Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 768825 (MFSA-2021-06) - <www-client/{firefox,thunderbird}-{78.7.1,85.0.1}: Buffer overflow in depth pitch calculations for compressed textures (MFSA-2021-06)
Summary: <www-client/{firefox,thunderbird}-{78.7.1,85.0.1}: Buffer overflow in depth p...
Status: RESOLVED INVALID
Alias: MFSA-2021-06
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://www.mozilla.org/en-US/securit...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-02-05 08:50 UTC by Sam James
Modified: 2021-02-05 22:12 UTC (History)
2 users (show)

See Also:
Package list:
www-client/firefox-78.7.1 mail-client/thunderbird-78.7.1
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-05 08:50:33 UTC
Fixed in 78.7.1, 85.0.1.

Not yet published but seems it will be at: https://www.mozilla.org/en-GB/security/advisories/mfsa2021-06/
Comment 1 Larry the Git Cow gentoo-dev 2021-02-05 20:02:26 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=cadd71c3b13d5ac34683211b3939c81dadb00211

commit cadd71c3b13d5ac34683211b3939c81dadb00211
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-02-05 20:01:44 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-02-05 20:02:13 +0000

    mail-client/thunderbird: bump to v78.7.1
    
    Bug: https://bugs.gentoo.org/768825
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 mail-client/thunderbird/Manifest                  |   66 ++
 mail-client/thunderbird/thunderbird-78.7.1.ebuild | 1073 +++++++++++++++++++++
 2 files changed, 1139 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=21978bd45a46892515cab0ce6e2dae9fdb7ddefa

commit 21978bd45a46892515cab0ce6e2dae9fdb7ddefa
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-02-05 19:47:44 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-02-05 20:02:13 +0000

    www-client/firefox: bump to v78.7.1 ESR
    
    Bug: https://bugs.gentoo.org/768825
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 www-client/firefox/Manifest              |   97 +++
 www-client/firefox/firefox-78.7.1.ebuild | 1147 ++++++++++++++++++++++++++++++
 2 files changed, 1244 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=72ff7e264ae4b3f4a5eb5cc4d7c2b825c04c651d

commit 72ff7e264ae4b3f4a5eb5cc4d7c2b825c04c651d
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-02-05 19:04:18 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-02-05 20:02:12 +0000

    www-client/firefox: bump to v85.0.1
    
    Bug: https://bugs.gentoo.org/768825
    Closes: https://bugs.gentoo.org/761277
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 www-client/firefox/Manifest              |   97 +++
 www-client/firefox/firefox-85.0.1.ebuild | 1137 ++++++++++++++++++++++++++++++
 2 files changed, 1234 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2021-02-05 20:11:42 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=603251712b8713cb17a91f987bb2c8683398d7cb

commit 603251712b8713cb17a91f987bb2c8683398d7cb
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-02-05 20:11:32 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-02-05 20:11:32 +0000

    www-client/firefox-bin: bump to v85.0.1
    
    Bug: https://bugs.gentoo.org/768825
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 www-client/firefox-bin/Manifest                  |  97 ++++++
 www-client/firefox-bin/firefox-bin-85.0.1.ebuild | 411 +++++++++++++++++++++++
 2 files changed, 508 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ec26965f7fdec70ab49c6a7f46973f5dca240525

commit ec26965f7fdec70ab49c6a7f46973f5dca240525
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-02-05 20:08:56 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-02-05 20:08:56 +0000

    www-client/firefox-bin: bump to v78.7.1 ESR
    
    Bug: https://bugs.gentoo.org/768825
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 www-client/firefox-bin/Manifest                  |  97 ++++++
 www-client/firefox-bin/firefox-bin-78.7.1.ebuild | 411 +++++++++++++++++++++++
 2 files changed, 508 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2c31a56f723c4bfb2bd983bb799a06c1adb2d161

commit 2c31a56f723c4bfb2bd983bb799a06c1adb2d161
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2021-02-05 20:05:33 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2021-02-05 20:05:33 +0000

    mail-client/thunderbird-bin: bump to v78.7.1
    
    Bug: https://bugs.gentoo.org/768825
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 mail-client/thunderbird-bin/Manifest               |  66 ++++
 .../thunderbird-bin/thunderbird-bin-78.7.1.ebuild  | 378 +++++++++++++++++++++
 2 files changed, 444 insertions(+)
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2021-02-05 22:12:06 UTC
NFU:

> Note: This issue only affected Windows operating systems. Other operating systems are unaffected.