MGASA-2018-0393

Source
https://advisories.mageia.org/MGASA-2018-0393.html
Import Source
https://advisories.mageia.org/MGASA-2018-0393.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0393
Related
Published
2018-10-01T08:44:39Z
Modified
2018-10-01T08:19:44Z
Summary
Updated firefox packages fix security vulnerability
Details

Firefox 60 is now the only supported version of the ESR series and it brings a completely new browser engine, designed to take full advantage of the processing power in modern devices. Firefox also now exclusively supports extensions built using the WebExtension API.

This update brings Firefox 60.2.1 along with the needed updated libraries : - NSS 3.36.5 (fixes CVE CVE-2018-12384) - Sqlite 3.22.0 - Hunspell 1.6.2

References
Credits

Affected packages

Mageia:6 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.2.1-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
60.2.1-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / nss

Package

Name
nss
Purl
pkg:rpm/mageia/nss?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.36.5-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / sqlite3

Package

Name
sqlite3
Purl
pkg:rpm/mageia/sqlite3?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.22.0-2.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / hunspell1.6

Package

Name
hunspell1.6
Purl
pkg:rpm/mageia/hunspell1.6?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.2-1.mga6

Ecosystem specific

{
    "section": "core"
}