Bug 27193 - Firefox 68.12
Summary: Firefox 68.12
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 27204
  Show dependency treegraph
 
Reported: 2020-08-25 00:03 CEST by David Walser
Modified: 2020-08-28 17:35 CEST (History)
4 users (show)

See Also:
Source RPM: nspr, firefox
CVE:
Status comment:


Attachments

Description David Walser 2020-08-25 00:03:45 CEST
Mozilla has released Firefox 68.12.0 today (August 24):
https://www.mozilla.org/en-US/firefox/68.12.0/releasenotes/

Release notes are not available yet.

Also out is NSPR 4.28:
https://groups.google.com/g/mozilla.dev.tech.nspr/c/YLamaq1rVco

No new rootcerts or nss 3.52.x.
Comment 1 Aurelien Oudelet 2020-08-25 08:43:14 CEST
Thanks reporting this.

Assigning to all packagers as their no registered maintainer.
CC tv as he did some commits.

CC: (none) => thierry.vignaud
Assignee: bugsquad => pkg-bugs

Comment 3 David Walser 2020-08-26 13:21:13 CEST
RedHat has issued an advisory for this today (August 26):
https://access.redhat.com/errata/RHSA-2020:3556
Nicolas Salguero 2020-08-26 22:00:01 CEST

Blocks: (none) => 27204

Comment 4 David Walser 2020-08-26 22:04:15 CEST
Advisory:
========================

Updated firefox packages fix security vulnerabilities:

By holding a reference to the eval() function from an about:blank window, a
malicious webpage could have gained access to the InstallTrigger object which
would allow them to prompt the user to install an extension. Combined with user
confusion, this could result in an unintended or malicious extension being
installed (CVE-2020-15664).

When aborting an operation, such as a fetch, an abort signal may be deleted
while alerting the objects to be notified. This results in a use-after-free and
we presume that with enough effort it could have been exploited to run
arbitrary code (CVE-2020-15669).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15664
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15669
https://groups.google.com/g/mozilla.dev.tech.nspr/c/YLamaq1rVco
https://www.mozilla.org/en-US/security/advisories/mfsa2020-37/
========================

Updated packages in core/updates_testing:
========================
libnspr4-4.28-1.mga7
libnspr-devel-4.28-1.mga7
firefox-68.12.0-2.mga7
firefox-devel-68.12.0-2.mga7
firefox-af-68.12.0-1.mga7
firefox-an-68.12.0-1.mga7
firefox-ar-68.12.0-1.mga7
firefox-ast-68.12.0-1.mga7
firefox-az-68.12.0-1.mga7
firefox-be-68.12.0-1.mga7
firefox-bg-68.12.0-1.mga7
firefox-bg-68.12.0-1.mga7
firefox-bn-68.12.0-1.mga7
firefox-br-68.12.0-1.mga7
firefox-bs-68.12.0-1.mga7
firefox-ca-68.12.0-1.mga7
firefox-cs-68.12.0-1.mga7
firefox-cy-68.12.0-1.mga7
firefox-da-68.12.0-1.mga7
firefox-de-68.12.0-1.mga7
firefox-el-68.12.0-1.mga7
firefox-en_CA-68.12.0-1.mga7
firefox-en_GB-68.12.0-1.mga7
firefox-en_US-68.12.0-1.mga7
firefox-eo-68.12.0-1.mga7
firefox-es_AR-68.12.0-1.mga7
firefox-es_CL-68.12.0-1.mga7
firefox-es_ES-68.12.0-1.mga7
firefox-es_MX-68.12.0-1.mga7
firefox-et-68.12.0-1.mga7
firefox-eu-68.12.0-1.mga7
firefox-fa-68.12.0-1.mga7
firefox-ff-68.12.0-1.mga7
firefox-fi-68.12.0-1.mga7
firefox-fr-68.12.0-1.mga7
firefox-fy_NL-68.12.0-1.mga7
firefox-ga_IE-68.12.0-1.mga7
firefox-gd-68.12.0-1.mga7
firefox-gl-68.12.0-1.mga7
firefox-gu_IN-68.12.0-1.mga7
firefox-he-68.12.0-1.mga7
firefox-hi_IN-68.12.0-1.mga7
firefox-hr-68.12.0-1.mga7
firefox-hsb-68.12.0-1.mga7
firefox-hu-68.12.0-1.mga7
firefox-hy_AM-68.12.0-1.mga7
firefox-ia-68.12.0-1.mga7
firefox-id-68.12.0-1.mga7
firefox-is-68.12.0-1.mga7
firefox-it-68.12.0-1.mga7
firefox-ja-68.12.0-1.mga7
firefox-ka-68.12.0-1.mga7
firefox-kab-68.12.0-1.mga7
firefox-kk-68.12.0-1.mga7
firefox-km-68.12.0-1.mga7
firefox-kn-68.12.0-1.mga7
firefox-ko-68.12.0-1.mga7
firefox-lij-68.12.0-1.mga7
firefox-lt-68.12.0-1.mga7
firefox-lv-68.12.0-1.mga7
firefox-mk-68.12.0-1.mga7
firefox-mr-68.12.0-1.mga7
firefox-ms-68.12.0-1.mga7
firefox-my-68.12.0-1.mga7
firefox-nb_NO-68.12.0-1.mga7
firefox-nl-68.12.0-1.mga7
firefox-nn_NO-68.12.0-1.mga7
firefox-oc-68.12.0-1.mga7
firefox-pa_IN-68.12.0-1.mga7
firefox-pl-68.12.0-1.mga7
firefox-pt_BR-68.12.0-1.mga7
firefox-pt_PT-68.12.0-1.mga7
firefox-ro-68.12.0-1.mga7
firefox-ru-68.12.0-1.mga7
firefox-si-68.12.0-1.mga7
firefox-sk-68.12.0-1.mga7
firefox-sl-68.12.0-1.mga7
firefox-sq-68.12.0-1.mga7
firefox-sr-68.12.0-1.mga7
firefox-sv_SE-68.12.0-1.mga7
firefox-ta-68.12.0-1.mga7
firefox-te-68.12.0-1.mga7
firefox-th-68.12.0-1.mga7
firefox-tr-68.12.0-1.mga7
firefox-uk-68.12.0-1.mga7
firefox-ur-68.12.0-1.mga7
firefox-uz-68.12.0-1.mga7
firefox-vi-68.12.0-1.mga7
firefox-xh-68.12.0-1.mga7
firefox-zh_CN-68.12.0-1.mga7
firefox-zh_TW-68.12.0-1.mga7

from SRPMS:
nspr-4.28-1.mga7.src.rpm
firefox-68.12.0-2.mga7.src.rpm
firefox-l10n-68.12.0-1.mga7.src.rpm

Blocks: 27204 => (none)
Assignee: pkg-bugs => qa-bugs

David Walser 2020-08-26 22:04:50 CEST

Blocks: (none) => 27204

Comment 5 Len Lawrence 2020-08-26 22:54:25 CEST
mga7, x86_64

Updated firefox, GB and US
Installed development packages.

Restored previous session.  Browsed bookmarks.
Checked CUPS at localhost:631.
Downloaded an rpm file via rpmfind.net.
Logged in to gmail account after looking up password.
Ran local sidereal time clock for Edinburgh - javascript site
Examined local directories and displayed local images in the browser.
Looked at Radio Times schedule listing.
Watched a scifi movie on Youtube fullscreen - sound and video OK, controls work.

All working fine here.

Leaving open for other testers.

CC: (none) => tarazed25

Comment 6 Aurelien Oudelet 2020-08-27 08:28:51 CEST
mga 7 VM (Plasma) on x86_64

Updated Firefox, FR
All seems to work fine, even access Netflix... ($%ù! DRM..., I know... this is silly...).

Should other people with other translations?
Aurelien Oudelet 2020-08-27 14:36:11 CEST

Whiteboard: (none) => MGA7-64-OK

Aurelien Oudelet 2020-08-27 14:59:46 CEST

Keywords: (none) => advisory

Aurelien Oudelet 2020-08-27 16:26:36 CEST

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 7 Mageia Robot 2020-08-27 17:54:05 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0348.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 8 Morgan Leijström 2020-08-28 17:35:00 CEST
(In reply to Aurelien Oudelet from comment #6)
> Should other people with other translations?

At least one non english is absolute minimum IMO.

Len seem to have tested functionality well

Now i tested Swedish OK.
Yes, we could be more people...

CC: (none) => fri


Note You need to log in before you can comment on or make changes to this bug.