Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/DAE28B909B174D05D3368A9202D0417C
HistoryDec 14, 2020 - 12:00 a.m.

Security fix for the ALT Linux 10 package firefox-esr version 78.6.0-alt1

2020-12-1400:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
10

0.004 Low

EPSS

Percentile

72.9%

Dec. 14, 2020 Andrey Cherepanov 78.6.0-alt1

- New version (78.6.0).
- Fixes:
  + CVE-2020-16042 Operations on a BigInt could have caused uninitialized memory to be exposed
  + CVE-2020-26971 Heap buffer overflow in WebGL
  + CVE-2020-26973 CSS Sanitizer performed incorrect sanitization
  + CVE-2020-26974 Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free
  + CVE-2020-26978 Internal network hosts could have been probed by a malicious webpage
  + CVE-2020-35111 The proxy.onRequest API did not catch view-source URLs
  + CVE-2020-35112 Opening an extension-less download may have inadvertently launched an executable instead
  + CVE-2020-35113 Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6