CLD-701 Details

Other IDs this deficiency may be known by:

CVE ID None
Other ID(s) fixed-in-60.7.2

Basic Information:

Affected Package(s) firefox
Deficiency Type SECURITY
Date Created 2019-07-14 09:48:30
Date Last Modified 2019-07-14 10:07:42

Version Specific Information:

Cucumber 1.1 i686 fixed in firefox-60.7.2esr-i686-1
Cucumber 1.1 x86_64 fixed in firefox-60.7.2esr-x86_64-1

Details:

This is an upstream release that fixes the following security vulnerabilities:
	CVE-2019-11702: IE protocols can be used to open known local files
	CVE-2019-9816: Type confusion with object groups and UnboxedObjects
	CVE-2019-9817: Stealing of cross-domain images using canvas
	CVE-2019-9818: Use-after-free in crash generation server
	CVE-2019-9819: Compartment mismatch with fetch API
	CVE-2019-9820: Use-after-free of ChromeEventHandler by DocShell
	CVE-2019-11691: Use-after-free in XMLHttpRequest
	CVE-2019-11692: Use-after-free removing listeners in the event listener
		manager
	CVE-2019-11693: Buffer overflow in WebGL bufferdata on Linux
	CVE-2019-7317: Use-after-free in png_image_free of libpng library
	CVE-2019-9797: Cross-origin theft of images with createImageBitmap
	CVE-2018-18511: Cross-origin theft of images with
		ImageBitmapRenderingContext
	CVE-2019-11694: Uninitialized memory memory leakage in Windows sandbox
	CVE-2019-11698: Theft of user history data through drag and drop of
		hyperlinks to and from bookmarks
	CVE-2019-5798: Out-of-bounds read in Skia
	CVE-2019-9800: Memory safety bugs fixed in Firefox 67 and
		Firefox ESR 60.7

For more information see:
	This is an upstream
	release that fixes the following security vulnerabilities:
	CVE-2019-11702: IE protocols can be used to open known local files
	CVE-2019-9816: Type confusion with object groups and UnboxedObjects
	CVE-2019-9817: Stealing of cross-domain images using canvas
	CVE-2019-9818: Use-after-free in crash generation server
	CVE-2019-9819: Compartment mismatch with fetch API
	CVE-2019-9820: Use-after-free of ChromeEventHandler by DocShell
	CVE-2019-11691: Use-after-free in XMLHttpRequest
	CVE-2019-11692: Use-after-free removing listeners in the event listener
		manager
	CVE-2019-11693: Buffer overflow in WebGL bufferdata on Linux
	CVE-2019-7317: Use-after-free in png_image_free of libpng library
	CVE-2019-9797: Cross-origin theft of images with createImageBitmap
	CVE-2018-18511: Cross-origin theft of images with
		ImageBitmapRenderingContext
	CVE-2019-11694: Uninitialized memory memory leakage in Windows sandbox
	CVE-2019-11698: Theft of user history data through drag and drop of
		hyperlinks to and from bookmarks
	CVE-2019-5798: Out-of-bounds read in Skia
	CVE-2019-9800: Memory safety bugs fixed in Firefox 67 and
		Firefox ESR 60.7

For more information see:
	https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/
	https://www.mozilla.org/en-US/security/advisories/mfsa2019-16/
	https://www.mozilla.org/en-US/security/advisories/mfsa2019-19/