Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Mageia 6 MGASA-2019-0116 Moderate: Firefox Memory Bugs Fixed

mageia
Calendar Grey March 21, 2019
Dist Mageia Esm H88
The Opera browser received its latest upgrade on Fedora on April 15, 2020, tackling important vulnerabilities and enhancing user experience.
Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506)

Summary

Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506).
Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788).
Use-after-free when removing in-use DOM elements (CVE-2019-9790).
Type inference is incorrect for constructors entered through on-stack replacement with IonMonkey (CVE-2019-9791).
IonMonkey leaks JS_OPTIMIZED_OUT magic value to script (CVE-2019-9792).
Improper bounds checks when Spectre mitigations are disabled (CVE-2019-9793).
Type-confusion in IonMonkey JIT compiler (CVE-2019-9795).
Use-after-free with SMIL animation controller (CVE-2019-9796).

References

- https://bugs.mageia.org/show_bug.cgi?id=24534

- https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/

- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/

- https://access.redhat.com/errata/RHSA-2019:0622

- https://www.cve.org/CVERecord?id=CVE-2018-18506

- https://www.cve.org/CVERecord?id=CVE-2019-9788

- https://www.cve.org/CVERecord?id=CVE-2019-9790

- https://www.cve.org/CVERecord?id=CVE-2019-9791

- https://www.cve.org/CVERecord?id=CVE-2019-9792

- https://www.cve.org/CVERecord?id=CVE-2019-9793

- https://www.cve.org/CVERecord?id=CVE-2019-9795

- https://www.cve.org/CVERecord?id=CVE-2019-9796

Resolution

SRPMS

- 6/core/firefox-60.6.0-2.mga6

- 6/core/firefox-l10n-60.6.0-1.mga6

- 6/core/nspr-4.21-1.mga6

- 6/core/rootcerts-20190306.00-1.mga6

- 6/core/nss-3.36.7-1.1.mga6

Publication date: 21 Mar 2019
URL: https://advisories.mageia.org/MGASA-2019-0116.html
Type: security
CVE: CVE-2018-18506, CVE-2019-9788, CVE-2019-9790, CVE-2019-9791, CVE-2019-9792, CVE-2019-9793, CVE-2019-9795, CVE-2019-9796

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here