Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2019.0268
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2019-0268)
Zusammenfassung:The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) announced via the MGASA-2019-0268 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) announced via the MGASA-2019-0268 advisory.

Vulnerability Insight:
The updated packages fix several bugs and some security issues:

Sandbox escape through Firefox Sync. (CVE-2019-9812)

Stored passwords in 'Saved Logins' can be copied without master password
entry. (CVE-2019-11733)

Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1.
(CVE-2019-11735)

File manipulation and privilege escalation in Mozilla Maintenance Service.
(CVE-2019-11736)

Content security policy bypass through hash-based sources in directives.
(CVE-2019-11738)

Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox
ESR 60.9. (CVE-2019-11740)

Same-origin policy violation with SVG filters and canvas to steal
cross-origin images. (CVE-2019-11742)

Cross-origin access to unload event attributes. (CVE-2019-11743)

XSS by breaking out of title and textarea elements using innerHTML.
(CVE-2019-11744)

Use-after-free while manipulating video. (CVE-2019-11746)

'Forget about this site' removes sites from pre-loaded HSTS list.
(CVE-2019-11747)

Persistence of WebRTC permissions in a third party context. (CVE-2019-11748)

Camera information available without prompting using getUserMedia.
(CVE-2019-11749)

Type confusion in Spidermonkey. (CVE-2019-11750)

Malicious code execution through command line parameters. (CVE-2019-11751)

Use-after-free while extracting a key value in IndexedDB. (CVE-2019-11752)

Privilege escalation with Mozilla Maintenance Service in custom Firefox
installation location. (CVE-2019-11753)

Affected Software/OS:
'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-11733
https://bugzilla.mozilla.org/show_bug.cgi?id=1565780
SuSE Security Announcement: openSUSE-SU-2019:2251 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html
SuSE Security Announcement: openSUSE-SU-2019:2260 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-11735
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1561404%2C1561484%2C1568047%2C1561912%2C1565744%2C1568858%2C1570358
Common Vulnerability Exposure (CVE) ID: CVE-2019-11736
https://bugzilla.mozilla.org/show_bug.cgi?id=1551913
https://bugzilla.mozilla.org/show_bug.cgi?id=1552206
Common Vulnerability Exposure (CVE) ID: CVE-2019-11738
https://bugzilla.mozilla.org/show_bug.cgi?id=1452037
Common Vulnerability Exposure (CVE) ID: CVE-2019-11740
https://security.gentoo.org/glsa/201911-07
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1563133%2C1573160
SuSE Security Announcement: openSUSE-SU-2019:2248 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
SuSE Security Announcement: openSUSE-SU-2019:2249 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
https://usn.ubuntu.com/4150-1/
Common Vulnerability Exposure (CVE) ID: CVE-2019-11742
https://bugzilla.mozilla.org/show_bug.cgi?id=1559715
Common Vulnerability Exposure (CVE) ID: CVE-2019-11743
https://bugzilla.mozilla.org/show_bug.cgi?id=1560495
https://w3c.github.io/navigation-timing
Common Vulnerability Exposure (CVE) ID: CVE-2019-11744
https://bugzilla.mozilla.org/show_bug.cgi?id=1562033
Common Vulnerability Exposure (CVE) ID: CVE-2019-11746
https://bugzilla.mozilla.org/show_bug.cgi?id=1564449
Common Vulnerability Exposure (CVE) ID: CVE-2019-11747
https://bugzilla.mozilla.org/show_bug.cgi?id=1564481
Common Vulnerability Exposure (CVE) ID: CVE-2019-11748
https://bugzilla.mozilla.org/show_bug.cgi?id=1564588
Common Vulnerability Exposure (CVE) ID: CVE-2019-11749
https://bugzilla.mozilla.org/show_bug.cgi?id=1565374
Common Vulnerability Exposure (CVE) ID: CVE-2019-11750
https://bugzilla.mozilla.org/show_bug.cgi?id=1568397
Common Vulnerability Exposure (CVE) ID: CVE-2019-11751
https://bugzilla.mozilla.org/show_bug.cgi?id=1572838
Common Vulnerability Exposure (CVE) ID: CVE-2019-11752
https://bugzilla.mozilla.org/show_bug.cgi?id=1501152
Common Vulnerability Exposure (CVE) ID: CVE-2019-11753
https://bugzilla.mozilla.org/show_bug.cgi?id=1574980
Common Vulnerability Exposure (CVE) ID: CVE-2019-9812
https://bugzilla.mozilla.org/show_bug.cgi?id=1538015
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.