Oval Definition:oval:com.redhat.rhsa:def:20190219
Revision Date:2019-01-30Version:636
Title:RHSA-2019:0219: firefox security update (Critical)
Description:Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 60.5.0 ESR.

Security Fix(es):

  • Mozilla: Use-after-free parsing HTML5 stream (CVE-2018-18500)

  • Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5 (CVE-2018-18501)

  • Mozilla: Privilege escalation through IPC channel messages (CVE-2018-18505)

    For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

    Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Yaniv Frank (SophosLabs), Alex Gaynor, Christoph Diehl, Steven Crane, Jason Kratzer, Gary Kwong, Christian Holler, and Jed Davis as the original reporters.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-18500
    CVE-2018-18501
    CVE-2018-18505
    RHSA-2019:0219
    RHSA-2019:0219-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND firefox is earlier than 0:60.5.0-2.el7
  • AND firefox is signed with Red Hat redhatrelease2 key
  • BACK