firefox-60.3.0-1.0.1.el7.AXS7

エラータID: AXSA:2018-3376:08

Release date: 
Monday, November 5, 2018 - 07:01
Subject: 
firefox-60.3.0-1.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 60.3.0 ESR.

Security Fix(es):

* Mozilla: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3 (CVE-2018-12390)

* Mozilla: Crash with nested event loops (CVE-2018-12392)

* Mozilla: Integer overflow during Unicode conversion while loading JavaScript (CVE-2018-12393)

* Mozilla: WebExtension bypass of domain restrictions through header rewriting (CVE-2018-12395)

* Mozilla: WebExtension content scripts can execute in disallowed contexts (CVE-2018-12396)

* Mozilla: WebExtension local file permission check bypass (CVE-2018-12397)

* Mozilla: Memory safety bugs fixed in Firefox ESR 60.3 (CVE-2018-12389)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Asianux would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Christian Holler, Bob Owen, Boris Zbarsky, Calixte Denizet, Jason Kratzer, Jed Davis, Taegeon Lee, Philipp, Ronald Crane, Raul Gurzau, Gary Kwong, Tyson Smith, Raymond Forbes, Bogdan Tara, Nils, r, Rob Wu, Andrew Swan, and Daniel Veditz as the original reporters.

Bug Fix(es):

* Previously, passwords saved in the Firefox browser and encrypted by a master password were erased when Firefox was exited. This update ensures that NSS files used to decrypt stored login data are handled correctly. As a result, the affected passwords are no longer lost after restarting Firefox. (BZ#1638082)

CVE-2018-12389
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.
CVE-2018-12390
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.
CVE-2018-12392
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.
CVE-2018-12393
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.
CVE-2018-12395
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.
CVE-2018-12396
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.
CVE-2018-12397
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-60.3.0-1.0.1.el7.AXS7.src.rpm
    MD5: a4f4d6313636d026f1eec8db3d42e4e1
    SHA-256: 1fc6c4810b4ec5153a8a1be979b2b0984c366bf8135678de9878b4b8256b147f
    Size: 416.10 MB

Asianux Server 7 for x86_64
  1. firefox-60.3.0-1.0.1.el7.AXS7.x86_64.rpm
    MD5: dac3da25f4f379be19e906f38837cb98
    SHA-256: aafcdb3f4efc61d702f36d2a9018b1928dd22a129ef375bdd1981b0621b391ec
    Size: 90.64 MB
  2. firefox-60.3.0-1.0.1.el7.AXS7.i686.rpm
    MD5: c0a3c84c461c60a1cd160f7c0c4120fd
    SHA-256: 4f654a7bffcf3bbc98709e673afdbf4ba6d75958b29845a9946abd2493e43660
    Size: 92.38 MB