This update to MozillaFirefox fixes several security issues and bugs.
Mozilla Firefox was updated to 44.0. Mozilla NSS was updated to 3.21
Mozilla NSPR was updated to 4.11.
The following vulnerabilities were fixed:
* CVE-2016-1930/CVE-2016-1931: Miscellaneous memory safety hazards
(boo#963633)
* CVE-2016-1933: Out of Memory crash when parsing GIF format images
(boo#963634)
* CVE-2016-1935: Buffer overflow in WebGL after out of memory allocation
(boo#963635)
* CVE-2015-7208/CVE-2016-1939: Firefox allows for control characters to be
set in cookie names (boo#963637)
* CVE-2016-1937: Missing delay following user click events in protocol
handler dialog (boo#963641)
* CVE-2016-1938: Errors in mp_div and mp_exptmod cryptographic functions
in NSS (boo#963731)
* CVE-2016-1942/CVE-2016-1943: Addressbar spoofing attacks (boo#963643)
* CVE-2016-1944/CVE-2016-1945/CVE-2016-1946: Unsafe memory manipulation
found through...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.1:
zypper in -t patch openSUSE-2016-128=1
- openSUSE 13.2:
zypper in -t patch openSUSE-2016-128=1
To bring your system up-to-date, use "zypper patch".
- openSUSE Leap 42.1 (i586 x86_64):
MozillaFirefox-44.0-12.2
MozillaFirefox-branding-upstream-44.0-12.2
MozillaFirefox-buildsymbols-44.0-12.2
MozillaFirefox-devel-44.0-12.2
MozillaFirefox-translations-common-44.0-12.2
MozillaFirefox-translations-other-44.0-12.2
libfreebl3-3.21-9.1
libfreebl3-debuginfo-3.21-9.1
libsoftokn3-3.21-9.1
libsoftokn3-debuginfo-3.21-9.1
mozilla-nspr-4.11-7.1
mozilla-nspr-debuginfo-4.11-7.1
mozilla-nspr-debugsource-4.11-7.1
mozilla-nspr-devel-4.11-7.1
mozilla-nss-3.21-9.1
mozilla-nss-certs-3.21-9.1
mozilla-nss-certs-debuginfo-3.21-9.1
mozilla-nss-debuginfo-3.21-9.1
mozilla-nss-debugsource-3.21-9.1
mozilla-nss-devel-3.21-9.1
mozilla-nss-sysinit-3.21-9.1
mozilla-nss-sysinit-debuginfo-3.21-9.1
mozilla-nss-tools-3.21-9.1
mozilla-nss-tools-debuginfo-3.21-9.1
- openSUSE Leap 42.1 (x86_64):
MozillaFirefox-debuginfo-44.0-12.2
MozillaFirefox-debugsource-44.0-12.2
libfreebl3-32bit-3.21-9.1
libfreebl3-debuginfo-32bit-3.21-9.1
libsoftokn3-32bit-3.21-9.1
libsoftokn3-debuginfo-32bit-3.21-9.1
mozilla-nspr-32...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2015-7208.html
https://www.suse.com/security/cve/CVE-2016-1930.html
https://www.suse.com/security/cve/CVE-2016-1931.html
https://www.suse.com/security/cve/CVE-2016-1933.html
https://www.suse.com/security/cve/CVE-2016-1935.html
https://www.suse.com/security/cve/CVE-2016-1937.html
https://www.suse.com/security/cve/CVE-2016-1938.html
https://www.suse.com/security/cve/CVE-2016-1939.html
https://www.suse.com/security/cve/CVE-2016-1942.html
https://www.suse.com/security/cve/CVE-2016-1943.html
https://www.suse.com/security/cve/CVE-2016-1944.html
https://www.suse.com/security/cve/CVE-2016-1945.html
https://www.suse.com/security/cve/CVE-2016-1946.html
https://www.suse.com/security/cve/CVE-2016-1947.html
https://bugzilla.suse.com/963633
https://bugzilla.suse.com/963634
https://bugzilla.suse.com/963635
https://bugzilla.suse.com/963637
https://bugzilla.suse.com/963641
https://bugzilla.suse.com/963643
https://bugzilla.suse.com/963644
https://bugzilla.suse.com/963645
https://bugzilla...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.