Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202012-03 ] Mozilla Firefox: Multiple vulnerabilities
Date: Mon, 07 Dec 2020 00:38:28
Message-Id: 4696ec19-2ae3-b603-9298-60a453b0aa8d@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202012-03
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Mozilla Firefox: Multiple vulnerabilities
9 Date: December 07, 2020
10 Bugs: #755170
11 ID: 202012-03
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Mozilla Firefox, the worst
19 of which could result in the arbitrary execution of code.
20
21 Background
22 ==========
23
24 Mozilla Firefox is a popular open-source web browser from the Mozilla
25 project.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/firefox < 83 >= 78.5.0:0/esr78
34 >= 83
35 2 www-client/firefox-bin < 83 >= 78.5.0:0/esr78
36 >= 83
37 -------------------------------------------------------------------
38 2 affected packages
39
40 Description
41 ===========
42
43 Multiple vulnerabilities have been discovered in Mozilla Firefox.
44 Please review the CVE identifiers referenced below for details.
45
46 Impact
47 ======
48
49 Please review the referenced CVE identifiers for details.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All Mozilla Firefox users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=www-client/firefox-83"
63
64 All Mozilla Firefox binary users should upgrade to the latest version:
65
66 # emerge --sync
67 # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-83"
68
69 All Mozilla Firefox (ESR) users should upgrade to the latest version:
70
71 # emerge --sync
72 # emerge --ask --oneshot -v ">=www-client/firefox-78.5.0:0/esr78"
73
74 All Mozilla Firefox (ESR) binary users should upgrade to the latest
75 version:
76
77 # emerge --sync
78 # emerge --ask --oneshot -v ">=www-client/firefox-bin-78.5.0:0/esr78"
79
80 References
81 ==========
82
83 [ 1 ] Mozilla Foundation Security Advisory 2020-51
84 https://www.mozilla.org/en-US/security/advisories/mfsa2020-51/
85 [ 2 ] CVE-2020-16012
86 https://nvd.nist.gov/vuln/detail/CVE-2020-16012
87 [ 3 ] CVE-2020-26951
88 https://nvd.nist.gov/vuln/detail/CVE-2020-26951
89 [ 4 ] CVE-2020-26953
90 https://nvd.nist.gov/vuln/detail/CVE-2020-26953
91 [ 5 ] CVE-2020-26956
92 https://nvd.nist.gov/vuln/detail/CVE-2020-26956
93 [ 6 ] CVE-2020-26958
94 https://nvd.nist.gov/vuln/detail/CVE-2020-26958
95 [ 7 ] CVE-2020-26959
96 https://nvd.nist.gov/vuln/detail/CVE-2020-26959
97 [ 8 ] CVE-2020-26960
98 https://nvd.nist.gov/vuln/detail/CVE-2020-26960
99 [ 9 ] CVE-2020-26961
100 https://nvd.nist.gov/vuln/detail/CVE-2020-26961
101 [ 10 ] CVE-2020-26965
102 https://nvd.nist.gov/vuln/detail/CVE-2020-26965
103 [ 11 ] CVE-2020-26968
104 https://nvd.nist.gov/vuln/detail/CVE-2020-26968
105 [ 12 ] Mozilla Foundation Security Advisory 2020-50
106 https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/
107
108 Availability
109 ============
110
111 This GLSA and any updates to it are available for viewing at
112 the Gentoo Security Website:
113
114 https://security.gentoo.org/glsa/202012-03
115
116 Concerns?
117 =========
118
119 Security is a primary focus of Gentoo Linux and ensuring the
120 confidentiality and security of our users' machines is of utmost
121 importance to us. Any security concerns should be addressed to
122 security@g.o or alternatively, you may file a bug at
123 https://bugs.gentoo.org.
124
125 License
126 =======
127
128 Copyright 2020 Gentoo Foundation, Inc; referenced text
129 belongs to its owner(s).
130
131 The contents of this document are licensed under the
132 Creative Commons - Attribution / Share Alike license.
133
134 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
OpenPGP_signature.asc application/pgp-signature