firefox-68.2.0-1.0.1.el7.AXS7

エラータID: AXSA:2019-4378:06

Release date: 
Monday, November 11, 2019 - 08:39
Subject: 
firefox-68.2.0-1.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 68.2.0 ESR.

Security Fix(es):

* Mozilla: Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2 (CVE-2019-11764)

* Mozilla: Use-after-free when creating index updates in IndexedDB (CVE-2019-11757)

* Mozilla: Potentially exploitable crash due to 360 Total Security (CVE-2019-11758)

* Mozilla: Stack buffer overflow in HKDF output (CVE-2019-11759)

* Mozilla: Stack buffer overflow in WebRTC networking (CVE-2019-11760)

* Mozilla: Unintended access to a privileged JSONView object (CVE-2019-11761)

* Mozilla: document.domain-based origin isolation has same-origin-property violation (CVE-2019-11762)

* Mozilla: Incorrect HTML parsing results in XSS bypass technique (CVE-2019-11763)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2019-11757
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-11758
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-11759
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-11760
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-11761
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-11762
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-11763
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-11764
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-68.2.0-1.0.1.el7.AXS7.src.rpm
    MD5: 55ef15c2b8feb42dba529a7e4da9c871
    SHA-256: e1f42acd4cae955f4c39fa6f07846f2306337f73980f289fcb0beb979e3357b8
    Size: 504.01 MB

Asianux Server 7 for x86_64
  1. firefox-68.2.0-1.0.1.el7.AXS7.x86_64.rpm
    MD5: 28bd772d303699eb8fba94603850ed25
    SHA-256: 375bdae39c6bab64824af49857b1231b4b0038b3df3d07f0bf51857767047735
    Size: 94.22 MB
  2. firefox-68.2.0-1.0.1.el7.AXS7.i686.rpm
    MD5: 1f694d6e4014ea14247ed7a095aa1d5f
    SHA-256: 5ab8cc40e3616e25b4df5fcc0f99afc871d08039a22b85e16b1b45f4398f75ec
    Size: 97.05 MB