Mageia alert MGASA-2018-0202 (firefox)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2018-0202: Updated firefox packages fix security vulnerability | |
Date: | Sun, 15 Apr 2018 15:34:31 +0200 | |
Message-ID: | <20180415133431.643B49FACA@duvel.mageia.org> |
MGASA-2018-0202 - Updated firefox packages fix security vulnerability Publication date: 15 Apr 2018 URL: https://advisories.mageia.org/MGASA-2018-0202.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-5125, CVE-2018-5127, CVE-2018-5129, CVE-2018-5130, CVE-2018-5131, CVE-2018-5144, CVE-2018-5145, CVE-2018-5148 Description: Memory safety bugs fixed in Firefox ESR 52.7 (CVE-2018-5125). Buffer overflow manipulating SVG animatedPathSegList (CVE-2018-5127). Out-of-bounds write with malformed IPC messages (CVE-2018-5129). Mismatched RTP payload type can trigger memory corruption (CVE-2018-5130). Fetch API improperly returns cached copies of no-store/no-cache resources (CVE-2018-5131). Integer overflow during Unicode conversion (CVE-2018-5144). Memory safety bugs fixed in Firefox ESR 52.7 (CVE-2018-5145). A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash (CVE-2018-5148). References: - https://bugs.mageia.org/show_bug.cgi?id=22776 - https://www.mozilla.org/en-US/security/advisories/mfsa201... - https://www.mozilla.org/en-US/security/advisories/mfsa201... - https://www.mozilla.org/security/known-vulnerabilities/fi... - https://access.redhat.com/errata/RHSA-2018:0527 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5125 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5127 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5129 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5130 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5131 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5144 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5145 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5148 SRPMS: - 6/core/firefox-52.7.3-2.mga6 - 6/core/firefox-l10n-52.7.3-1.mga6 - 6/core/nspr-4.19-1.mga6