MGASA-2020-0161

Source
https://advisories.mageia.org/MGASA-2020-0161.html
Import Source
https://advisories.mageia.org/MGASA-2020-0161.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0161
Related
Published
2020-04-05T17:07:15Z
Modified
2020-04-05T16:44:20Z
Summary
Updated firefox packages fix security vulnerabilities
Details

Updated firefox packages fix security vulnerabilities:

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free (CVE-2020-6819).

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free (CVE-2020-6820).

References
Credits

Affected packages

Mageia:7 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
68.6.1-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
68.6.1-1.mga7

Ecosystem specific

{
    "section": "core"
}