File _patchinfo of Package patchinfo.13712
<patchinfo incident="13712">
<issue tracker="bnc" id="1160498">EMU: VUL-0: MozillaFirefox, Update Firefox to 72.0.1/68.4.1 esr (MFSA 2020-03)</issue>
<issue tracker="bnc" id="1160305">VUL-0: MozillaFirefox, MozillaThunderbird: Update Firefox and Thunderbird to 72.0/68.4 esr (MFSA 2020-01 and MFSA 2020-02)</issue>
<issue tracker="cve" id="2019-17021"/>
<issue tracker="cve" id="2019-17015"/>
<issue tracker="cve" id="2019-17024"/>
<issue tracker="cve" id="2019-17026"/>
<issue tracker="cve" id="2019-17017"/>
<issue tracker="cve" id="2019-17022"/>
<issue tracker="cve" id="2019-17016"/>
<packager>MSirringhaus</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for MozillaFirefox</summary>
<description>This update for MozillaFirefox fixes the following issues:
- Firefox Extended Support Release 68.4.1 ESR
* Fixed: Security fix
MFSA 2020-03 (bsc#1160498)
* CVE-2019-17026 (bmo#1607443)
IonMonkey type confusion with StoreElementHole and
FallibleStoreElement
- Firefox Extended Support Release 68.4.0 ESR
* Fixed: Various security fixes
MFSA 2020-02 (bsc#1160305)
* CVE-2019-17015 (bmo#1599005)
Memory corruption in parent process during new content
process initialization on Windows
* CVE-2019-17016 (bmo#1599181)
Bypass of @namespace CSS sanitization during pasting
* CVE-2019-17017 (bmo#1603055)
Type Confusion in XPCVariant.cpp
* CVE-2019-17021 (bmo#1599008)
Heap address disclosure in parent process during content
process initialization on Windows
* CVE-2019-17022 (bmo#1602843)
CSS sanitization does not escape HTML tags
* CVE-2019-17024 (bmo#1507180, bmo#1595470, bmo#1598605,
bmo#1601826)
Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4
</description>
</patchinfo>