MGASA-2018-0202
Dashboard / Vulnerabilities / MGASA-2018-0202
MGASA-2018-0202
Summary: Updated firefox packages fix security vulnerability
Details: Memory safety bugs fixed in Firefox ESR 52.7 (CVE-2018-5125). Buffer overflow manipulating SVG animatedPathSegList (CVE-2018-5127). Out-of-bounds write with malformed IPC messages (CVE-2018-5129). Mismatched RTP payload type can trigger memory corruption (CVE-2018-5130). Fetch API improperly returns cached copies of no-store/no-cache resources (CVE-2018-5131). Integer overflow during Unicode conversion (CVE-2018-5144). Memory safety bugs fixed in Firefox ESR 52.7 (CVE-2018-5145). A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash (CVE-2018-5148).
References: https://advisories.mageia.org/MGASA-2018-0202.html, https://bugs.mageia.org/show_bug.cgi?id=22776, https://www.mozilla.org/en-US/security/advisories/mfsa2018-07/, https://www.mozilla.org/en-US/security/advisories/mfsa2018-10/, https://www.mozilla.org/security/known-vulnerabilities/firefox-esr/, https://access.redhat.com/errata/RHSA-2018:0527
Affected packages
Package
Name: firefox
Purl: pkg:rpm/mageia/firefox?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
