firefox (SL5, SL6, SL7)

Synopsis: Critical: firefox security update
Advisory ID: SLSA-2015:2657-1
Issue Date: 2015-12-16
CVE Numbers: CVE-2015-7201
CVE-2015-7210
CVE-2015-7212
CVE-2015-7205
CVE-2015-7213
CVE-2015-7222
CVE-2015-7214

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user
running Firefox. (CVE-2015-7201, CVE-2015-7205, CVE-2015-7210,
CVE-2015-7212, CVE-2015-7213, CVE-2015-7222)

A flaw was found in the way Firefox handled content using the ‘data:’ and
‘view-source:’ URIs. An attacker could use this flaw to bypass the same-
origin policy and read data from cross-site URLs and local files.
(CVE-2015-7214)

5.0 ESR, which corrects these issues. After installing the update, Firefox
must be restarted for the changes to take effect.

SL5
x86_64
firefox-38.5.0-2.el5_11.i386.rpm
firefox-38.5.0-2.el5_11.x86_64.rpm
firefox-debuginfo-38.5.0-2.el5_11.i386.rpm
firefox-debuginfo-38.5.0-2.el5_11.x86_64.rpm
i386
firefox-38.5.0-2.el5_11.i386.rpm
firefox-debuginfo-38.5.0-2.el5_11.i386.rpm
SL6
x86_64
firefox-38.5.0-2.el6_7.x86_64.rpm
firefox-debuginfo-38.5.0-2.el6_7.x86_64.rpm
firefox-38.5.0-2.el6_7.i686.rpm
firefox-debuginfo-38.5.0-2.el6_7.i686.rpm
i386
firefox-38.5.0-2.el6_7.i686.rpm
firefox-debuginfo-38.5.0-2.el6_7.i686.rpm

– Scientific Linux Development Team