Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 6: 2019-0131 Moderate: Firefox Buffer Overflow and Type Confusion

mageia
Calendar Grey April 5, 2019
Dist Mageia Esm H88
The recent Firefox updates have been rolled out to tackle vulnerabilities such as buffer overflows and type mismatches in Mageia.
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow (CVE-2019-9810)

Summary

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow (CVE-2019-9810).
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write (CVE-2019-9813).

References

- https://bugs.mageia.org/show_bug.cgi?id=24549

- https://www.mozilla.org/en-US/security/advisories/mfsa2019-10/

- https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/

- https://www.cve.org/CVERecord?id=CVE-2019-9810

- https://www.cve.org/CVERecord?id=CVE-2019-9813

Resolution

SRPMS

- 6/core/firefox-60.6.1-2.mga6

- 6/core/firefox-l10n-60.6.1-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 05 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0131.html
Type: security
CVE: CVE-2019-9810, CVE-2019-9813

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here