671-1
- USN-4701-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1904515 | https://bugzilla.redhat.com/1904515 | |
Bugzilla | 1908022 | https://bugzilla.redhat.com/1908022 | |
Bugzilla | 1908023 | https://bugzilla.redhat.com/1908023 | |
Bugzilla | 1908024 | https://bugzilla.redhat.com/1908024 | |
Bugzilla | 1908025 | https://bugzilla.redhat.com/1908025 | |
Bugzilla | 1908027 | https://bugzilla.redhat.com/1908027 | |
Bugzilla | 1908029 | https://bugzilla.redhat.com/1908029 | |
RHSA | RHSA-2020:5561 | https://access.redhat.com/errata/RHSA-2020:5561 | |
CVE | CVE-2020-16042 | https://access.redhat.com/security/cve/CVE-2020-16042 | |
CVE | CVE-2020-26971 | https://access.redhat.com/security/cve/CVE-2020-26971 | |
CVE | CVE-2020-26973 | https://access.redhat.com/security/cve/CVE-2020-26973 | |
CVE | CVE-2020-26974 | https://access.redhat.com/security/cve/CVE-2020-26974 | |
CVE | CVE-2020-26978 | https://access.redhat.com/security/cve/CVE-2020-26978 | |
CVE | CVE-2020-35111 | https://access.redhat.com/security/cve/CVE-2020-35111 | |
CVE | CVE-2020-35113 | https://access.redhat.com/security/cve/CVE-2020-35113 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-7.9 | redhat | firefox | < 78.6.0-1.el7_9 | redhat-7.9 | x86_64 | |
Affected | pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-7.9 | redhat | firefox | < 78.6.0-1.el7_9 | redhat-7.9 | s390x | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-7.9 | redhat | firefox | < 78.6.0-1.el7_9 | redhat-7.9 | ppc64le | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-7.9 | redhat | firefox | < 78.6.0-1.el7_9 | redhat-7.9 | ppc64 | |
Affected | pkg:rpm/redhat/firefox?arch=i686&distro=redhat-7.9 | redhat | firefox | < 78.6.0-1.el7_9 | redhat-7.9 | i686 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |