Bug 46170 - firefox-esr: Multiple issues (4.2)
firefox-esr: Multiple issues (4.2)
Status: CLOSED DUPLICATE of bug 45611
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.2
Other Linux
: P5 normal (vote)
: ---
Assigned To: Philipp Hahn
Stefan Gohmann
http://metadata.ftp-master.debian.org...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-01-25 14:48 CET by Philipp Hahn
Modified: 2018-02-14 06:49 CET (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Philipp Hahn univentionstaff 2018-01-25 14:48:18 CET
firefox-esr (52.6.0esr-1~deb8u1)

* CVE-2018-5089: Memory safety bugs fixed in Firefox 58 and Firefox ESR 52.6 (MFSA 2018-03)
* CVE-2018-5091: Use-after-free with DTMF timers (MFSA 2018-03)
* CVE-2018-5095: Integer overflow in Skia library during edge builder allocation (MFSA 2018-03)
* CVE-2018-5096: Use-after-free while editing form elements (MFSA 2018-03)
* CVE-2018-5097: Use-after-free when source document is manipulated during XSLT (MFSA 2018-03)
* CVE-2018-5098: Use-after-free while manipulating form input elements (MFSA 2018-03)
* CVE-2018-5099: Use-after-free with widget listener (MFSA 2018-03)
* CVE-2018-5102: Use-after-free in HTML media elements (MFSA 2018-03)
* CVE-2018-5103: Use-after-free during mouse event handling (MFSA 2018-03)
* CVE-2018-5104: Use-after-free during font face manipulation (MFSA 2018-03)
* CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right (MFSA 2018-03)
Comment 1 Philipp Hahn univentionstaff 2018-01-25 14:53:08 CET
3f7daf1289 Bug #46170: firefox-esr
Comment 2 Philipp Hahn univentionstaff 2018-01-25 14:59:59 CET

*** This bug has been marked as a duplicate of bug 45611 ***
Comment 3 Stefan Gohmann univentionstaff 2018-02-14 06:49:26 CET
OK, duplicate
Comment 4 Stefan Gohmann univentionstaff 2018-02-14 06:49:42 CET
Nothing to release