Oval Definition:oval:com.redhat.rhsa:def:20171106
Revision Date:2017-04-21Version:636
Title:RHSA-2017:1106: firefox security update (Critical)
Description:Mozilla Firefox is an open source web browser.

This update upgrades Firefox to version 52.1.0 ESR.

Security Fix(es):

  • Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2017-5429, CVE-2017-5430, CVE-2017-5432, CVE-2017-5433, CVE-2017-5434, CVE-2017-5435, CVE-2017-5436, CVE-2017-5437, CVE-2017-5438, CVE-2017-5439, CVE-2017-5440, CVE-2017-5441, CVE-2017-5442, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445, CVE-2017-5446, CVE-2017-5447, CVE-2017-5448, CVE-2017-5449, CVE-2017-5451, CVE-2017-5454, CVE-2017-5455, CVE-2017-5456, CVE-2017-5459, CVE-2017-5460, CVE-2017-5464, CVE-2017-5465, CVE-2017-5466, CVE-2017-5467, CVE-2017-5469)

    Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Mozilla developers and community, Nils, Holger Fuhrmannek, Atte Kettunen, Takeshi Terada, Huzaifa Sidhpurwala, Nicolas Grégoire, Chamal De Silva, Chun Han Hsiao, Ivan Fratric of Google Project Zero, Anonymous working with Trend Micro's Zero Day Initiative, Haik Aftandilian, Paul Theriault, Julian Hector, Petr Cerny, Jordi Chancel, and Heather Miller of Google Skia team as the original reporters.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-10195
    CVE-2016-10196
    CVE-2016-10197
    CVE-2017-5429
    CVE-2017-5430
    CVE-2017-5432
    CVE-2017-5433
    CVE-2017-5434
    CVE-2017-5435
    CVE-2017-5436
    CVE-2017-5437
    CVE-2017-5438
    CVE-2017-5439
    CVE-2017-5440
    CVE-2017-5441
    CVE-2017-5442
    CVE-2017-5443
    CVE-2017-5444
    CVE-2017-5445
    CVE-2017-5446
    CVE-2017-5447
    CVE-2017-5448
    CVE-2017-5449
    CVE-2017-5451
    CVE-2017-5454
    CVE-2017-5455
    CVE-2017-5456
    CVE-2017-5459
    CVE-2017-5460
    CVE-2017-5464
    CVE-2017-5465
    CVE-2017-5466
    CVE-2017-5467
    CVE-2017-5469
    RHSA-2017:1106
    RHSA-2017:1106-00
    RHSA-2017:1106-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND firefox is earlier than 0:52.1.0-2.el7_3
  • AND firefox is signed with Red Hat redhatrelease2 key
  • BACK