Summary: | <www-client/firefox{,-bin}-{78.7.0,85.0}: multiple vulnerabilities (MFSA2021-{03,04}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | mozilla |
Priority: | Normal | Flags: | nattka:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | A2 [glsa+ cve] | ||
Package list: |
www-client/firefox-78.7.0
|
Runtime testing required: | --- |
Bug Depends on: | 784569 | ||
Bug Blocks: | 767397 |
Description
John Helmert III
2021-01-26 18:12:37 UTC
Actually, at the bottom of the advisories there's the normal memory safety fixes which are presumed to be able to produce code execution exploits. CVE-2021-{23964,23965}. x86 done amd64 done arm64 done all arches done This issue was resolved and addressed in GLSA 202102-01 at https://security.gentoo.org/glsa/202102-01 by GLSA coordinator Aaron Bauman (b-man). re-opened for cleanup The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=311b1adcad283bca8c383ad3f807143df090c077 commit 311b1adcad283bca8c383ad3f807143df090c077 Author: Joonas Niilola <juippis@gentoo.org> AuthorDate: 2021-02-01 05:53:55 +0000 Commit: Joonas Niilola <juippis@gentoo.org> CommitDate: 2021-02-01 05:54:41 +0000 www-client/firefox-bin: security cleanup Bug: https://bugs.gentoo.org/767334 Signed-off-by: Joonas Niilola <juippis@gentoo.org> www-client/firefox-bin/Manifest | 97 ------ www-client/firefox-bin/firefox-bin-78.6.1.ebuild | 411 ----------------------- 2 files changed, 508 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8b0ec6a4a863a7a31980028678f6ffd7d5e96557 commit 8b0ec6a4a863a7a31980028678f6ffd7d5e96557 Author: Joonas Niilola <juippis@gentoo.org> AuthorDate: 2021-02-01 05:53:26 +0000 Commit: Joonas Niilola <juippis@gentoo.org> CommitDate: 2021-02-01 05:54:40 +0000 www-client/firefox: security cleanup Bug: https://bugs.gentoo.org/767334 Signed-off-by: Joonas Niilola <juippis@gentoo.org> www-client/firefox/Manifest | 96 --- www-client/firefox/firefox-78.6.1.ebuild | 1130 ------------------------------ 2 files changed, 1226 deletions(-) Thanks! All done. Freeing CVE-2021-23961 for tracker creation. |