Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE 11.4: 2014:0419-1 Important: Mozilla Security Patch

opensuse
Calendar Grey March 21, 2014
Dist Opensuse Esm H88
A vital security patch for openSUSE addresses 29 vulnerabilities linked to Mozilla software, featuring crucial fixes and comprehensive user implementation guidelines
An update that fixes 29 vulnerabilities is now available

Description

This patch contains a collection of security relevant

updates for Mozilla applications.

Update Firefox to 24.4.0 (bnc#868603) Update Thunderbird to

24.4.0 Update NSPR to 4.10.4 Update NSS to 3.15.5

* MFSA 2014-15/CVE-2014-1493/CVE-2014-1494 Miscellaneous

memory safety hazards

* MFSA 2014-17/CVE-2014-1497 (bmo#966311) Out of bounds

read during WAV file decoding

* MFSA 2014-26/CVE-2014-1508 (bmo#963198) Information

disclosure through polygon rendering in MathML

* MFSA 2014-27/CVE-2014-1509 (bmo#966021) Memory

corruption in Cairo during PDF font rendering

* MFSA 2014-28/CVE-2014-1505 (bmo#941887) SVG filters information disclosure through feDisplacementMap

* MFSA 2014-29/CVE-2014-1510/CVE-2014-1511 (bmo#982906,

bmo#982909) Privilege escalation using

WebIDL-implemented APIs

* MFSA 2014-30/CVE-2014-1512 (bmo#982957) Use-after-free

in TypeObject

* MFSA 2014-31/CVE-2014-1513 (bmo#982974) Out-of-bounds

read/write through...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch 2014-37

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

MozillaFirefox-24.4.0-107.3

MozillaFirefox-branding-upstream-24.4.0-107.3

MozillaFirefox-buildsymbols-24.4.0-107.3

MozillaFirefox-debuginfo-24.4.0-107.3

MozillaFirefox-debugsource-24.4.0-107.3

MozillaFirefox-devel-24.4.0-107.3

MozillaFirefox-translations-common-24.4.0-107.3

MozillaFirefox-translations-other-24.4.0-107.3

MozillaThunderbird-24.4.0-89.2

MozillaThunderbird-buildsymbols-24.4.0-89.2

MozillaThunderbird-debuginfo-24.4.0-89.2

MozillaThunderbird-debugsource-24.4.0-89.2

MozillaThunderbird-devel-24.4.0-89.2

MozillaThunderbird-translations-common-24.4.0-89.2

MozillaThunderbird-translations-other-24.4.0-89.2

enigmail-1.6.0+24.4.0-89.2

libfreebl3-3.15.5-82.1

libfreebl3-debuginfo-3.15.5-82.1

libsoftokn3-3.15.5-82.1

libsoftokn3-debuginfo-3.15.5-82.1

mozilla-nspr-4.10.4-40.1

mozilla-nspr-debuginfo-4.10.4-40.1

mozilla-nspr-debugsource-4.10.4-40.1

mozilla-nspr-devel-4.10.4-40.1

mozilla-nss-3.15.5-82.1

mozilla-nss-certs-3.15.5-82.1

mozilla-nss-certs-debuginfo-3.15.5-82.1

mozilla-nss-deb...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2014-1477.html

https://www.suse.com/security/cve/CVE-2014-1478.html

https://www.suse.com/security/cve/CVE-2014-1479.html

https://www.suse.com/security/cve/CVE-2014-1480.html

https://www.suse.com/security/cve/CVE-2014-1481.html

https://www.suse.com/security/cve/CVE-2014-1482.html

https://www.suse.com/security/cve/CVE-2014-1483.html

https://www.suse.com/security/cve/CVE-2014-1485.html

https://www.suse.com/security/cve/CVE-2014-1486.html

https://www.suse.com/security/cve/CVE-2014-1487.html

https://www.suse.com/security/cve/CVE-2014-1488.html

https://www.suse.com/security/cve/CVE-2014-1490.html

https://www.suse.com/security/cve/CVE-2014-1491.html

https://www.suse.com/security/cve/CVE-2014-1493.html

https://www.suse.com/security/cve/CVE-2014-1494.html

https://www.suse.com/security/cve/CVE-2014-1497.html

https://www.suse.com/security/cve/CVE-2014-1498.html

https://www.suse.com/security/cve/CVE-2014-1499.html

https://www.suse.com/security/cve/CVE-2014-1500.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:0419-1
Rating: important
Affected Products: openSUSE 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here