firefox-78.12.0-1.el8.ML.1

エラータID: AXSA:2021-2303:20

Release date: 
Tuesday, August 10, 2021 - 04:14
Subject: 
firefox-78.12.0-1.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 78.12.0 ESR.

Security Fix(es):

* Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970)
* Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976)
* chromium-browser: Out of bounds write in ANGLE (CVE-2021-30547)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-29970
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
CVE-2021-29976
Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
CVE-2021-30547
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-78.12.0-1.el8.ML.1.src.rpm
    MD5: 8353edda11594635c008728f58bae7ce
    SHA-256: e8c34d7649fe1e601a04731fb873fceaf4036e2dcb358071a978e35e57275340
    Size: 673.66 MB

Asianux Server 8 for x86_64
  1. firefox-78.12.0-1.el8.ML.1.x86_64.rpm
    MD5: c1e913d0587989654a2983a10a3af479
    SHA-256: 77c092d94b194edec884d5cadfaa9dc5cabdf0641131da05326b8f471cdb3dbf
    Size: 101.73 MB