firefox-45.4.0-1.0.1.el7.AXS7

エラータID: AXSA:2016-681:07

Release date: 
Friday, September 23, 2016 - 18:33
Subject: 
firefox-45.4.0-1.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance and portability.

Security issues fixed with this release:

CVE-2016-5250
Mozilla Firefox before 48.0 allows remote attackers to obtain
sensitive information about the previously retrieved page via Resource
Timing API calls.
CVE-2016-5257
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5261
Integer overflow in the WebSocketChannel class in the WebSockets
subsystem in Mozilla Firefox before 48.0 allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via crafted packets that trigger incorrect buffer-resize
operations during buffering.
CVE-2016-5270
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5272
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5274
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5276
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5277
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5278
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5280
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5281
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2016-5284
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-45.4.0-1.0.1.el7.AXS7.src.rpm
    MD5: fced7a77660bc0e667df8e3820e12582
    SHA-256: eb8eab281192b8ebe37a081c42faee076a359cb2377e40e83a4613a376d84631
    Size: 337.83 MB

Asianux Server 7 for x86_64
  1. firefox-45.4.0-1.0.1.el7.AXS7.x86_64.rpm
    MD5: 199069cac7ff0382fd410dad8e39720c
    SHA-256: 11fb5ee895542d550ed73b7052439bc86e6d367b58590591078dacb6f3df6e05
    Size: 76.35 MB
  2. firefox-45.4.0-1.0.1.el7.AXS7.i686.rpm
    MD5: df5349c02726a834923038035d672538
    SHA-256: 42495bd66d4ddb2a61bcd5cffce7cf48ff1bf44a2520261754d400ce9c250aca
    Size: 76.63 MB