firefox-78.3.0-1.0.1.AXS4

エラータID: AXSA:2020-825:20

Release date: 
Wednesday, October 28, 2020 - 06:20
Subject: 
firefox-78.3.0-1.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 78.3.0 ESR.

Security Fix(es):

* Mozilla: Memory safety bugs fixed in Firefox 81 and Firefox ESR 78.3 (CVE-2020-15673)

* Mozilla: XSS when pasting attacker-controlled data into a contenteditable element (CVE-2020-15676)

* Mozilla: Download origin spoofing via redirect (CVE-2020-15677)

* Mozilla: When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free scenario (CVE-2020-15678)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-15673
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-15676
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-15677
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-15678
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-78.3.0-1.0.1.AXS4.src.rpm
    MD5: 4725d907951be2c69d73ea197611391e
    SHA-256: 1d369fb5ae9073ab11365df2784b2d3010ab37fd7521827f0a1f284cac434225
    Size: 690.88 MB

Asianux Server 4 for x86
  1. firefox-78.3.0-1.0.1.AXS4.i686.rpm
    MD5: ed7bbc0ab0fd406c47e5238b2e5c63fe
    SHA-256: ca767f0313e382b629878a92f05f5118ec5d69d3c8c99aaa5023553b2e41c8e5
    Size: 133.45 MB

Asianux Server 4 for x86_64
  1. firefox-78.3.0-1.0.1.AXS4.x86_64.rpm
    MD5: 001a27251ccbdc575b6eff68a36934fb
    SHA-256: 3af6fc3820cd0e97afeb530495d2a3b907e5229a5c89169da8a4927ee9fb4b3b
    Size: 130.11 MB
  2. firefox-78.3.0-1.0.1.AXS4.i686.rpm
    MD5: ed7bbc0ab0fd406c47e5238b2e5c63fe
    SHA-256: ca767f0313e382b629878a92f05f5118ec5d69d3c8c99aaa5023553b2e41c8e5
    Size: 133.45 MB