Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Mageia: 2019-0213 Moderate: Firefox Security Update for Script Injection

mageia
Calendar Grey July 21, 2019
Dist Mageia Esm H88
Enhanced Chrome updates tackle several security flaws related to script vulnerabilities and memory integrity concerns.
Sandbox escape via installation of malicious language pack

Summary

Sandbox escape via installation of malicious language pack. (CVE-2019-9811)
Script injection within domain through inner window reuse. (CVE-2019-11711)
Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects. (CVE-2019-11712)
Use-after-free with HTTP/2 cached stream. (CVE-2019-11713)
NeckoChild can trigger crash when accessed off of main thread. (CVE-2019-11714)
Empty or malformed p256-ECDH public keys may trigger a segmentation fault. (CVE-2019-11729)
HTML parsing error can contribute to content XSS. (CVE-2019-11715)
globalThis not enumerable until accessed. (CVE-2019-11716)
Caret character improperly escaped in origins. (CVE-2019-11717)
Activity Stream writes unsanitized content to innerHTML. (CVE-2019-11718)
Out-of-bounds read when importing curve25519 private key. (CVE-2019-11719)
Character encoding XSS vulnerability. (CVE-2019-11720)
Domain spoofing through unicode latin 'kra' character. (CVE-2019-11721)
Same-origin policy treats all files in a dire...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=25105

- https://www.firefox.com/en-US/firefox/68.0/releasenotes/?redirect_source=mozilla-org

- https://www.firefox.com/en-US/firefox/68.0esr/releasenotes/?redirect_source=mozilla-org

- https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/

- - https://www.cve.org/CVERecord?id=CVE-2019-9811

- https://www.cve.org/CVERecord?id=CVE-2019-11711

- https://www.cve.org/CVERecord?id=CVE-2019-11712

- https://www.cve.org/CVERecord?id=CVE-2019-11713

- https://www.cve.org/CVERecord?id=CVE-2019-11714

- https://www.cve.org/CVERecord?id=CVE-2019-11729

- https://www.cve.org/CVERecord?id=CVE-2019-11715

- https://www.cve.org/CVERecord?id=CVE-2019-11716

- https://www.cve.org/CVERecord?id=CVE-2019-11717

- https://www.cve.org/CVERecord?id=CVE-2019-11718

- https://www.cve.org/CVERecord?id=CVE-2019-11719

- https://www.cve.org/CVERecord?id=CVE-2019-11720

- https://www.cve.org/CVERecord?id=CVE-2019-11721

- https://www.cve.org/CVERecord?id=CVE-2019-11730

- https://www.cve.org/CVERecord?id=CVE-2019-11723

- https://www.cve.org/CVERecord?id=CVE-2019-11724

- https://www.cve.org/CVERecord?id=CVE-2019-11725

- https://www.cve.org/CVERecord?id=CVE-2019-11727

- https://www.cve.org/CVERecord?id=CVE-2019-11728

- https://www.cve.org/CVERecord?id=CVE-2019-11710

- https://www.cve.org/CVERecord?id=CVE-2019-11709

Resolution

SRPMS

- 7/core/firefox-68.0-1.1.mga7

- 7/core/firefox-l10n-68.0-1.mga7

- 7/core/nss-3.45.0-1.mga7

- 7/core/rootcerts-20190604.00-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 21 Jul 2019
URL: https://advisories.mageia.org/MGASA-2019-0213.html
Type: security
CVE: CVE-2019-9811, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713, CVE-2019-11714, CVE-2019-11729, CVE-2019-11715, CVE-2019-11716, CVE-2019-11717, CVE-2019-11718, CVE-2019-11719, CVE-2019-11720, CVE-2019-11721, CVE-2019-11730, CVE-2019-11723, CVE-2019-11724, CVE-2019-11725, CVE-2019-11727, CVE-2019-11728, CVE-2019-11710, CVE-2019-11709

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here