firefox-52.6.0-1.0.1.AXS4

エラータID: AXSA:2018-2539:01

Release date: 
Friday, January 26, 2018 - 17:09
Subject: 
firefox-52.6.0-1.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Mozilla Firefox is an open source web browser.

This update upgrades Firefox to version 52.6.0 ESR.

Security Fix(es):

* Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2018-5089, CVE-2018-5091, CVE-2018-5095, CVE-2018-5096, CVE-2018-5097, CVE-2018-5098, CVE-2018-5099, CVE-2018-5102, CVE-2018-5103, CVE-2018-5104, CVE-2018-5117)

* To mitigate timing-based side-channel attacks similar to "Spectre" and "Meltdown", the resolution of performance.now() has been reduced from 5μs to 20μs.

Asianux would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Christian Holler, Jason Kratzer, Marcia Knous, Nathan Froyd, Oriol Brufau, Ronald Crane, Randell Jesup, Tyson Smith, Cobos Álvarez, Ryan VanderMeulen, Sebastian Hengst, Karl Tomlinson, Xidorn Quan, Ludovic Hirlimann, Jason Orendorff, Looben Yang, Anonymous, Nils, and Xisigr as the original reporters.

CVE-2018-5089
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5091
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5095
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5096
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5097
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5098
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5099
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5102
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5103
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5104
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.
CVE-2018-5117
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-52.6.0-1.0.1.AXS4.src.rpm
    MD5: 7aa1c7c90ae0a350599e217a533d7938
    SHA-256: 966b4b1af19f4dc3d3ce4e3c4e48c3cb88410de30aab2eac5af110f7d8d83612
    Size: 370.10 MB

Asianux Server 4 for x86
  1. firefox-52.6.0-1.0.1.AXS4.i686.rpm
    MD5: 616ea62d5e009dd4c6d18f08177db423
    SHA-256: 5c7760a39b4f2047506635fc03b10bae8abbc5b75b81ebdb72a6e7ebfea9fa80
    Size: 80.19 MB

Asianux Server 4 for x86_64
  1. firefox-52.6.0-1.0.1.AXS4.x86_64.rpm
    MD5: 0d4007639e5e17c967175f4bfe941d1c
    SHA-256: 90f5a3c4cb1300928a2c4f11016405c2197d34f20dedd655a43d90c4e8aec13b
    Size: 79.72 MB
  2. firefox-52.6.0-1.0.1.AXS4.i686.rpm
    MD5: 616ea62d5e009dd4c6d18f08177db423
    SHA-256: 5c7760a39b4f2047506635fc03b10bae8abbc5b75b81ebdb72a6e7ebfea9fa80
    Size: 80.19 MB