Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202012-20 ] Mozilla Firefox, Mozilla Thunderbird: Multiple vulnerabilities
Date: Wed, 23 Dec 2020 20:34:59
Message-Id: 6957f7e3-4cba-31b5-6d92-67f1931e7162@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202012-20
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Mozilla Firefox, Mozilla Thunderbird: Multiple
9 vulnerabilities
10 Date: December 23, 2020
11 Bugs: #759097
12 ID: 202012-20
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 Multiple vulnerabilities have been found in Mozilla Firefox and Mozilla
20 Thunderbird, the worst of which could result in the arbitrary execution
21 of code.
22
23 Background
24 ==========
25
26 Mozilla Firefox is a popular open-source web browser from the Mozilla
27 project.
28
29 Mozilla Thunderbird is a popular open-source email client from the
30 Mozilla project.
31
32 Affected packages
33 =================
34
35 -------------------------------------------------------------------
36 Package / Vulnerable / Unaffected
37 -------------------------------------------------------------------
38 1 www-client/firefox < 84.0 >= 78.6.0:0/esr78
39 >= 84.0
40 2 www-client/firefox-bin < 84.0 >= 78.6.0:0/esr78
41 >= 84.0
42 3 mail-client/thunderbird < 78.6.0 >= 78.6.0
43 4 mail-client/thunderbird-bin
44 < 78.6.0 >= 78.6.0
45 -------------------------------------------------------------------
46 4 affected packages
47
48 Description
49 ===========
50
51 Multiple vulnerabilities have been discovered in Mozilla Firefox and
52 Mozilla Thunderbird. Please review the CVE identifiers referenced below
53 for details.
54
55 Impact
56 ======
57
58 Please review the referenced CVE identifiers for details.
59
60 Workaround
61 ==========
62
63 There is no known workaround at this time.
64
65 Resolution
66 ==========
67
68 All Mozilla Firefox users should upgrade to the latest version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose ">=www-client/firefox-84.0"
72
73 All Mozilla Firefox (bin) users should upgrade to the latest version:
74
75 # emerge --sync
76 # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-84.0"
77
78 All Mozilla Firefox ESR users should upgrade to the latest version:
79
80 # emerge --sync
81 # emerge --ask --oneshot -v ">=www-client/firefox-78.6.0:0/esr78"
82
83 All Mozilla Firefox ESR (bin) users should upgrade to the latest
84 version:
85
86 # emerge --sync
87 # emerge --ask --oneshot -v ">=www-client/firefox-bin-78.6.0:0/esr78"
88
89 All Mozilla Thunderbird users should upgrade to the latest version:
90
91 # emerge --sync
92 # emerge --ask --oneshot --verbose ">=mail-client/thunderbird-78.6.0"
93
94 All Mozilla Thunderbird (bin) users should upgrade to the latest
95 version:
96
97 # emerge --sync
98 # emerge --ask --oneshot -v ">=mail-client/thunderbird-bin-78.6.0"
99
100 References
101 ==========
102
103 [ 1 ] CVE-2020-16042
104 https://nvd.nist.gov/vuln/detail/CVE-2020-16042
105 [ 2 ] CVE-2020-26971
106 https://nvd.nist.gov/vuln/detail/CVE-2020-26971
107 [ 3 ] CVE-2020-26973
108 https://nvd.nist.gov/vuln/detail/CVE-2020-26973
109 [ 4 ] CVE-2020-26974
110 https://nvd.nist.gov/vuln/detail/CVE-2020-26974
111 [ 5 ] CVE-2020-26978
112 https://nvd.nist.gov/vuln/detail/CVE-2020-26978
113 [ 6 ] CVE-2020-35111
114 https://nvd.nist.gov/vuln/detail/CVE-2020-35111
115 [ 7 ] CVE-2020-35113
116 https://nvd.nist.gov/vuln/detail/CVE-2020-35113
117 [ 8 ] MFSA-2020-55
118 https://www.mozilla.org/en-US/security/advisories/mfsa2020-55/
119 [ 9 ] MFSA-2020-56
120 https://www.mozilla.org/en-US/security/advisories/mfsa2020-56/
121
122 Availability
123 ============
124
125 This GLSA and any updates to it are available for viewing at
126 the Gentoo Security Website:
127
128 https://security.gentoo.org/glsa/202012-20
129
130 Concerns?
131 =========
132
133 Security is a primary focus of Gentoo Linux and ensuring the
134 confidentiality and security of our users' machines is of utmost
135 importance to us. Any security concerns should be addressed to
136 security@g.o or alternatively, you may file a bug at
137 https://bugs.gentoo.org.
138
139 License
140 =======
141
142 Copyright 2020 Gentoo Foundation, Inc; referenced text
143 belongs to its owner(s).
144
145 The contents of this document are licensed under the
146 Creative Commons - Attribution / Share Alike license.
147
148 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
OpenPGP_signature.asc application/pgp-signature