Alpine: multiple firefox-esr packages: security update to 60.7.0-r0

critical Tenable Cloud Security Plugin ID 404419

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use.
This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox <
67, and Firefox ESR < 60.7. (CVE-2019-9820)

- Cross-origin images can be read from a canvas element in violation of the same-origin policy using the
transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*.
This vulnerability affects Firefox < 65.0.1. (CVE-2018-18511)

- Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker
to perform an out of bounds memory read via a crafted HTML page. (CVE-2019-5798)

- png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function
is called under png_safe_execute. (CVE-2019-7317)

- Cross-origin images can be read in violation of the same-origin policy by exporting an image after using
createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element.
This vulnerability affects Firefox < 66. (CVE-2019-9797)

See Also

https://security.alpinelinux.org/vuln/CVE-2018-18511

https://security.alpinelinux.org/vuln/CVE-2019-5798

https://security.alpinelinux.org/vuln/CVE-2019-7317

https://security.alpinelinux.org/vuln/CVE-2019-9797

https://security.alpinelinux.org/vuln/CVE-2019-9800

https://security.alpinelinux.org/vuln/CVE-2019-9815

https://security.alpinelinux.org/vuln/CVE-2019-9816

https://security.alpinelinux.org/vuln/CVE-2019-9817

https://security.alpinelinux.org/vuln/CVE-2019-9818

https://security.alpinelinux.org/vuln/CVE-2019-9819

https://security.alpinelinux.org/vuln/CVE-2019-9820

https://security.alpinelinux.org/vuln/CVE-2019-11691

https://security.alpinelinux.org/vuln/CVE-2019-11692

https://security.alpinelinux.org/vuln/CVE-2019-11693

https://security.alpinelinux.org/vuln/CVE-2019-11694

https://security.alpinelinux.org/vuln/CVE-2019-11698

Plugin Details

Severity: Critical

ID: 404419

Version: Revision 1.39

Type: Local

Published: 10/31/2023

Updated: 6/9/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-9820

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 1/25/2019

Reference Information

CVE: CVE-2018-18511, CVE-2019-11691, CVE-2019-11692, CVE-2019-11693, CVE-2019-11694, CVE-2019-11698, CVE-2019-5798, CVE-2019-7317, CVE-2019-9797, CVE-2019-9800, CVE-2019-9815, CVE-2019-9816, CVE-2019-9817, CVE-2019-9818, CVE-2019-9819, CVE-2019-9820

BID: 107009, 107363, 108098, 107486, 108418