Firefox 60 is now the only supported version of the ESR series and it brings a completely new browser engine, designed to take full advantage of the processing power in modern devices. Firefox also now exclusively supports extensions built using the WebExtension API. . MGASA-2018-0393 - Updated firefox packages fix security vulnerability Publication date: 01 Oct 2018 URL: https://advisories.mageia.org/MGASA-2018-0393.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-12384 Firefox 60 is now the only supported version of the ESR series and it brings a completely new browser engine, designed to take full advantage of the processing power in modern devices. Firefox also now exclusively supports extensions built using the WebExtension API. This update brings Firefox 60.2.1 along with the needed updated libraries : - NSS 3.36.5 (fixes CVE CVE-2018-12384) - Sqlite 3.22.0 - Hunspell 1.6.2 References: - https://bugs.mageia.org/show_bug.cgi?id=23511 - https://www.cve.org/CVERecord?id=CVE-2018-12384 SRPMS: - 6/core/firefox-60.2.1-1.mga6 - 6/core/firefox-l10n-60.2.1-1.mga6 - 6/core/nss-3.36.5-1.1.mga6 - 6/core/sqlite3-3.22.0-2.1.mga6 - 6/core/hunspell1.6-1.6.2-1.mga6 . Recent updates for the Firefox browser on Mageia focus on crucial security vulnerabilities while introducing a range of new functionalities and improvements.. Firefox Update, Mageia Security, Browser Protection, Web Extensions, Software Patch. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-2920-1 March 10, 2016 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine for Qt (QML plugin) Details: It was discovered that the ContainerNode::parserRemoveChild function in Blink mishandled widget updates in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2016-1630) It was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun function in Chromium mishandled nested message loops. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2016-1631) Multiple use-after-frees were discovered in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2016-1633, CVE-2016-1634, CVE-2016-1644) It was discovered that the PendingScript::notifyFinished function in Blink relied on memory-cache information about integrity-check occurrences instead of integrity-check successes. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass Subresource Integrity (SRI) protections. (CVE-2016-1636) It was discovered that the SkATan2_255 function in Skia mishandled arctangent calculations. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this toobtain sensitive information. (CVE-2016-1637) A use-after-free was discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2016-1641) Multiple security issues were discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2016-1642) A type-confusion bug was discovered in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2016-1643) Multiple security issues were discovered in V8. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2016-2843) An invalid cast was discovered in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2016-2844) It was discovered that the Content Security Policy (CSP) implementation in Blink did not ignore a URL's path component in the case of a ServiceWorker fetch. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information. (CVE-2016-2845) Update instructions: The problem can be corrected by updating your system tothe following package versions: Ubuntu 15.10: liboxideqtcore0 1.13.6-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.13.6-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2920-1 CVE-2016-1630, CVE-2016-1631, CVE-2016-1633, CVE-2016-1634, CVE-2016-1636, CVE-2016-1637, CVE-2016-1641, CVE-2016-1642, CVE-2016-1643, CVE-2016-1644, CVE-2016-2843, CVE-2016-2844, CVE-2016-2845 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.15.10.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.13.6-0ubuntu0.14.04.1 . Address several Oxide vulnerabilities in Ubuntu to mitigate potential threats and uphold system protection and integrity.. Oxide Security, Ubuntu Fixes, Browser Engine Security, Code Execution, DoS Attack. . Severity: Important. LinuxSecurity.com Team
A flaw was discovered in the browser engine. A variable could be made to overflow causing the browser to crash. If a user were tricked into opening a malicious web page, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2008-2785) . =========================================================== Ubuntu Security Notice USN-626-2 August 04, 2008 devhelp, epiphany-browser, midbrowser, yelp update https://bugs.launchpad.net/ubuntu/+source/xulrunner-1.9/+bug/253462 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: devhelp 0.19-1ubuntu1.8.04.3 epiphany-gecko 2.22.2-0ubuntu0.8.04.5 midbrowser 0.3.0rc1a-1~8.04.2 yelp 2.22.1-0ubuntu2.8.04.2 After a standard system upgrade you need to restart Devhelp, Epiphany, Midbrowser and Yelp to effect the necessary changes. Details follow: USN-626-1 fixed vulnerabilities in xulrunner-1.9. The changes required that Devhelp, Epiphany, Midbrowser and Yelp also be updated to use the new xulrunner-1.9. Original advisory details: A flaw was discovered in the browser engine. A variable could be made to overflow causing the browser to crash. If a user were tricked into opening a malicious web page, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2008-2785) Billy Rios discovered that Firefox and xulrunner, as used by browsers such as Epiphany, did not properly perform URI splitting with pipe symbols when passed a command-line URI. If Firefox or xulrunner were passed amalicious URL, an attacker may be able to execute local content with chrome privileges. (CVE-2008-2933) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 31298 9c7bb3906f79ab2c1f190cbefb703f82 Size/MD5: 1114 bb5bf149ce7b8df7a16d7ab7c411d5ed Size/MD5: 675357 3a9cb38f83d7f20391b19e305608f289 Size/MD5: 41819 89fa0f8815e04a0f634241b6c1f364d3 Size/MD5: 1589 61c107f668ad8b4aa25c398b0c93fe1d Size/MD5: 7126288 cdc44e20c2ebaba1fe71c1154030dcd9 Size/MD5: 1081 fcc8bc8330370aa9df477a6b6f6fb819 Size/MD5: 46625228 e35bc6b300ba8ba6795cc3c8544c1c70 Size/MD5: 1268814 35076923ad47e759c7944548421dee51 Size/MD5: 1230 bd4fda6dd2e3c57f2db67e635e805a5b Size/MD5: 1528478 e97a18f7e002d293394726004fc110b7 Architecture independent packages: Size/MD5: 38486 95c5a3b17fd74b4dd632e7c8a2c559ec Size/MD5: 3296778 b77676d76c4a5ba0728fca33aadc238a Size/MD5: 115802 30f9179b2bbeb7fc0170ec9156deedd5 Size/MD5: 49494 bb116eb3227198464792497dbf1b1fa3 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 17026 5fd05c053b42d0ab1228e97953aa8775 Size/MD5: 100988 c8f2b1a6898df9a34715ed306ce0f28d Size/MD5: 6702 35a0280af7c5ad62333b6ad64c612bd9 Size/MD5: 1948612 87efe42bb7facafb8f5c24ecb7d256ef Size/MD5: 579338 3e65b363fad9bb0f9364d13312d438c1 Size/MD5: 1222428 1ec764e382c763932d3485062f9d30a8 Size/MD5: 359272 22eda6f6103d5b22a7fd6734941ce57a i386 architecture (x86 compatible Intel/AMD): Size/MD5: 31736 3930e413a69542a6fe692da52e122bf6 Size/MD5: 79106 7d4f9e0bca4834ffe03160a25fd5d915 Size/MD5: 21908 4da4fbb4969b6f50dfdd970e6b330434 Size/MD5: 1863560 670d52c0413ae0f34b7d515e75f35022 Size/MD5: 545286 900c7fe883d5b0a134e6f562d91dfdff Size/MD5: 1192374 75f56b11566863c175d97f2015c8c4e0 Size/MD5: 346632 08944188ce8e4e48b76f63c6bead71f9 lpia architecture (Low Power Intel Architecture): Size/MD5: 16710 9eca7f0fe03d7555b777e2f3bbd69444 Size/MD5: 92962 6ebfa49dcabb3d76a43c929d0ad9b86d Size/MD5: 6708 1e479fcf05f054761cb6c5f645691272 Size/MD5: 1881282 9acc6a2939b1a0f25d9957170fb2be0d Size/MD5: 540030 f21b130d59e6765fcf62145741edfb31 Size/MD5: 1187040 8b9a8b1a869b4126113c1a42144fa749 Size/MD5: 347230 bb2cf6e1ffd5251a3fdc0ca040591720 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 19474 c8238d336c7d5809ffd284e23e583258 Size/MD5: 101252 71fc2e25b914d62b9dcc84fa34a37bb5 Size/MD5: 6712 f02cac506dc419a8d6bbea10f17f6c31 Size/MD5: 1931954 959869f5deb73dc20ad999df7db6db29 Size/MD5: 576138 a07f45bdb84eda63783fda40635d12a8 Size/MD5: 1212598 1e1c5ab7e9e4e1ad45763faffc0e2d83 Size/MD5: 361420 7f1093eb894d3c55c8d15efd793ae451 . Important modifications for web rendering engine in Ubuntu 8.04 LTS targeting vulnerabilities linked to denial of service and potential code execution threats.. Denial of Service, Security Advisory, Ubuntu Updates, Code Execution Risks. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.