MGASA-2015-0305

Source
https://advisories.mageia.org/MGASA-2015-0305.html
Import Source
https://advisories.mageia.org/MGASA-2015-0305.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0305
Related
Published
2015-08-07T19:20:18Z
Modified
2015-08-07T19:08:16Z
Summary
Updated firefox package fixes CVE-2015-4495
Details

Updated firefox packages fix security vulnerability:

Security researcher Cody Crews reported on a way to violate the same origin policy and inject script into a non-privileged part of the built-in PDF Viewer in Firefox. This would allow an attacker to read and steal sensitive local files on the victim's computer (CVE-2015-4495).

References
Credits

Affected packages

Mageia:4 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
38.1.1-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
38.1.1-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
38.1.1-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
38.1.1-1.mga5

Ecosystem specific

{
    "section": "core"
}