firefox-38.5.0-3.0.1.el7.AXS7

エラータID: AXSA:2015-966:04

Release date: 
Wednesday, December 23, 2015 - 11:44
Subject: 
firefox-38.5.0-3.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance and portability.

Security issues fixed with this release:

CVE-2015-7201
Multiple unspecified vulnerabilities in the browser engine in Mozilla
Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote
attackers to cause a denial of service (memory corruption and
application crash) or possibly execute arbitrary code via unknown
vectors.
CVE-2015-7205
Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might
allow remote attackers to obtain sensitive information, cause a denial
of service, or possibly have unspecified other impact by triggering a
crafted WebRTC RTP packet.
CVE-2015-7210
Use-after-free vulnerability in Mozilla Firefox before 43.0 and
Firefox ESR 38.x before 38.5 allows remote attackers to execute
arbitrary code by triggering attempted use of a data channel that has
been closed by a WebRTC function.
CVE-2015-7212
Integer overflow in the
mozilla::layers::BufferTextureClient::AllocateForSurface function in
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows
remote attackers to execute arbitrary code by triggering a graphics
operation that requires a large texture allocation.
CVE-2015-7213
Integer overflow in the MPEG4Extractor::readMetaData function in
MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0
and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote
attackers to execute arbitrary code via a crafted MP4 video file that
triggers a buffer overflow.
CVE-2015-7214
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow
remote attackers to bypass the Same Origin Policy via data: and
view-source: URIs.
CVE-2015-7222
Integer underflow in the Metadata::setData function in MetaData.cpp in
libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x
before 38.5 allows remote attackers to execute arbitrary code or cause
a denial of service (incorrect memory allocation and application
crash) via an MP4 video file with crafted covr metadata that triggers
a buffer overflow.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-38.5.0-3.0.1.el7.AXS7.src.rpm
    MD5: 8fb7c62ce23120573245615d1bb00b4a
    SHA-256: 8f81e35c7fba2830787ad4b322d5c8ec6cb8e730b853aa1ab0928e0cf5312f40
    Size: 305.59 MB

Asianux Server 7 for x86_64
  1. firefox-38.5.0-3.0.1.el7.AXS7.x86_64.rpm
    MD5: 362fac3398082da7e51ee91614d3802d
    SHA-256: 41dd93b9a6574c1c56ddbc9829c0cdfa82a40c87d4fed3959df43eafc40b0f1a
    Size: 71.54 MB
  2. firefox-38.5.0-3.0.1.el7.AXS7.i686.rpm
    MD5: d3e41ab5ad2ab32221b472f41ef0c883
    SHA-256: 7f8edaf6a20148e94b7c2eb9f3a8f7eb6115f9ebef16f2acd947819fbf7d40c4
    Size: 71.76 MB