Bug 26325

Summary: Firefox 68.6
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: andrewsfarm, fri, herman.viaene, joselp, sysadmin-bugs, tmb
Version: 7Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA7-64-OK MGA7-32-OK
Source RPM: nss, firefox, firefox-l10n CVE:
Status comment:
Bug Depends on:    
Bug Blocks: 26334    

Description David Walser 2020-03-10 14:07:33 CET
Mozilla has released Firefox 68.6.0 today (March 10):
https://www.mozilla.org/en-US/firefox/68.6.0/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2020-09/

NSS 3.51 will go along with it:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.51_release_notes

NSS updates are building for Mageia 7 and Cauldron, and firefox and firefox-l10n are checked into SVN.
Comment 1 David Walser 2020-03-10 17:15:48 CET
All packages built and uploaded.  Upstream advisory released.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20503
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6805
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6806
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6807
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6811
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6812
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6814
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.51_release_notes
https://www.mozilla.org/en-US/security/advisories/mfsa2020-09/
========================

Updated packages in core/updates_testing:
========================
nss-3.51.0-1.mga7
nss-doc-3.51.0-1.mga7
libnss3-3.51.0-1.mga7
libnss-devel-3.51.0-1.mga7
libnss-static-devel-3.51.0-1.mga7
firefox-68.6.0-1.mga7
firefox-devel-68.6.0-1.mga7
firefox-af-68.6.0-1.mga7
firefox-an-68.6.0-1.mga7
firefox-ar-68.6.0-1.mga7
firefox-ast-68.6.0-1.mga7
firefox-az-68.6.0-1.mga7
firefox-bg-68.6.0-1.mga7
firefox-bn-68.6.0-1.mga7
firefox-br-68.6.0-1.mga7
firefox-bs-68.6.0-1.mga7
firefox-ca-68.6.0-1.mga7
firefox-cs-68.6.0-1.mga7
firefox-cy-68.6.0-1.mga7
firefox-da-68.6.0-1.mga7
firefox-de-68.6.0-1.mga7
firefox-el-68.6.0-1.mga7
firefox-en_GB-68.6.0-1.mga7
firefox-en_US-68.6.0-1.mga7
firefox-eo-68.6.0-1.mga7
firefox-es_AR-68.6.0-1.mga7
firefox-es_CL-68.6.0-1.mga7
firefox-es_ES-68.6.0-1.mga7
firefox-es_MX-68.6.0-1.mga7
firefox-et-68.6.0-1.mga7
firefox-eu-68.6.0-1.mga7
firefox-fa-68.6.0-1.mga7
firefox-ff-68.6.0-1.mga7
firefox-fi-68.6.0-1.mga7
firefox-fr-68.6.0-1.mga7
firefox-fy_NL-68.6.0-1.mga7
firefox-ga_IE-68.6.0-1.mga7
firefox-gd-68.6.0-1.mga7
firefox-gl-68.6.0-1.mga7
firefox-gu_IN-68.6.0-1.mga7
firefox-he-68.6.0-1.mga7
firefox-hi_IN-68.6.0-1.mga7
firefox-hr-68.6.0-1.mga7
firefox-hsb-68.6.0-1.mga7
firefox-hu-68.6.0-1.mga7
firefox-hy_AM-68.6.0-1.mga7
firefox-id-68.6.0-1.mga7
firefox-is-68.6.0-1.mga7
firefox-it-68.6.0-1.mga7
firefox-ja-68.6.0-1.mga7
firefox-kk-68.6.0-1.mga7
firefox-km-68.6.0-1.mga7
firefox-kn-68.6.0-1.mga7
firefox-ko-68.6.0-1.mga7
firefox-lij-68.6.0-1.mga7
firefox-lt-68.6.0-1.mga7
firefox-lv-68.6.0-1.mga7
firefox-mk-68.6.0-1.mga7
firefox-mr-68.6.0-1.mga7
firefox-ms-68.6.0-1.mga7
firefox-nb_NO-68.6.0-1.mga7
firefox-nl-68.6.0-1.mga7
firefox-nn_NO-68.6.0-1.mga7
firefox-pa_IN-68.6.0-1.mga7
firefox-pl-68.6.0-1.mga7
firefox-pt_BR-68.6.0-1.mga7
firefox-pt_PT-68.6.0-1.mga7
firefox-ro-68.6.0-1.mga7
firefox-ru-68.6.0-1.mga7
firefox-si-68.6.0-1.mga7
firefox-sk-68.6.0-1.mga7
firefox-sl-68.6.0-1.mga7
firefox-sq-68.6.0-1.mga7
firefox-sr-68.6.0-1.mga7
firefox-sv_SE-68.6.0-1.mga7
firefox-ta-68.6.0-1.mga7
firefox-te-68.6.0-1.mga7
firefox-th-68.6.0-1.mga7
firefox-tr-68.6.0-1.mga7
firefox-uk-68.6.0-1.mga7
firefox-uz-68.6.0-1.mga7
firefox-vi-68.6.0-1.mga7
firefox-xh-68.6.0-1.mga7
firefox-zh_CN-68.6.0-1.mga7
firefox-zh_TW-68.6.0-1.mga7

from SRPMS:
nss-3.51.0-1.mga7.src.rpm
firefox-68.6.0-1.mga7.src.rpm
firefox-l10n-68.6.0-1.mga7.src.rpm

Assignee: bugsquad => qa-bugs

Comment 2 Thomas Andrews 2020-03-10 19:43:23 CET
AMD Phenom II X4 910, 8GB RAM, Radeon HD 8490 graphics, Atheros wifi, 64-bit Plasma system.

The following 5 packages are going to be installed:

- firefox-68.6.0-1.mga7.x86_64
- firefox-en_GB-68.6.0-1.mga7.noarch
- firefox-en_US-68.6.0-1.mga7.noarch
- lib64nss3-3.51.0-1.mga7.x86_64
- nss-3.51.0-1.mga7.x86_64

Packages installed cleanly. ran Firefox, tried several websites, including one that uses flash in a radar loop. Played a Youtube video, browsed eBay, watched local weather forecast video.

Everything looks good here.

CC: (none) => andrewsfarm

Comment 3 Jose Manuel López 2020-03-10 20:20:53 CET
Hi,

Packages installed cleanly. Firefox works fine, all complements works, no problems in Asus I7, 12 Gb ram and Intel Graphics with Nvidia Optimus and Mageia 7.1 Plasma updated.

Greetings!!

CC: (none) => joselp

Comment 4 Morgan Leijström 2020-03-10 23:25:07 CET
64 bit i7, nvidia, plasma

- firefox-68.6.0-1.mga7.x86_64
- firefox-sv_SE-68.6.0-1.mga7.noarch
- lib64nss3-3.51.0-1.mga7.x86_64

Settings, history, open tabs, plugins preserved.
Surfed some sites, watched videos,...  All OK.

CC: (none) => fri

Comment 5 Thomas Andrews 2020-03-11 13:42:21 CET
HP Probook 6550b, i3, Intel graphics, 64-bit Plasma system.

Packages installed cleanly. All bookmarks, etc. preserved. Read the morning newspaper, watched a weather forecast, checked in at Facebook. All OK.
Comment 6 Herman Viaene 2020-03-11 20:24:19 CET
MGA7-64 Plasma on Lenovo B50
No installation issues.
Bookmarks, text, pictures, videos all OK.

CC: (none) => herman.viaene

Comment 7 Thomas Andrews 2020-03-11 21:31:14 CET
Dell Inspiron 5100, P4, Radeon RV200 graphics, slow Atheros wifi, 32-bit Xfce system.

Packages installed cleanly, browser works OK, within the limits imposed by the hardware involved.
Comment 8 Thomas Andrews 2020-03-11 21:33:47 CET
I think this can be sent on its way. Validating. Advisory information in Comment 1.

Whiteboard: (none) => MGA7-64-OK MGA7-32-OK
CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Nicolas Salguero 2020-03-13 09:29:40 CET

Blocks: (none) => 26334

Thomas Backlund 2020-03-14 08:35:18 CET

CC: (none) => tmb
Keywords: (none) => advisory

Comment 9 Mageia Robot 2020-03-14 09:36:39 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0141.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 10 David Walser 2020-03-16 13:30:16 CET
RedHat has issued an advisory for this today (March 16):
https://access.redhat.com/errata/RHSA-2020:0820