Scientific Linux Security Update : firefox on SL6.x i386/x86_64

High Nessus Plugin ID 109851

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

This update upgrades Firefox to version 52.8.0 ESR.

Security Fix(es) :

- Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8 (CVE-2018-5150)

- Mozilla: Backport critical security fixes in Skia (CVE-2018-5183)

- Mozilla: Use-after-free with SVG animations and clip paths (CVE-2018-5154)

- Mozilla: Use-after-free with SVG animations and text paths (CVE-2018-5155)

- Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files (CVE-2018-5157)

- Mozilla: Malicious PDF can inject JavaScript into PDF Viewer (CVE-2018-5158)

- Mozilla: Integer overflow and out-of-bounds write in Skia (CVE-2018-5159)

- Mozilla: Lightweight themes can be installed without user interaction (CVE-2018-5168)

- Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension (CVE-2018-5178)

Solution

Update the affected firefox and / or firefox-debuginfo packages.

See Also

http://www.nessus.org/u?e0c87798

Plugin Details

Severity: High

ID: 109851

File Name: sl_20180515_firefox_on_SL6_x.nasl

Version: 1.2

Type: local

Agent: unix

Published: 2018/05/16

Modified: 2018/05/18

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2018/05/15

Reference Information

CVE: CVE-2018-5150, CVE-2018-5154, CVE-2018-5155, CVE-2018-5157, CVE-2018-5158, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178, CVE-2018-5183

IAVA: 2018-A-0160