Описание
ELSA-2015-0766: firefox security update (CRITICAL)
[31.6.0-2.0.1.el5_11]
- Add firefox-oracle-default-prefs.js and firefox-oracle-default-bookmarks.html and remove the corresponding Red Hat files
[31.6.0-1]
- Update to 31.6.0 ESR Build 2
[31.6.0-1]
- Update to 31.6.0 ESR
Обновленные пакеты
Oracle Linux 5
Oracle Linux x86_64
firefox
31.6.0-2.0.1.el5_11
Oracle Linux i386
firefox
31.6.0-2.0.1.el5_11
Oracle Linux 6
Oracle Linux x86_64
firefox
31.6.0-2.0.1.el6_6
Oracle Linux i686
firefox
31.6.0-2.0.1.el6_6
Oracle Linux 7
Oracle Linux x86_64
firefox
31.6.0-2.0.1.el7_1
xulrunner
31.6.0-2.0.1.el7_1
xulrunner-devel
31.6.0-2.0.1.el7_1
Ссылки на источники
Связанные уязвимости
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.