Sandbox escape via installation of malicious language pack. (CVE-2019-9811) Script injection within domain through inner window reuse. (CVE-2019-11711) Cross-origin POST requests can be made with NPAPI plugins by following 308 . MGASA-2019-0212 - Updated thunderbird packages fix security vulnerability Publication date: 21 Jul 2019 URL: https://advisories.mageia.org/MGASA-2019-0212.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-9811, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713, CVE-2019-11729, CVE-2019-11715, CVE-2019-11717, CVE-2019-11719, CVE-2019-11730, CVE-2019-11709 Sandbox escape via installation of malicious language pack. (CVE-2019-9811) Script injection within domain through inner window reuse. (CVE-2019-11711) Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects. (CVE-2019-11712) Use-after-free with HTTP/2 cached stream. (CVE-2019-11713) Empty or malformed p256-ECDH public keys may trigger a segmentation fault. (CVE-2019-11729) HTML parsing error can contribute to content XSS. (CVE-2019-11715) Caret character improperly escaped in origins. (CVE-2019-11717) Out-of-bounds read when importing curve25519 private key. (CVE-2019-11719) Same-origin policy treats all files in a directory as having the same-origin. (CVE-2019-11730) Memory safety bugs fixed in Firefox 68, Firefox ESR 60.8 and Thunderbird 60.8. (CVE-2019-11709) Enigmail 2.0.12 sets the default keyserver to keys.openpgp.org in order to mitigate the SKS Keyserver Network Attack. References: - https://bugs.mageia.org/show_bug.cgi?id=25103 - https://www.thunderbird.net/en-US/thunderbird/60.8.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2019-23/ - https://enigmail.net/index.php/en/download/changelog#enig2.0.12 - https://access.redhat.com/errata/RHSA-2019:1775 - https://www.cve.org/CVERecord?id=CVE-2019-9811 - https://www.cve.org/CVERecord?id=CVE-2019-11711 - https://www.cve.org/CVERecord?id=CVE-2019-11712 -https://www.cve.org/CVERecord?id=CVE-2019-11713 - https://www.cve.org/CVERecord?id=CVE-2019-11729 - https://www.cve.org/CVERecord?id=CVE-2019-11715 - https://www.cve.org/CVERecord?id=CVE-2019-11717 - https://www.cve.org/CVERecord?id=CVE-2019-11719 - https://www.cve.org/CVERecord?id=CVE-2019-11730 - https://www.cve.org/CVERecord?id=CVE-2019-11709 SRPMS: - 6/core/thunderbird-60.8.0-1.1.mga6 - 6/core/thunderbird-l10n-60.8.0-1.mga6 - 7/core/thunderbird-60.8.0-1.1.mga7 - 7/core/thunderbird-l10n-60.8.0-1.mga7 . Revised Thunderbird versions address security flaws related to script injection and sandbox bypass vulnerabilities.. thunderbird security update, mageia security advisory, malicious language pack, script injection, cross-origin request. . Severity: Medium. LinuxSecurity.com Team
This update upgrades Firefox to version 60.8.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following [More...]. Synopsis: Critical: firefox security update Advisory ID: SLSA-2019:1763-1 Issue Date: 2019-07-11 CVE Numbers: CVE-2019-11709 CVE-2019-11711 CVE-2019-11712 CVE-2019-11713 CVE-2019-11715 CVE-2019-11717 CVE-2019-11730 CVE-2019-9811 -- This update upgrades Firefox to version 60.8.0 ESR. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects (CVE-2019-11712) * Mozilla: Use-after-free with HTTP/2 cached stream (CVE-2019-11713) * Mozilla: HTML parsing error can contribute to content XSS (CVE-2019-11715) * Mozilla: Caret character improperly escaped in origins (CVE-2019-11717) * Mozilla: Same-origin policy treats all files in a directory as having the same-origin (CVE-2019-11730) -- SL7 x86_64 firefox-60.8.0-1.el7_6.x86_64.rpm firefox-debuginfo-60.8.0-1.el7_6.x86_64.rpm firefox-60.8.0-1.el7_6.i686.rpm firefox-debuginfo-60.8.0-1.el7_6.i686.rpm - Scientific Linux Development Team . Critical Firefox patch for Scientific Linux addresses memory integrity flaws and scripting exploit risks.. firefox update, critical security, Scientific Linux, malicious language pack, memory safety. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.