Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia 7: MGASA-2019-0376 Moderate: Firefox Stack Corruption Issue

mageia
Calendar Grey December 8, 2019
Dist Mageia Esm H88
Recent firefox updates tackle severe problems such as heap corruption and memory safety flaws.
Updated firefox packages fix security vulnerabilities: Stack corruption due to incorrect number of arguments in WebRTC code

Summary

Updated firefox packages fix security vulnerabilities:
Stack corruption due to incorrect number of arguments in WebRTC code. (CVE-2019-13722)
Buffer overflow in plain text serializer. (CVE-2019-17005)
Use-after-free in worker destruction. (CVE-2019-17008)
Updater temporary files accessible to unprivileged processes. (CVE-2019-17009)
Use-after-free when performing device orientation checks. (CVE-2019-17010)
Use-after-free when retrieving a document in antitracking. (CVE-2019-17011)
Memory safety bugs fixed in Firefox 71 and Firefox ESR 68.3. (CVE-2019-17012)

References

- https://bugs.mageia.org/show_bug.cgi?id=25820

- https://www.firefox.com/en-US/firefox/68.3.0/releasenotes/?redirect_source=mozilla-org

- https://www.mozilla.org/en-US/security/advisories/mfsa2019-37/

- https://www.cve.org/CVERecord?id=CVE-2019-13722

- https://www.cve.org/CVERecord?id=CVE-2019-17005

- https://www.cve.org/CVERecord?id=CVE-2019-17008

- https://www.cve.org/CVERecord?id=CVE-2019-17009

- https://www.cve.org/CVERecord?id=CVE-2019-17010

- https://www.cve.org/CVERecord?id=CVE-2019-17011

- https://www.cve.org/CVERecord?id=CVE-2019-17012

Resolution

SRPMS

- 7/core/firefox-68.3.0-1.mga7

- 7/core/firefox-l10n-68.3.0-1.mga7

- 7/core/nspr-4.24-1.mga7

Severity
medium
Lowest
Low
Medium
High
Critical

Publication date: 08 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0376.html
Type: security
CVE: CVE-2019-13722, CVE-2019-17005, CVE-2019-17008, CVE-2019-17009, CVE-2019-17010, CVE-2019-17011, CVE-2019-17012

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here