MGASA-2018-0097
Dashboard / Vulnerabilities / MGASA-2018-0097
MGASA-2018-0097
Summary: Updated firefox packages fix security vulnerabilities
Details: Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox (CVE-2018-5089, CVE-2018-5091, CVE-2018-5095, CVE-2018-5096, CVE-2018-5097, CVE-2018-5098, CVE-2018-5099, CVE-2018-5102, CVE-2018-5103, CVE-2018-5104, CVE-2018-5117). To mitigate timing-based side-channel attacks similar to "Spectre" and "Meltdown", the resolution of performance.now() has been reduced from 5μs to 20μs.
References: https://advisories.mageia.org/MGASA-2018-0097.html, https://bugs.mageia.org/show_bug.cgi?id=22432, https://www.mozilla.org/en-US/security/advisories/mfsa2018-01/, https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/, https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/, https://access.redhat.com/errata/RHSA-2018:0122
Affected packages
Package
Name: nspr
Purl: pkg:rpm/mageia/nspr?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
