Oval Definition:oval:com.redhat.rhsa:def:20205237
Revision Date:2020-11-30Version:636
Title:RHSA-2020:5237: firefox security update (Important)
Description:Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 78.5.0 ESR.

Security Fix(es):

  • Mozilla: Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code (CVE-2020-26951)

  • Mozilla: Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5 (CVE-2020-26968)

  • Mozilla: Variable time processing of cross-origin images during drawImage calls (CVE-2020-16012)

  • Mozilla: Fullscreen could be enabled without displaying the security UI (CVE-2020-26953)

  • Mozilla: XSS through paste (manual and clipboard API) (CVE-2020-26956)

  • Mozilla: Requests intercepted through ServiceWorkers lacked MIME type restrictions (CVE-2020-26958)

  • Mozilla: Use-after-free in WebRequestService (CVE-2020-26959)

  • Mozilla: Potential use-after-free in uses of nsTArray (CVE-2020-26960)

  • Mozilla: DoH did not filter IPv4 mapped IP Addresses (CVE-2020-26961)

  • Mozilla: Software keyboards may have remembered typed passwords (CVE-2020-26965)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2020-16012
    CVE-2020-26951
    CVE-2020-26953
    CVE-2020-26956
    CVE-2020-26958
    CVE-2020-26959
    CVE-2020-26960
    CVE-2020-26961
    CVE-2020-26965
    CVE-2020-26968
    RHSA-2020:5237
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • firefox is earlier than 0:78.5.0-1.el8_3
  • AND firefox is signed with Red Hat redhatrelease2 key
  • AND
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • BACK