MGASA-2014-0006
Dashboard / Vulnerabilities / MGASA-2014-0006
MGASA-2014-0006
Summary: Updated firefox and thunderbird packages fix security vulnerabilities
Details: Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox or Thunderbird to terminate unexpectedly or, potentially, execute arbitrary code with the privileges of the user running Firefox or Thunderbird (CVE-2013-5609, CVE-2013-5616, CVE-2013-5618, CVE-2013-6671, CVE-2013-5613). It was found that a subordinate Certificate Authority (CA) mis-issued an intermediate certificate, which could be used to conduct man-in-the-middle attacks. This update renders that particular intermediate certificate as untrusted (MFSA 2013-117). The rootcerts and nss packages have been updated to fix the MFSA 2013-117 issue. The thunderbird-lightning package has been updated to a version that is compatible with the updated thunderbird.
References: https://advisories.mageia.org/MGASA-2014-0006.html, https://bugs.mageia.org/show_bug.cgi?id=11945, http://www.mozilla.org/security/announce/2013/mfsa2013-104.html, http://www.mozilla.org/security/announce/2013/mfsa2013-108.html, http://www.mozilla.org/security/announce/2013/mfsa2013-109.html, http://www.mozilla.org/security/announce/2013/mfsa2013-111.html, http://www.mozilla.org/security/announce/2013/mfsa2013-114.html, http://www.mozilla.org/security/announce/2013/mfsa2013-117.html, http://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html, http://www.mozilla.org/security/known-vulnerabilities/thunderbird.html, https://rhn.redhat.com/errata/RHSA-2013-1812.html, https://rhn.redhat.com/errata/RHSA-2013-1823.html, https://rhn.redhat.com/errata/RHSA-2013-1861.html
Affected packages
Package
Name: rootcerts
Purl: pkg:rpm/mageia/rootcerts?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
