firefox-78.5.0-1.0.1.AXS4

エラータID: AXSA:2020-966:26

Release date: 
Thursday, December 3, 2020 - 12:50
Subject: 
firefox-78.5.0-1.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 78.5.0 ESR.

Security Fix(es):

* Mozilla: Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code (CVE-2020-26951)

* Mozilla: Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5 (CVE-2020-26968)

* Mozilla: Variable time processing of cross-origin images during drawImage calls (CVE-2020-16012)

* Mozilla: Fullscreen could be enabled without displaying the security UI (CVE-2020-26953)

* Mozilla: XSS through paste (manual and clipboard API) (CVE-2020-26956)

* Mozilla: Requests intercepted through ServiceWorkers lacked MIME type restrictions (CVE-2020-26958)

* Mozilla: Use-after-free in WebRequestService (CVE-2020-26959)

* Mozilla: Potential use-after-free in uses of nsTArray (CVE-2020-26960)

* Mozilla: DoH did not filter IPv4 mapped IP Addresses (CVE-2020-26961)

* Mozilla: Software keyboards may have remembered typed passwords (CVE-2020-26965)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-16012
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26951
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26953
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26956
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26958
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26959
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26960
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26961
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26965
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2020-26968
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-78.5.0-1.0.1.AXS4.src.rpm
    MD5: 0b68bf9048e72af8a14227be1cf5e43c
    SHA-256: 0dfd2d08f214b590f9196c7f9e3980e8e3a7c94fe5b655df5284745ecb9b990a
    Size: 690.50 MB

Asianux Server 4 for x86
  1. firefox-78.5.0-1.0.1.AXS4.i686.rpm
    MD5: 6f11b7e8254c82283bfe22040950bf0d
    SHA-256: f039505120dc3a62ca5d8cbd8b82e87e0c236b5b2279948178b7eb7388ecad49
    Size: 129.93 MB

Asianux Server 4 for x86_64
  1. firefox-78.5.0-1.0.1.AXS4.x86_64.rpm
    MD5: d6e8447a1f6d8c7d1ff51955b77fd46b
    SHA-256: 6499118ee86b0294d6a56456287fe37e6d38a67f0a6e859610c3957ede6ce811
    Size: 126.52 MB
  2. firefox-78.5.0-1.0.1.AXS4.i686.rpm
    MD5: 6f11b7e8254c82283bfe22040950bf0d
    SHA-256: f039505120dc3a62ca5d8cbd8b82e87e0c236b5b2279948178b7eb7388ecad49
    Size: 129.93 MB