USN-6074-1 caused some minor regressions in Firefox.. =========================================================================Ubuntu Security Notice USN-6074-2 May 16, 2023 firefox regressions ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: USN-6074-1 caused some minor regressions in Firefox. Software Description: - firefox: Mozilla Open Source web browser Details: USN-6074-1 fixed vulnerabilities in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-32205, CVE-2023-32207, CVE-2023-32210, CVE-2023-32211, CVE-2023-32212, CVE-2023-32213, CVE-2023-32215, CVE-2023-32216) Irvan Kurniawan discovered that Firefox did not properly manage memory when using RLBox Expat driver. An attacker could potentially exploits this issue to cause a denial of service. (CVE-2023-32206) Anne van Kesteren discovered that Firefox did not properly validate the import() call in service workers. An attacker could potentially exploits this to obtain sensitive information. (CVE-2023-32208) Sam Ezeh discovered that Firefox did not properly handle certain favicon image files. If a user were tricked into opening a malicicous favicon file, an attacker could cause a denial of service. (CVE-2023-32209) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: firefox 113.0.1+build1-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 113.0.1+build1-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6074-2 https://ubuntu.com/security/notices/USN-6074-1 https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/2019782 Package Information: https://launchpad.net/ubuntu/+source/firefox/113.0.1+build1-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/113.0.1+build1-0ubuntu0.18.04.1 . We are releasing Ubuntu's USN-6081-1 advisory that addresses recent regression issues encountered in Firefox. Detailed update instructions to rectify these problems are included.. Firefox Update, Ubuntu Advisory, Security Fix, Web Browser Bug. . Severity: Critical. LinuxSecurity.com Team
* New upstream version (92.0). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-09ba2aa171 2021-09-10 16:04:06.977961 --------------------------------------------------------------------------------Name : firefox Product : Fedora 34 Version : 92.0 Release : 2.fc34 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: * New upstream version (92.0) --------------------------------------------------------------------------------ChangeLog: * Thu Sep 9 2021 Martin Stransky - 92.0-2 - Disable test * Fri Sep 3 2021 Martin Stransky - 92.0-1 - Updated to 92.0 - Added fix for mozbz#1728749 - Added fix for mozbz#1708709 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-09ba2aa171' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- New upstream version (82.0.2) - Fixed Wayland crashes (rhbz#1888920). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-1a48fa788b 2020-10-31 01:53:00.658388 --------------------------------------------------------------------------------Name : firefox Product : Fedora 33 Version : 82.0.2 Release : 1.fc33 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - New upstream version (82.0.2) - Fixed Wayland crashes (rhbz#1888920) --------------------------------------------------------------------------------ChangeLog: * Thu Oct 29 2020 Martin Stransky - 82.0.2-1 - Updated to 82.0.2 - Removed mzbz#1668771 due to rhbz#1888920 * Wed Oct 28 2020 Martin Stransky - 82.0.1-1 - Updated to 82.0.1 * Tue Oct 27 2020 Martin Stransky - 82.0-8 - Added fix for mozbz#1673313 * Tue Oct 27 2020 Martin Stransky - 82.0-7 - Added fix for rawhide crashes (rhbz#1891234) * Sat Oct 24 2020 Martin Stransky - 82.0-6 - Enable LTO --------------------------------------------------------------------------------References: [ 1 ] Bug #1888920 - Firefox crashes on wayland with WL: error in client communication https://bugzilla.redhat.com/show_bug.cgi?id=1888920 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-1a48fa788b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- update to new upstream (50.0). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e39b7c826b 2016-11-20 11:37:16.810973 -------------------------------------------------------------------------------- Name : firefox Product : Fedora 23 Version : 50.0 Release : 1.fc23 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. -------------------------------------------------------------------------------- Update Information: - update to new upstream (50.0) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade firefox' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.