Security Vulnerabilities fixed in firefox RHSA-2020:5561

description-logoDescription

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 78.6.0 ESR. Security Fix(es): chromium-browser: Uninitialized Use in V8 (CVE-2020-16042) Mozilla: Heap buffer overflow in WebGL (CVE-2020-26971) Mozilla: CSS Sanitizer performed incorrect sanitization (CVE-2020-26973) Mozilla: Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free (CVE-2020-26974) Mozilla: Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6 (CVE-2020-35113) Mozilla: Internal network hosts could have been probed by a malicious webpage (CVE-2020-26978) Mozilla: The proxy.onRequest API did not catch view-source URLs (CVE-2020-35111) chromium-browser: Uninitialized Use in V8 (CVE-2020-16042) Mozilla: Heap buffer overflow in WebGL (CVE-2020-26971) Mozilla: CSS Sanitizer performed incorrect sanitization (CVE-2020-26973) Mozilla: Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free (CVE-2020-26974) Mozilla: Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6 (CVE-2020-35113) Mozilla: Internal network hosts could have been probed by a malicious webpage (CVE-2020-26978) Mozilla: The proxy.onRequest API did not catch view-source URLs (CVE-2020-35111) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

affected-products-logoAffected Applications

firefox