| Summary: | Firefox and Thunderbird 31.5 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | sysadmin-bugs |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/634775/ | ||
| Whiteboard: | has_procedure advisory MGA4-32-OK mga4-64-ok | ||
| Source RPM: | nspr, nss, firefox, thunderbird | CVE: | |
| Status comment: | |||
|
Description
David Walser
2015-02-25 04:08:15 CET
Both are working fine for me on Mageia 4 i586. Whiteboard:
(none) =>
MGA4-32-OK Testing complete mga4 64 all tests ok. thunderbird (imap, pop3, smtp, search, enigmail, spelling) firefox (flash, https, http, search, bookmarks, spelling) Whiteboard:
MGA4-32-OK =>
MGA4-32-OK mga4-64-ok RedHat's Thunderbird advisory is available: https://rhn.redhat.com/errata/RHSA-2015-0266.html Advisory: ======================== Updated firefox and thunderbird packages fix security vulnerabilities: Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox or Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running it (CVE-2015-0836, CVE-2015-0831, CVE-2015-0827). An information leak flaw was found in the way Firefox and Thunderbird implemented autocomplete forms. An attacker able to trick a user into specifying a local file in the form could use this flaw to access the contents of that file (CVE-2015-0822). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0822 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0827 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0831 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0836 https://www.mozilla.org/en-US/security/advisories/mfsa2015-11/ https://www.mozilla.org/en-US/security/advisories/mfsa2015-16/ https://www.mozilla.org/en-US/security/advisories/mfsa2015-19/ https://www.mozilla.org/en-US/security/advisories/mfsa2015-24/ https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/ https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/ https://rhn.redhat.com/errata/RHSA-2015-0265.html https://rhn.redhat.com/errata/RHSA-2015-0266.html URL:
(none) =>
http://lwn.net/Vulnerabilities/634775/ Validating. Advisory uploaded. Please push to 4 updates Thanks Keywords:
(none) =>
validated_update An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2015-0089.html Status:
NEW =>
RESOLVED |