Oval Definition:oval:com.redhat.rhsa:def:20173382
Revision Date:2017-12-05Version:637
Title:RHSA-2017:3382: firefox security update (Important)
Description:Mozilla Firefox is an open source web browser.

This update upgrades Firefox to version 52.5.1 ESR.

Security Fix(es):

  • A privacy flaw was discovered in Firefox. In Private Browsing mode, a web worker could write persistent data to IndexedDB, which was not cleared when exiting and would persist across multiple sessions. A malicious website could exploit the flaw to bypass private-browsing protections and uniquely fingerprint visitors. (CVE-2017-7843)

    Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Konark as the original reporter.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-7843
    RHSA-2017:3382
    RHSA-2017:3382-00
    RHSA-2017:3382-01
    Platform(s):Red Hat Enterprise Linux 6
    Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND firefox is earlier than 0:52.5.1-1.el6_9
  • AND firefox is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND firefox is earlier than 0:52.5.1-1.el7_4
  • AND firefox is signed with Red Hat redhatrelease2 key
  • BACK