Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

openSUSE Evergreen 11.4: 2015:0567-1 Important: Firefox DoS Issues

opensuse
Calendar Grey March 22, 2015
Scroller Opensuse
Crucial openSUSE patch addresses multiple vulnerabilities in Firefox version 31.5.3. Ensure your system is protected and upgraded today.
An update that fixes 7 vulnerabilities is now available

Description

Update to Firefox 31.5.3 (bnc#923534)

* MFSA 2015-28/CVE-2015-0818 (bmo#1144988) Privilege escalation through

SVG navigation

* MFSA 2015-29/CVE-2015-0817 (bmo#1145255) Code execution through

incorrect JavaScript bounds checking elimination

- update to Firefox 31.5.0esr (bnc#917597)

* MFSA 2015-11/CVE-2015-0836 Miscellaneous memory safety hazards

* MFSA 2015-12/CVE-2015-0833 (bmo#945192) Invoking Mozilla updater will

load locally stored DLL files (Windows only)

* MFSA 2015-16/CVE-2015-0831 (bmo#1130514) Use-after-free in IndexedDB

* MFSA 2015-19/CVE-2015-0827 (bmo#1117304) Out-of-bounds read and write

while rendering SVG content

* MFSA 2015-24/CVE-2015-0822 (bmo#1110557) Reading of local files

through manipulation of form autocomplete

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Evergreen 11.4:

zypper in -t patch 2015-11=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Evergreen 11.4 (i586 x86_64):

MozillaFirefox-31.5.3-137.1

MozillaFirefox-branding-upstream-31.5.3-137.1

MozillaFirefox-buildsymbols-31.5.3-137.1

MozillaFirefox-debuginfo-31.5.3-137.1

MozillaFirefox-debugsource-31.5.3-137.1

MozillaFirefox-devel-31.5.3-137.1

MozillaFirefox-translations-common-31.5.3-137.1

MozillaFirefox-translations-other-31.5.3-137.1

References

https://www.suse.com/security/cve/CVE-2015-0817.html

https://www.suse.com/security/cve/CVE-2015-0818.html

https://www.suse.com/security/cve/CVE-2015-0822.html

https://www.suse.com/security/cve/CVE-2015-0827.html

https://www.suse.com/security/cve/CVE-2015-0831.html

https://www.suse.com/security/cve/CVE-2015-0833.html

https://www.suse.com/security/cve/CVE-2015-0836.html

https://bugzilla.suse.com/show_bug.cgi?id=917597

https://bugzilla.suse.com/show_bug.cgi?id=923534

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:0567-1
Rating: important
Affected Products: openSUSE Evergreen 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.