MGASA-2015-0305
Dashboard / Vulnerabilities / MGASA-2015-0305
Summary: Updated firefox package fixes CVE-2015-4495
Details: Updated firefox packages fix security vulnerability: Security researcher Cody Crews reported on a way to violate the same origin policy and inject script into a non-privileged part of the built-in PDF Viewer in Firefox. This would allow an attacker to read and steal sensitive local files on the victim's computer (CVE-2015-4495).
References: https://advisories.mageia.org/MGASA-2015-0305.html, https://bugs.mageia.org/show_bug.cgi?id=16550, https://www.mozilla.org/en-US/security/advisories/mfsa2015-78/, https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/
Affected packages
Package
Name: firefox
Purl: pkg:rpm/mageia/firefox?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
