| Summary: | Firefox 78.11 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, fri, guillaume.royer, joselp, ouaurelien, sysadmin-bugs |
| Version: | 8 | Keywords: | IN_ERRATA8, advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7TOO MGA7-64-OK MGA8-64-OK | ||
| Source RPM: | nspr, rootcerts, nss, firefox | CVE: | CVE-2021-29967 |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 28788, 29073 | ||
|
Description
David Walser
2021-06-01 00:01:23 CEST
David Walser
2021-06-01 00:01:31 CEST
Whiteboard:
(none) =>
MGA7TOO Still need java-1.8.0-openjdk removed from Mageia 7 core/updates_testing and rootcerts built there, so it's not actually available yet, but everything else is, so people can start testing if they want. Updated packages in core/updates_testing: ======================================== libnspr4-4.31-1.mga7 libnspr-devel-4.31-1.mga7 rootcerts-20210525.00-1.mga7 rootcerts-java-20210525.00-1.mga7 nss-3.66.0-1.mga7 nss-doc-3.66.0-1.mga7 libnss3-3.66.0-1.mga7 libnss-devel-3.66.0-1.mga7 libnss-static-devel-3.66.0-1.mga7 firefox-78.11.0-1.mga7 firefox-devel-78.11.0-1.mga7 firefox-af-78.11.0-1.mga7 firefox-an-78.11.0-1.mga7 firefox-ar-78.11.0-1.mga7 firefox-ast-78.11.0-1.mga7 firefox-az-78.11.0-1.mga7 firefox-be-78.11.0-1.mga7 firefox-bg-78.11.0-1.mga7 firefox-bn-78.11.0-1.mga7 firefox-br-78.11.0-1.mga7 firefox-bs-78.11.0-1.mga7 firefox-ca-78.11.0-1.mga7 firefox-cs-78.11.0-1.mga7 firefox-cy-78.11.0-1.mga7 firefox-da-78.11.0-1.mga7 firefox-de-78.11.0-1.mga7 firefox-el-78.11.0-1.mga7 firefox-en_CA-78.11.0-1.mga7 firefox-en_GB-78.11.0-1.mga7 firefox-en_US-78.11.0-1.mga7 firefox-eo-78.11.0-1.mga7 firefox-es_AR-78.11.0-1.mga7 firefox-es_CL-78.11.0-1.mga7 firefox-es_ES-78.11.0-1.mga7 firefox-es_MX-78.11.0-1.mga7 firefox-et-78.11.0-1.mga7 firefox-eu-78.11.0-1.mga7 firefox-fa-78.11.0-1.mga7 firefox-ff-78.11.0-1.mga7 firefox-fi-78.11.0-1.mga7 firefox-fr-78.11.0-1.mga7 firefox-fy_NL-78.11.0-1.mga7 firefox-ga_IE-78.11.0-1.mga7 firefox-gd-78.11.0-1.mga7 firefox-gl-78.11.0-1.mga7 firefox-gu_IN-78.11.0-1.mga7 firefox-he-78.11.0-1.mga7 firefox-hi_IN-78.11.0-1.mga7 firefox-hr-78.11.0-1.mga7 firefox-hsb-78.11.0-1.mga7 firefox-hu-78.11.0-1.mga7 firefox-hy_AM-78.11.0-1.mga7 firefox-ia-78.11.0-1.mga7 firefox-id-78.11.0-1.mga7 firefox-is-78.11.0-1.mga7 firefox-it-78.11.0-1.mga7 firefox-ja-78.11.0-1.mga7 firefox-ka-78.11.0-1.mga7 firefox-kab-78.11.0-1.mga7 firefox-kk-78.11.0-1.mga7 firefox-km-78.11.0-1.mga7 firefox-kn-78.11.0-1.mga7 firefox-ko-78.11.0-1.mga7 firefox-lij-78.11.0-1.mga7 firefox-lt-78.11.0-1.mga7 firefox-lv-78.11.0-1.mga7 firefox-mk-78.11.0-1.mga7 firefox-mr-78.11.0-1.mga7 firefox-ms-78.11.0-1.mga7 firefox-my-78.11.0-1.mga7 firefox-nb_NO-78.11.0-1.mga7 firefox-nl-78.11.0-1.mga7 firefox-nn_NO-78.11.0-1.mga7 firefox-oc-78.11.0-1.mga7 firefox-pa_IN-78.11.0-1.mga7 firefox-pl-78.11.0-1.mga7 firefox-pt_BR-78.11.0-1.mga7 firefox-pt_PT-78.11.0-1.mga7 firefox-ro-78.11.0-1.mga7 firefox-ru-78.11.0-1.mga7 firefox-si-78.11.0-1.mga7 firefox-sk-78.11.0-1.mga7 firefox-sl-78.11.0-1.mga7 firefox-sq-78.11.0-1.mga7 firefox-sr-78.11.0-1.mga7 firefox-sv_SE-78.11.0-1.mga7 firefox-ta-78.11.0-1.mga7 firefox-te-78.11.0-1.mga7 firefox-th-78.11.0-1.mga7 firefox-tl-78.11.0-1.mga7 firefox-tr-78.11.0-1.mga7 firefox-uk-78.11.0-1.mga7 firefox-ur-78.11.0-1.mga7 firefox-uz-78.11.0-1.mga7 firefox-vi-78.11.0-1.mga7 firefox-xh-78.11.0-1.mga7 firefox-zh_CN-78.11.0-1.mga7 firefox-zh_TW-78.11.0-1.mga7 libnspr4-4.31-1.mga8 libnspr-devel-4.31-1.mga8 rootcerts-20210525.00-1.mga8 rootcerts-java-20210525.00-1.mga8 nss-3.66.0-1.mga8 nss-doc-3.66.0-1.mga8 libnss3-3.66.0-1.mga8 libnss-devel-3.66.0-1.mga8 libnss-static-devel-3.66.0-1.mga8 firefox-78.11.0-1.mga8 firefox-devel-78.11.0-1.mga8 firefox-af-78.11.0-1.mga8 firefox-an-78.11.0-1.mga8 firefox-ar-78.11.0-1.mga8 firefox-ast-78.11.0-1.mga8 firefox-az-78.11.0-1.mga8 firefox-be-78.11.0-1.mga8 firefox-bg-78.11.0-1.mga8 firefox-bn-78.11.0-1.mga8 firefox-br-78.11.0-1.mga8 firefox-bs-78.11.0-1.mga8 firefox-ca-78.11.0-1.mga8 firefox-cs-78.11.0-1.mga8 firefox-cy-78.11.0-1.mga8 firefox-da-78.11.0-1.mga8 firefox-de-78.11.0-1.mga8 firefox-el-78.11.0-1.mga8 firefox-en_CA-78.11.0-1.mga8 firefox-en_GB-78.11.0-1.mga8 firefox-en_US-78.11.0-1.mga8 firefox-eo-78.11.0-1.mga8 firefox-es_AR-78.11.0-1.mga8 firefox-es_CL-78.11.0-1.mga8 firefox-es_ES-78.11.0-1.mga8 firefox-es_MX-78.11.0-1.mga8 firefox-et-78.11.0-1.mga8 firefox-eu-78.11.0-1.mga8 firefox-fa-78.11.0-1.mga8 firefox-ff-78.11.0-1.mga8 firefox-fi-78.11.0-1.mga8 firefox-fr-78.11.0-1.mga8 firefox-fy_NL-78.11.0-1.mga8 firefox-ga_IE-78.11.0-1.mga8 firefox-gd-78.11.0-1.mga8 firefox-gl-78.11.0-1.mga8 firefox-gu_IN-78.11.0-1.mga8 firefox-he-78.11.0-1.mga8 firefox-hi_IN-78.11.0-1.mga8 firefox-hr-78.11.0-1.mga8 firefox-hsb-78.11.0-1.mga8 firefox-hu-78.11.0-1.mga8 firefox-hy_AM-78.11.0-1.mga8 firefox-ia-78.11.0-1.mga8 firefox-id-78.11.0-1.mga8 firefox-is-78.11.0-1.mga8 firefox-it-78.11.0-1.mga8 firefox-ja-78.11.0-1.mga8 firefox-ka-78.11.0-1.mga8 firefox-kab-78.11.0-1.mga8 firefox-kk-78.11.0-1.mga8 firefox-km-78.11.0-1.mga8 firefox-kn-78.11.0-1.mga8 firefox-ko-78.11.0-1.mga8 firefox-lij-78.11.0-1.mga8 firefox-lt-78.11.0-1.mga8 firefox-lv-78.11.0-1.mga8 firefox-mk-78.11.0-1.mga8 firefox-mr-78.11.0-1.mga8 firefox-ms-78.11.0-1.mga8 firefox-my-78.11.0-1.mga8 firefox-nb_NO-78.11.0-1.mga8 firefox-nl-78.11.0-1.mga8 firefox-nn_NO-78.11.0-1.mga8 firefox-oc-78.11.0-1.mga8 firefox-pa_IN-78.11.0-1.mga8 firefox-pl-78.11.0-1.mga8 firefox-pt_BR-78.11.0-1.mga8 firefox-pt_PT-78.11.0-1.mga8 firefox-ro-78.11.0-1.mga8 firefox-ru-78.11.0-1.mga8 firefox-si-78.11.0-1.mga8 firefox-sk-78.11.0-1.mga8 firefox-sl-78.11.0-1.mga8 firefox-sq-78.11.0-1.mga8 firefox-sr-78.11.0-1.mga8 firefox-sv_SE-78.11.0-1.mga8 firefox-ta-78.11.0-1.mga8 firefox-te-78.11.0-1.mga8 firefox-th-78.11.0-1.mga8 firefox-tl-78.11.0-1.mga8 firefox-tr-78.11.0-1.mga8 firefox-uk-78.11.0-1.mga8 firefox-ur-78.11.0-1.mga8 firefox-uz-78.11.0-1.mga8 firefox-vi-78.11.0-1.mga8 firefox-xh-78.11.0-1.mga8 firefox-zh_CN-78.11.0-1.mga8 firefox-zh_TW-78.11.0-1.mga8 from SRPMS: nspr-4.31-1.mga7.src.rpm rootcerts-20210525.00-1.mga7.src.rpm nss-3.66.0-1.mga7.src.rpm firefox-78.11.0-1.mga7.src.rpm firefox-l10n-78.11.0-1.mga7.src.rpm nspr-4.31-1.mga8.src.rpm rootcerts-20210525.00-1.mga8.src.rpm nss-3.66.0-1.mga8.src.rpm firefox-78.11.0-1.mga8.src.rpm firefox-l10n-78.11.0-1.mga8.src.rpm CC:
(none) =>
mageia, qa-bugs, sysadmin-bugs It installed in Mageia 8, works fine, now the bank websites open correctly and all test that I have been is ok. Good work!! Greetings! CC:
(none) =>
joselp
Aurelien Oudelet
2021-06-01 17:02:47 CEST
Blocks:
(none) =>
27374
Aurelien Oudelet
2021-06-01 17:06:06 CEST
Blocks:
(none) =>
28359 Suggested advisory: ======================== Updated firefox, nss, nspr and rootcerts packages fix a security vulnerability: Memory safety bugs fixed in Firefox 89 and Firefox ESR 78.11 Mozilla developers Gabriele Svelto, Anny Gakhokidze, Alexandru Michis, Christian Holler reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. (CVE-2021-29967). Note that CVE-2021-29964: Out of bounds-read when parsing a `WM_COPYDATA` message A locally-installed hostile program could send WM_COPYDATA messages that Firefox would processing incorrectly, leading to an out-of-bounds read. This bug only affects Firefox on Windows. Other operating systems are unaffected (CVE-2021-29964), we will not include this in our advisory. This update also fixes: - Unable to connect to Element with the firefox ESR packaged by Mageia (Bug 28755). - Crashes on certain webpages with our packaged version (Bug 28652). - Some connections to websites like Santander Bank (Bug 28359). - Neither audio nor video with BigBlueButton and other WebRTC services with our packaged version of Firefox ESR (Bug 27374). It seems a previous patch was still applied and prevents such functionalities to work. Thanks Martin Whitaker for 28755, 28359, 27374 and Neal Gompa for 28652. References: - https://bugs.mageia.org/show_bug.cgi?id=29064 - https://bugs.mageia.org/show_bug.cgi?id=28755 - https://bugs.mageia.org/show_bug.cgi?id=28652 - https://bugs.mageia.org/show_bug.cgi?id=28359 - https://bugs.mageia.org/show_bug.cgi?id=27374 - https://www.mozilla.org/en-US/firefox/78.11.0/releasenotes/ - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/4eyMP8SrUGk - https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.65_release_notes - https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.66_release_notes ======================== Updated packages in 8/core/updates_testing: ======================== libnspr4-4.31-1.mga8 libnspr-devel-4.31-1.mga8 rootcerts-20210525.00-1.mga8 rootcerts-java-20210525.00-1.mga8 nss-3.66.0-1.mga8 nss-doc-3.66.0-1.mga8 libnss3-3.66.0-1.mga8 libnss-devel-3.66.0-1.mga8 libnss-static-devel-3.66.0-1.mga8 firefox-78.11.0-1.mga8 firefox-devel-78.11.0-1.mga8 firefox-af-78.11.0-1.mga8 firefox-an-78.11.0-1.mga8 firefox-ar-78.11.0-1.mga8 firefox-ast-78.11.0-1.mga8 firefox-az-78.11.0-1.mga8 firefox-be-78.11.0-1.mga8 firefox-bg-78.11.0-1.mga8 firefox-bn-78.11.0-1.mga8 firefox-br-78.11.0-1.mga8 firefox-bs-78.11.0-1.mga8 firefox-ca-78.11.0-1.mga8 firefox-cs-78.11.0-1.mga8 firefox-cy-78.11.0-1.mga8 firefox-da-78.11.0-1.mga8 firefox-de-78.11.0-1.mga8 firefox-el-78.11.0-1.mga8 firefox-en_CA-78.11.0-1.mga8 firefox-en_GB-78.11.0-1.mga8 firefox-en_US-78.11.0-1.mga8 firefox-eo-78.11.0-1.mga8 firefox-es_AR-78.11.0-1.mga8 firefox-es_CL-78.11.0-1.mga8 firefox-es_ES-78.11.0-1.mga8 firefox-es_MX-78.11.0-1.mga8 firefox-et-78.11.0-1.mga8 firefox-eu-78.11.0-1.mga8 firefox-fa-78.11.0-1.mga8 firefox-ff-78.11.0-1.mga8 firefox-fi-78.11.0-1.mga8 firefox-fr-78.11.0-1.mga8 firefox-fy_NL-78.11.0-1.mga8 firefox-ga_IE-78.11.0-1.mga8 firefox-gd-78.11.0-1.mga8 firefox-gl-78.11.0-1.mga8 firefox-gu_IN-78.11.0-1.mga8 firefox-he-78.11.0-1.mga8 firefox-hi_IN-78.11.0-1.mga8 firefox-hr-78.11.0-1.mga8 firefox-hsb-78.11.0-1.mga8 firefox-hu-78.11.0-1.mga8 firefox-hy_AM-78.11.0-1.mga8 firefox-ia-78.11.0-1.mga8 firefox-id-78.11.0-1.mga8 firefox-is-78.11.0-1.mga8 firefox-it-78.11.0-1.mga8 firefox-ja-78.11.0-1.mga8 firefox-ka-78.11.0-1.mga8 firefox-kab-78.11.0-1.mga8 firefox-kk-78.11.0-1.mga8 firefox-km-78.11.0-1.mga8 firefox-kn-78.11.0-1.mga8 firefox-ko-78.11.0-1.mga8 firefox-lij-78.11.0-1.mga8 firefox-lt-78.11.0-1.mga8 firefox-lv-78.11.0-1.mga8 firefox-mk-78.11.0-1.mga8 firefox-mr-78.11.0-1.mga8 firefox-ms-78.11.0-1.mga8 firefox-my-78.11.0-1.mga8 firefox-nb_NO-78.11.0-1.mga8 firefox-nl-78.11.0-1.mga8 firefox-nn_NO-78.11.0-1.mga8 firefox-oc-78.11.0-1.mga8 firefox-pa_IN-78.11.0-1.mga8 firefox-pl-78.11.0-1.mga8 firefox-pt_BR-78.11.0-1.mga8 firefox-pt_PT-78.11.0-1.mga8 firefox-ro-78.11.0-1.mga8 firefox-ru-78.11.0-1.mga8 firefox-si-78.11.0-1.mga8 firefox-sk-78.11.0-1.mga8 firefox-sl-78.11.0-1.mga8 firefox-sq-78.11.0-1.mga8 firefox-sr-78.11.0-1.mga8 firefox-sv_SE-78.11.0-1.mga8 firefox-ta-78.11.0-1.mga8 firefox-te-78.11.0-1.mga8 firefox-th-78.11.0-1.mga8 firefox-tl-78.11.0-1.mga8 firefox-tr-78.11.0-1.mga8 firefox-uk-78.11.0-1.mga8 firefox-ur-78.11.0-1.mga8 firefox-uz-78.11.0-1.mga8 firefox-vi-78.11.0-1.mga8 firefox-xh-78.11.0-1.mga8 firefox-zh_CN-78.11.0-1.mga8 firefox-zh_TW-78.11.0-1.mga8 from SRPM: nspr-4.31-1.mga8.src.rpm rootcerts-20210525.00-1.mga8.src.rpm nss-3.66.0-1.mga8.src.rpm firefox-78.11.0-1.mga8.src.rpm firefox-l10n-78.11.0-1.mga8.src.rpm ======================== Updated packages in 7/core/updates_testing: ======================================== libnspr4-4.31-1.mga7 libnspr-devel-4.31-1.mga7 rootcerts-20210525.00-1.mga7 rootcerts-java-20210525.00-1.mga7 nss-3.66.0-1.mga7 nss-doc-3.66.0-1.mga7 libnss3-3.66.0-1.mga7 libnss-devel-3.66.0-1.mga7 libnss-static-devel-3.66.0-1.mga7 firefox-78.11.0-1.mga7 firefox-devel-78.11.0-1.mga7 firefox-af-78.11.0-1.mga7 firefox-an-78.11.0-1.mga7 firefox-ar-78.11.0-1.mga7 firefox-ast-78.11.0-1.mga7 firefox-az-78.11.0-1.mga7 firefox-be-78.11.0-1.mga7 firefox-bg-78.11.0-1.mga7 firefox-bn-78.11.0-1.mga7 firefox-br-78.11.0-1.mga7 firefox-bs-78.11.0-1.mga7 firefox-ca-78.11.0-1.mga7 firefox-cs-78.11.0-1.mga7 firefox-cy-78.11.0-1.mga7 firefox-da-78.11.0-1.mga7 firefox-de-78.11.0-1.mga7 firefox-el-78.11.0-1.mga7 firefox-en_CA-78.11.0-1.mga7 firefox-en_GB-78.11.0-1.mga7 firefox-en_US-78.11.0-1.mga7 firefox-eo-78.11.0-1.mga7 firefox-es_AR-78.11.0-1.mga7 firefox-es_CL-78.11.0-1.mga7 firefox-es_ES-78.11.0-1.mga7 firefox-es_MX-78.11.0-1.mga7 firefox-et-78.11.0-1.mga7 firefox-eu-78.11.0-1.mga7 firefox-fa-78.11.0-1.mga7 firefox-ff-78.11.0-1.mga7 firefox-fi-78.11.0-1.mga7 firefox-fr-78.11.0-1.mga7 firefox-fy_NL-78.11.0-1.mga7 firefox-ga_IE-78.11.0-1.mga7 firefox-gd-78.11.0-1.mga7 firefox-gl-78.11.0-1.mga7 firefox-gu_IN-78.11.0-1.mga7 firefox-he-78.11.0-1.mga7 firefox-hi_IN-78.11.0-1.mga7 firefox-hr-78.11.0-1.mga7 firefox-hsb-78.11.0-1.mga7 firefox-hu-78.11.0-1.mga7 firefox-hy_AM-78.11.0-1.mga7 firefox-ia-78.11.0-1.mga7 firefox-id-78.11.0-1.mga7 firefox-is-78.11.0-1.mga7 firefox-it-78.11.0-1.mga7 firefox-ja-78.11.0-1.mga7 firefox-ka-78.11.0-1.mga7 firefox-kab-78.11.0-1.mga7 firefox-kk-78.11.0-1.mga7 firefox-km-78.11.0-1.mga7 firefox-kn-78.11.0-1.mga7 firefox-ko-78.11.0-1.mga7 firefox-lij-78.11.0-1.mga7 firefox-lt-78.11.0-1.mga7 firefox-lv-78.11.0-1.mga7 firefox-mk-78.11.0-1.mga7 firefox-mr-78.11.0-1.mga7 firefox-ms-78.11.0-1.mga7 firefox-my-78.11.0-1.mga7 firefox-nb_NO-78.11.0-1.mga7 firefox-nl-78.11.0-1.mga7 firefox-nn_NO-78.11.0-1.mga7 firefox-oc-78.11.0-1.mga7 firefox-pa_IN-78.11.0-1.mga7 firefox-pl-78.11.0-1.mga7 firefox-pt_BR-78.11.0-1.mga7 firefox-pt_PT-78.11.0-1.mga7 firefox-ro-78.11.0-1.mga7 firefox-ru-78.11.0-1.mga7 firefox-si-78.11.0-1.mga7 firefox-sk-78.11.0-1.mga7 firefox-sl-78.11.0-1.mga7 firefox-sq-78.11.0-1.mga7 firefox-sr-78.11.0-1.mga7 firefox-sv_SE-78.11.0-1.mga7 firefox-ta-78.11.0-1.mga7 firefox-te-78.11.0-1.mga7 firefox-th-78.11.0-1.mga7 firefox-tl-78.11.0-1.mga7 firefox-tr-78.11.0-1.mga7 firefox-uk-78.11.0-1.mga7 firefox-ur-78.11.0-1.mga7 firefox-uz-78.11.0-1.mga7 firefox-vi-78.11.0-1.mga7 firefox-xh-78.11.0-1.mga7 firefox-zh_CN-78.11.0-1.mga7 firefox-zh_TW-78.11.0-1.mga7 from SRPMS: nspr-4.31-1.mga7.src.rpm rootcerts-20210525.00-1.mga7.src.rpm nss-3.66.0-1.mga7.src.rpm firefox-78.11.0-1.mga7.src.rpm firefox-l10n-78.11.0-1.mga7.src.rpm ======================== CC:
(none) =>
ouaurelien $ inxi -Sxx System: Host: mageia.local Kernel: 5.10.41-desktop-1.mga8 x86_64 bits: 64 compiler: gcc v: 10.3.0 Desktop: KDE Plasma 5.20.4 tk: Qt 5.15.2 wm: kwin_x11 dm: SDDM Distro: Mageia 8 mga8 Using QARepo: - firefox-78.11.0-1.mga8.x86_64 - firefox-fr-78.11.0-1.mga8.noarch - lib64mozjs78-78.11.0-1.mga8.x86_64 (unrelated but worthy here.) - lib64nspr4-4.31-1.mga8.x86_64 - lib64nss3-3.66.0-1.mga8.x86_64 - nss-3.66.0-1.mga8.x86_64 - rootcerts-20210525.00-1.mga8.noarch - rootcerts-java-20210525.00-1.mga8.noarch Installs OK. Bug 28755 Correctly fixed. Bug 27374 Correctly fixed. Can't see other bug. Basic usage is OK. Widevine DRM sites OK. My bank is OK. MGA8-64-OK (In reply to David Walser from comment #1) > Still need java-1.8.0-openjdk removed from Mageia 7 core/updates_testing and > rootcerts built there... java removed and rootcerts is built
David Walser
2021-06-02 17:37:15 CEST
CC:
mageia, qa-bugs, sysadmin-bugs =>
(none) Minor advisory notes: - only the firefox package fixes security issues, that we know of, so only it needs to be in the title - advisory should not mention CVE-2021-29964, as it only affects Windows - make sure to also include 78.10.1 release notes in the references as there was a bug fix there that we missed (In reply to David Walser from comment #6) > Minor advisory notes: > - only the firefox package fixes security issues, that we know of, so only > it needs to be in the title > - advisory should not mention CVE-2021-29964, as it only affects Windows > - make sure to also include 78.10.1 release notes in the references as there > was a bug fix there that we missed Will do these. Been using this in Mageia 8 for a couple of days now, with no issues noted, other than those inherent with some web sites and the ESR version. Works as designed. CC:
(none) =>
andrewsfarm RedHat has issued an advisory for this on June 2: https://access.redhat.com/errata/RHSA-2021:2206 MGA8 XFCE Updated with QA Repo tool: - firefox-78.11.0-1.mga8.x86_64 - firefox-fr-78.11.0-1.mga8.noarch - lib64mozjs78-78.11.0-1.mga8.x86_64 (unrelated but worthy here.) - lib64nspr4-4.31-1.mga8.x86_64 - lib64nss3-3.66.0-1.mga8.x86_64 - nss-3.66.0-1.mga8.x86_64 - rootcerts-20210525.00-1.mga8.noarch - rootcerts-java-20210525.00-1.mga8.noarch Tested with my bank, Widvine (Netflix) ok Good News Matrix client web Element works now! BBB server test is Ok I can't test other visio conf systems CC:
(none) =>
guillaume.royer
Nicolas Salguero
2021-06-04 09:24:10 CEST
Blocks:
(none) =>
29073 MGA8-64bit I spent a day with it on my laptop. No issues encountered. CC:
(none) =>
brtians1 OK mga8-64, Plasma, Swedish, 4k screen, nvidia driver Been using it today: Browsing and log in to various sites I often use, no regression. I had no problem before except one site that still complain over version. CC:
(none) =>
fri MGA87 VM LXQt Updated with QA Repo tool: Tested with my bank, Widvine (Netflix) ok Matrix client web Element ok BBB server test is Ok (In reply to Guillaume Royer from comment #13) > MGA87 VM LXQt > > Updated with QA Repo tool: > > Tested with my bank, Widvine (Netflix) ok > Matrix client web Element ok > BBB server test is Ok You have to read MGA7 VM LXQt sorry for typin error... @Guillaume: 32 or 64 bit? Sames tests / MGA8 and MGA7 Plasma x86-64. MGA7-64-OK Validating. Advisory. (In reply to David Walser from comment #6) > Minor advisory notes: > - only the firefox package fixes security issues, that we know of, so only > it needs to be in the title > - advisory should not mention CVE-2021-29964, as it only affects Windows > - make sure to also include 78.10.1 release notes in the references as there > was a bug fix there that we missed Done. CC:
(none) =>
sysadmin-bugs An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0236.html Resolution:
(none) =>
FIXED https://wiki.mageia.org/en/Mageia_8_Errata#Firefox_ESR Keywords:
(none) =>
IN_ERRATA8 |