Bug 27193

Summary: Firefox 68.12
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: fri, sysadmin-bugs, tarazed25, thierry.vignaud
Version: 7Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA7-64-OK
Source RPM: nspr, firefox CVE:
Status comment:
Bug Depends on:    
Bug Blocks: 27204    

Description David Walser 2020-08-25 00:03:45 CEST
Mozilla has released Firefox 68.12.0 today (August 24):
https://www.mozilla.org/en-US/firefox/68.12.0/releasenotes/

Release notes are not available yet.

Also out is NSPR 4.28:
https://groups.google.com/g/mozilla.dev.tech.nspr/c/YLamaq1rVco

No new rootcerts or nss 3.52.x.
Comment 1 Aurelien Oudelet 2020-08-25 08:43:14 CEST
Thanks reporting this.

Assigning to all packagers as their no registered maintainer.
CC tv as he did some commits.

CC: (none) => thierry.vignaud
Assignee: bugsquad => pkg-bugs

Comment 3 David Walser 2020-08-26 13:21:13 CEST
RedHat has issued an advisory for this today (August 26):
https://access.redhat.com/errata/RHSA-2020:3556
Nicolas Salguero 2020-08-26 22:00:01 CEST

Blocks: (none) => 27204

Comment 4 David Walser 2020-08-26 22:04:15 CEST
Advisory:
========================

Updated firefox packages fix security vulnerabilities:

By holding a reference to the eval() function from an about:blank window, a
malicious webpage could have gained access to the InstallTrigger object which
would allow them to prompt the user to install an extension. Combined with user
confusion, this could result in an unintended or malicious extension being
installed (CVE-2020-15664).

When aborting an operation, such as a fetch, an abort signal may be deleted
while alerting the objects to be notified. This results in a use-after-free and
we presume that with enough effort it could have been exploited to run
arbitrary code (CVE-2020-15669).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15664
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15669
https://groups.google.com/g/mozilla.dev.tech.nspr/c/YLamaq1rVco
https://www.mozilla.org/en-US/security/advisories/mfsa2020-37/
========================

Updated packages in core/updates_testing:
========================
libnspr4-4.28-1.mga7
libnspr-devel-4.28-1.mga7
firefox-68.12.0-2.mga7
firefox-devel-68.12.0-2.mga7
firefox-af-68.12.0-1.mga7
firefox-an-68.12.0-1.mga7
firefox-ar-68.12.0-1.mga7
firefox-ast-68.12.0-1.mga7
firefox-az-68.12.0-1.mga7
firefox-be-68.12.0-1.mga7
firefox-bg-68.12.0-1.mga7
firefox-bg-68.12.0-1.mga7
firefox-bn-68.12.0-1.mga7
firefox-br-68.12.0-1.mga7
firefox-bs-68.12.0-1.mga7
firefox-ca-68.12.0-1.mga7
firefox-cs-68.12.0-1.mga7
firefox-cy-68.12.0-1.mga7
firefox-da-68.12.0-1.mga7
firefox-de-68.12.0-1.mga7
firefox-el-68.12.0-1.mga7
firefox-en_CA-68.12.0-1.mga7
firefox-en_GB-68.12.0-1.mga7
firefox-en_US-68.12.0-1.mga7
firefox-eo-68.12.0-1.mga7
firefox-es_AR-68.12.0-1.mga7
firefox-es_CL-68.12.0-1.mga7
firefox-es_ES-68.12.0-1.mga7
firefox-es_MX-68.12.0-1.mga7
firefox-et-68.12.0-1.mga7
firefox-eu-68.12.0-1.mga7
firefox-fa-68.12.0-1.mga7
firefox-ff-68.12.0-1.mga7
firefox-fi-68.12.0-1.mga7
firefox-fr-68.12.0-1.mga7
firefox-fy_NL-68.12.0-1.mga7
firefox-ga_IE-68.12.0-1.mga7
firefox-gd-68.12.0-1.mga7
firefox-gl-68.12.0-1.mga7
firefox-gu_IN-68.12.0-1.mga7
firefox-he-68.12.0-1.mga7
firefox-hi_IN-68.12.0-1.mga7
firefox-hr-68.12.0-1.mga7
firefox-hsb-68.12.0-1.mga7
firefox-hu-68.12.0-1.mga7
firefox-hy_AM-68.12.0-1.mga7
firefox-ia-68.12.0-1.mga7
firefox-id-68.12.0-1.mga7
firefox-is-68.12.0-1.mga7
firefox-it-68.12.0-1.mga7
firefox-ja-68.12.0-1.mga7
firefox-ka-68.12.0-1.mga7
firefox-kab-68.12.0-1.mga7
firefox-kk-68.12.0-1.mga7
firefox-km-68.12.0-1.mga7
firefox-kn-68.12.0-1.mga7
firefox-ko-68.12.0-1.mga7
firefox-lij-68.12.0-1.mga7
firefox-lt-68.12.0-1.mga7
firefox-lv-68.12.0-1.mga7
firefox-mk-68.12.0-1.mga7
firefox-mr-68.12.0-1.mga7
firefox-ms-68.12.0-1.mga7
firefox-my-68.12.0-1.mga7
firefox-nb_NO-68.12.0-1.mga7
firefox-nl-68.12.0-1.mga7
firefox-nn_NO-68.12.0-1.mga7
firefox-oc-68.12.0-1.mga7
firefox-pa_IN-68.12.0-1.mga7
firefox-pl-68.12.0-1.mga7
firefox-pt_BR-68.12.0-1.mga7
firefox-pt_PT-68.12.0-1.mga7
firefox-ro-68.12.0-1.mga7
firefox-ru-68.12.0-1.mga7
firefox-si-68.12.0-1.mga7
firefox-sk-68.12.0-1.mga7
firefox-sl-68.12.0-1.mga7
firefox-sq-68.12.0-1.mga7
firefox-sr-68.12.0-1.mga7
firefox-sv_SE-68.12.0-1.mga7
firefox-ta-68.12.0-1.mga7
firefox-te-68.12.0-1.mga7
firefox-th-68.12.0-1.mga7
firefox-tr-68.12.0-1.mga7
firefox-uk-68.12.0-1.mga7
firefox-ur-68.12.0-1.mga7
firefox-uz-68.12.0-1.mga7
firefox-vi-68.12.0-1.mga7
firefox-xh-68.12.0-1.mga7
firefox-zh_CN-68.12.0-1.mga7
firefox-zh_TW-68.12.0-1.mga7

from SRPMS:
nspr-4.28-1.mga7.src.rpm
firefox-68.12.0-2.mga7.src.rpm
firefox-l10n-68.12.0-1.mga7.src.rpm

Blocks: 27204 => (none)
Assignee: pkg-bugs => qa-bugs

David Walser 2020-08-26 22:04:50 CEST

Blocks: (none) => 27204

Comment 5 Len Lawrence 2020-08-26 22:54:25 CEST
mga7, x86_64

Updated firefox, GB and US
Installed development packages.

Restored previous session.  Browsed bookmarks.
Checked CUPS at localhost:631.
Downloaded an rpm file via rpmfind.net.
Logged in to gmail account after looking up password.
Ran local sidereal time clock for Edinburgh - javascript site
Examined local directories and displayed local images in the browser.
Looked at Radio Times schedule listing.
Watched a scifi movie on Youtube fullscreen - sound and video OK, controls work.

All working fine here.

Leaving open for other testers.

CC: (none) => tarazed25

Comment 6 Aurelien Oudelet 2020-08-27 08:28:51 CEST
mga 7 VM (Plasma) on x86_64

Updated Firefox, FR
All seems to work fine, even access Netflix... ($%ù! DRM..., I know... this is silly...).

Should other people with other translations?
Aurelien Oudelet 2020-08-27 14:36:11 CEST

Whiteboard: (none) => MGA7-64-OK

Aurelien Oudelet 2020-08-27 14:59:46 CEST

Keywords: (none) => advisory

Aurelien Oudelet 2020-08-27 16:26:36 CEST

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 7 Mageia Robot 2020-08-27 17:54:05 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0348.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 8 Morgan Leijström 2020-08-28 17:35:00 CEST
(In reply to Aurelien Oudelet from comment #6)
> Should other people with other translations?

At least one non english is absolute minimum IMO.

Len seem to have tested functionality well

Now i tested Swedish OK.
Yes, we could be more people...

CC: (none) => fri