MGASA-2020-0274

Source
https://advisories.mageia.org/MGASA-2020-0274.html
Import Source
https://advisories.mageia.org/MGASA-2020-0274.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0274
Related
Published
2020-07-04T22:47:21Z
Modified
2020-07-04T22:18:09Z
Summary
Updated firefox packages fix security vulnerability
Details

Updated nss and firefox packages fix security vulnerabilities:

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys (CVE-2020-12399).

Side channel vulnerabilities during RSA key generation in NSS (CVE-2020-12402).

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash due to a use-after-free (CVE-2020-12405).

Mozilla developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash due to type confusion with NativeTypes. We presume that with enough effort that it could be exploited to run arbitrary code (CVE-2020-12406).

Mozilla developers Tom Tung and Karl Tomlinson reported memory safety bugs present in Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2020-12410).

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript (CVE-2020-12418).

When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free in nsGlobalWindowInner. This could have led to memory corruption and a potentially exploitable crash (CVE-2020-12419).

When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash (CVE-2020-12420).

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user (CVE-2020-12421).

References
Credits

Affected packages

Mageia:7 / nspr

Package

Name
nspr
Purl
pkg:rpm/mageia/nspr?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.26-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / rootcerts

Package

Name
rootcerts
Purl
pkg:rpm/mageia/rootcerts?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20200612.00-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / nss

Package

Name
nss
Purl
pkg:rpm/mageia/nss?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.52.1-1.1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
68.10.0-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
68.10.0-1.mga7

Ecosystem specific

{
    "section": "core"
}