firefox-68.6.0-1.0.1.AXS4

エラータID: AXSA:2020-4526:07

Release date: 
Wednesday, March 25, 2020 - 06:10
Subject: 
firefox-68.6.0-1.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 68.6.0 ESR.

Security Fix(es):

* Mozilla: Use-after-free when removing data about origins (CVE-2020-6805)

* Mozilla: BodyStream::OnInputStreamReady was missing protections against state confusion (CVE-2020-6806)

* Mozilla: Use-after-free in cubeb during stream destruction (CVE-2020-6807)

* Mozilla: Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6 (CVE-2020-6814)

* Mozilla: Out of bounds reads in sctp_load_addresses_from_init (CVE-2019-20503)

* Mozilla: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection (CVE-2020-6811)

* Mozilla: The names of AirPods with personally identifiable information were exposed to websites with camera or microphone permission (CVE-2020-6812)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2019-20503
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
CVE-2020-6805
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-6806
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-6807
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-6811
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-6812
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-6814
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-68.6.0-1.0.1.AXS4.src.rpm
    MD5: 4d49cffcf4f98f11beed2dd4bda1efa1
    SHA-256: 50f9a539ea89fb98edb89449d7a012f32e5769862be4871888cc878093577c20
    Size: 506.69 MB

Asianux Server 4 for x86
  1. firefox-68.6.0-1.0.1.AXS4.i686.rpm
    MD5: 256ac07d0621c9950fbc3c8d16bea3df
    SHA-256: c2b2c7018e89f36cee4efe247d9d71d85bbfb63bc570a98aad39aab6b40a3a6e
    Size: 118.36 MB

Asianux Server 4 for x86_64
  1. firefox-68.6.0-1.0.1.AXS4.x86_64.rpm
    MD5: 11639e40ba66a02cc845e22a382ac00b
    SHA-256: a4578f4016432ab64d9a0d8ea6e23634985081ba73715f73eba79e45d3debb4f
    Size: 118.46 MB
  2. firefox-68.6.0-1.0.1.AXS4.i686.rpm
    MD5: 256ac07d0621c9950fbc3c8d16bea3df
    SHA-256: c2b2c7018e89f36cee4efe247d9d71d85bbfb63bc570a98aad39aab6b40a3a6e
    Size: 118.36 MB