![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.10.2020.0377 |
Category: | Mageia Linux Local Security Checks |
Title: | Mageia: Security Advisory (MGASA-2020-0377) |
Summary: | The remote host is missing an update for the 'crypto-policies, firefox, firefox-l10n, nspr, nss, p11-kit, rootcerts' package(s) announced via the MGASA-2020-0377 advisory. |
Description: | Summary: The remote host is missing an update for the 'crypto-policies, firefox, firefox-l10n, nspr, nss, p11-kit, rootcerts' package(s) announced via the MGASA-2020-0377 advisory. Vulnerability Insight: Mozilla developer Jason Kratzer reported memory safety bugs present in Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2020-15673). Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in a XSS issue due to JavaScript being executed after pasting attacker-controlled data into a contenteditable element (CVE-2020-15676). By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from (CVE-2020-15677). When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules (CVE-2020-15678). The firefox package has been updated to the 78.x ESR branch, which brings significant changes in how CA certificates and smart cards are loaded into Firefox. The root CA certificates are no longer statically built into the nss library. They are loaded dynamically via p11-kit-trust, and therefore may be modified by the system administrator. Smart card support should be automatically loaded via p11-kit-trust as well, rather than requiring opensc to be manually loaded. NSS also now complies with the system crypto policy, which is provided by the crypto-policies package. See the fedoraproject references for details. Affected Software/OS: 'crypto-policies, firefox, firefox-l10n, nspr, nss, p11-kit, rootcerts' package(s) on Mageia 7. Solution: Please install the updated package(s). CVSS Score: 6.8 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2020-15673 Debian Security Information: DSA-4770 (Google Search) https://www.debian.org/security/2020/dsa-4770 https://security.gentoo.org/glsa/202010-02 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1648493%2C1660800 https://www.mozilla.org/security/advisories/mfsa2020-42/ https://www.mozilla.org/security/advisories/mfsa2020-43/ https://www.mozilla.org/security/advisories/mfsa2020-44/ https://lists.debian.org/debian-lts-announce/2020/10/msg00020.html SuSE Security Announcement: openSUSE-SU-2020:1780 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00074.html SuSE Security Announcement: openSUSE-SU-2020:1785 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00077.html Common Vulnerability Exposure (CVE) ID: CVE-2020-15676 https://bugzilla.mozilla.org/show_bug.cgi?id=1646140 Common Vulnerability Exposure (CVE) ID: CVE-2020-15677 https://bugzilla.mozilla.org/show_bug.cgi?id=1641487 Common Vulnerability Exposure (CVE) ID: CVE-2020-15678 https://bugzilla.mozilla.org/show_bug.cgi?id=1660211 |
Copyright | Copyright (C) 2022 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |