Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2019.0268
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2019-0268)
Resumen:The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) announced via the MGASA-2019-0268 advisory.
Descripción:Summary:
The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) announced via the MGASA-2019-0268 advisory.

Vulnerability Insight:
The updated packages fix several bugs and some security issues:

Sandbox escape through Firefox Sync. (CVE-2019-9812)

Stored passwords in 'Saved Logins' can be copied without master password
entry. (CVE-2019-11733)

Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1.
(CVE-2019-11735)

File manipulation and privilege escalation in Mozilla Maintenance Service.
(CVE-2019-11736)

Content security policy bypass through hash-based sources in directives.
(CVE-2019-11738)

Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox
ESR 60.9. (CVE-2019-11740)

Same-origin policy violation with SVG filters and canvas to steal
cross-origin images. (CVE-2019-11742)

Cross-origin access to unload event attributes. (CVE-2019-11743)

XSS by breaking out of title and textarea elements using innerHTML.
(CVE-2019-11744)

Use-after-free while manipulating video. (CVE-2019-11746)

'Forget about this site' removes sites from pre-loaded HSTS list.
(CVE-2019-11747)

Persistence of WebRTC permissions in a third party context. (CVE-2019-11748)

Camera information available without prompting using getUserMedia.
(CVE-2019-11749)

Type confusion in Spidermonkey. (CVE-2019-11750)

Malicious code execution through command line parameters. (CVE-2019-11751)

Use-after-free while extracting a key value in IndexedDB. (CVE-2019-11752)

Privilege escalation with Mozilla Maintenance Service in custom Firefox
installation location. (CVE-2019-11753)

Affected Software/OS:
'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2019-11733
https://bugzilla.mozilla.org/show_bug.cgi?id=1565780
SuSE Security Announcement: openSUSE-SU-2019:2251 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html
SuSE Security Announcement: openSUSE-SU-2019:2260 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-11735
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1561404%2C1561484%2C1568047%2C1561912%2C1565744%2C1568858%2C1570358
Common Vulnerability Exposure (CVE) ID: CVE-2019-11736
https://bugzilla.mozilla.org/show_bug.cgi?id=1551913
https://bugzilla.mozilla.org/show_bug.cgi?id=1552206
Common Vulnerability Exposure (CVE) ID: CVE-2019-11738
https://bugzilla.mozilla.org/show_bug.cgi?id=1452037
Common Vulnerability Exposure (CVE) ID: CVE-2019-11740
https://security.gentoo.org/glsa/201911-07
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1563133%2C1573160
SuSE Security Announcement: openSUSE-SU-2019:2248 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
SuSE Security Announcement: openSUSE-SU-2019:2249 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
https://usn.ubuntu.com/4150-1/
Common Vulnerability Exposure (CVE) ID: CVE-2019-11742
https://bugzilla.mozilla.org/show_bug.cgi?id=1559715
Common Vulnerability Exposure (CVE) ID: CVE-2019-11743
https://bugzilla.mozilla.org/show_bug.cgi?id=1560495
https://w3c.github.io/navigation-timing
Common Vulnerability Exposure (CVE) ID: CVE-2019-11744
https://bugzilla.mozilla.org/show_bug.cgi?id=1562033
Common Vulnerability Exposure (CVE) ID: CVE-2019-11746
https://bugzilla.mozilla.org/show_bug.cgi?id=1564449
Common Vulnerability Exposure (CVE) ID: CVE-2019-11747
https://bugzilla.mozilla.org/show_bug.cgi?id=1564481
Common Vulnerability Exposure (CVE) ID: CVE-2019-11748
https://bugzilla.mozilla.org/show_bug.cgi?id=1564588
Common Vulnerability Exposure (CVE) ID: CVE-2019-11749
https://bugzilla.mozilla.org/show_bug.cgi?id=1565374
Common Vulnerability Exposure (CVE) ID: CVE-2019-11750
https://bugzilla.mozilla.org/show_bug.cgi?id=1568397
Common Vulnerability Exposure (CVE) ID: CVE-2019-11751
https://bugzilla.mozilla.org/show_bug.cgi?id=1572838
Common Vulnerability Exposure (CVE) ID: CVE-2019-11752
https://bugzilla.mozilla.org/show_bug.cgi?id=1501152
Common Vulnerability Exposure (CVE) ID: CVE-2019-11753
https://bugzilla.mozilla.org/show_bug.cgi?id=1574980
Common Vulnerability Exposure (CVE) ID: CVE-2019-9812
https://bugzilla.mozilla.org/show_bug.cgi?id=1538015
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.