Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE 11.4: 2014:0213-1 Important: Mozilla Multiple Fixes

opensuse
Calendar Grey February 8, 2014
Dist Opensuse Esm H88
This patch resolves essential Mozilla concerns rectifying 10 flaws in openSUSE, significantly boosting system safety.
An update that fixes 10 vulnerabilities is now available

Description

Updates for mozilla-nss (3.15.4) MozillaFirefox (24.3.0esr)

MozillaThunderbird (24.3.0) including fixes for the

following issues:

* MFSA 2014-01/CVE-2014-1477/CVE-2014-1478 Miscellaneous

memory safety hazards (rv:27.0 / rv:24.3)

* MFSA 2014-02/CVE-2014-1479 (bmo#911864) Clone protected

content with XBL scopes

* MFSA 2014-04/CVE-2014-1482 (bmo#943803) Incorrect use

of discarded images by RasterImage

* MFSA 2014-08/CVE-2014-1486 (bmo#942164) Use-after-free

with imgRequestProxy and image proccessing

* MFSA 2014-09/CVE-2014-1487 (bmo#947592) Cross-origin

information leak through web workers * MFSA 2014-12/CVE-2014-1490/CVE-2014-1491 (bmo#934545,

bmo#930874, bmo#930857) NSS ticket handling issues

* MFSA 2014-13/CVE-2014-1481(bmo#936056) Inconsistent

JavaScript handling of access to Window objects

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch 2014-16

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

MozillaFirefox-24.3.0-99.1

MozillaFirefox-branding-upstream-24.3.0-99.1

MozillaFirefox-buildsymbols-24.3.0-99.1

MozillaFirefox-debuginfo-24.3.0-99.1

MozillaFirefox-debugsource-24.3.0-99.1

MozillaFirefox-devel-24.3.0-99.1

MozillaFirefox-translations-common-24.3.0-99.1

MozillaFirefox-translations-other-24.3.0-99.1

MozillaThunderbird-24.3.0-85.1

MozillaThunderbird-buildsymbols-24.3.0-85.1

MozillaThunderbird-debuginfo-24.3.0-85.1

MozillaThunderbird-debugsource-24.3.0-85.1

MozillaThunderbird-devel-24.3.0-85.1

MozillaThunderbird-translations-common-24.3.0-85.1

MozillaThunderbird-translations-other-24.3.0-85.1

enigmail-1.6.0+24.3.0-85.1

libfreebl3-3.15.4-78.1

libfreebl3-debuginfo-3.15.4-78.1

libsoftokn3-3.15.4-78.1

libsoftokn3-debuginfo-3.15.4-78.1

mozilla-nss-3.15.4-78.1

mozilla-nss-certs-3.15.4-78.1

mozilla-nss-certs-debuginfo-3.15.4-78.1

mozilla-nss-debuginfo-3.15.4-78.1

mozilla-nss-debugsource-3.15.4-78.1

mozilla-nss-devel-3.15.4-78.1

mozilla-nss-sysinit-3.15.4-78.1

mozilla-nss-sysinit...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2013-1740.html

https://www.suse.com/security/cve/CVE-2014-1477.html

https://www.suse.com/security/cve/CVE-2014-1478.html

https://www.suse.com/security/cve/CVE-2014-1479.html

https://www.suse.com/security/cve/CVE-2014-1481.html

https://www.suse.com/security/cve/CVE-2014-1482.html

https://www.suse.com/security/cve/CVE-2014-1486.html

https://www.suse.com/security/cve/CVE-2014-1487.html

https://www.suse.com/security/cve/CVE-2014-1490.html

https://www.suse.com/security/cve/CVE-2014-1491.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:0213-1
Rating: important
Affected Products: openSUSE 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here