C
月内に
Mozillaは、FirefoxおよびThunderbirdのLinux向けリリースに使用されるGPG署名鍵(サブキー)が、誤ってGitHubのプライベートリポ…
📌 一言でいうと
Mozillaは、FirefoxおよびThunderbirdのLinux向けリリースに使用されるGPG署名鍵(サブキー)が、誤ってGitHubのプライベートリポジトリに公開されたため、当該鍵を失効させ、新しい鍵に更新しました。調査の結果、外部への流出や不正アクセスの形跡は確認されておらず、サプライチェーン攻撃のリスクは極めて低いと判断されています。影響を受けたのはLinux向けアーカイブ(tar)、RPMパッケージ、およびチェックサムファイルの署名に使用されるサブキーです。
🔍該当判定
- Linux OSを利用しており、FirefoxやThunderbirdを公式サイトからtar形式やRPMパッケージで直接ダウンロードしてインストールしている
- Linux環境で、FirefoxやThunderbirdのインストール時にGPG鍵(署名)を用いてファイルの正当性を検証する運用を行っている
- 社内サーバーやPCに、Linux版のFirefoxまたはThunderbirdを配布・展開する仕組みを構築している
上記いずれにも該当しない(Windows/Mac版を利用している、またはOS標準のパッケージ管理ツールのみを利用している) → 静観でOK
✅該当時の対応
Linux向けにFirefoxやThunderbirdを配布・検証している管理者は、Mozillaが提供する最新のGPG公開鍵を導入し、署名検証を更新することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Mozilla (Firefox/Thunderbird) GPG署名鍵の更新について
お疲れさまです。Mozillaによる署名鍵の更新に関する情報共有です。
■ 概要
MozillaのLinux向けリリース(Firefox/Thunderbird)に使用されていたGPG署名サブキーが、誤ってGitHubのプライベートリポジトリに保存されていたため、予防的措置として鍵の失効と更新が行われました。外部流出の形跡はなく、実害は報告されていません。
■ 影響範囲
- 対象製品: Firefox, Thunderbird (Linux向け)
- 対象ファイル: tarアーカイブ、RPMパッケージ、チェックサムファイル
■ 対応手順
1. Linux環境で上記製品を署名検証して導入している場合、最新のGPG公開鍵を再取得してください。
2. 新しい鍵を用いて、配布ファイルの整合性を再確認してください。
■ 参考情報
- Mozilla公式発表(xakep等のレポート経由)
対応優先度: 低
対応期限: 次回アップデート時
お疲れさまです。Mozillaによる署名鍵の更新に関する情報共有です。
■ 概要
MozillaのLinux向けリリース(Firefox/Thunderbird)に使用されていたGPG署名サブキーが、誤ってGitHubのプライベートリポジトリに保存されていたため、予防的措置として鍵の失効と更新が行われました。外部流出の形跡はなく、実害は報告されていません。
■ 影響範囲
- 対象製品: Firefox, Thunderbird (Linux向け)
- 対象ファイル: tarアーカイブ、RPMパッケージ、チェックサムファイル
■ 対応手順
1. Linux環境で上記製品を署名検証して導入している場合、最新のGPG公開鍵を再取得してください。
2. 新しい鍵を用いて、配布ファイルの整合性を再確認してください。
■ 参考情報
- Mozilla公式発表(xakep等のレポート経由)
対応優先度: 低
対応期限: 次回アップデート時
Subject: [Info] Update on Mozilla (Firefox/Thunderbird) GPG Signing Keys
Dear team,
This is a notification regarding the update of GPG signing keys by Mozilla.
■ Overview
Mozilla has revoked and replaced a GPG signing subkey used for Linux releases of Firefox and Thunderbird because an unencrypted copy was accidentally stored in a private GitHub repository. No evidence of unauthorized access was found, and the risk of a supply chain attack is considered extremely low.
■ Scope
- Affected Products: Firefox, Thunderbird (Linux versions)
- Affected Files: tar archives, RPM packages, and checksum files
■ Action Items
1. If you manually verify signatures for these products in Linux environments, please update to the latest GPG public key.
2. Use the new key to verify the integrity of the distributed files.
■ Reference
- Mozilla official announcements
Priority: Low
Deadline: Next scheduled update
Dear team,
This is a notification regarding the update of GPG signing keys by Mozilla.
■ Overview
Mozilla has revoked and replaced a GPG signing subkey used for Linux releases of Firefox and Thunderbird because an unencrypted copy was accidentally stored in a private GitHub repository. No evidence of unauthorized access was found, and the risk of a supply chain attack is considered extremely low.
■ Scope
- Affected Products: Firefox, Thunderbird (Linux versions)
- Affected Files: tar archives, RPM packages, and checksum files
■ Action Items
1. If you manually verify signatures for these products in Linux environments, please update to the latest GPG public key.
2. Use the new key to verify the integrity of the distributed files.
■ Reference
- Mozilla official announcements
Priority: Low
Deadline: Next scheduled update