Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE 42.1, 13.2: 2016:2368-1 Important Mozilla Update

opensuse
Calendar Grey September 24, 2016
Dist Opensuse Esm H88
Critical openSUSE upgrade for MozillaFirefox alongside mozilla-nss addresses 18 vulnerabilities. Apply the security update immediately!
An update that fixes 18 vulnerabilities is now available

Description

This update for MozillaFirefox and mozilla-nss fixes the following issues:

MozillaFirefox was updated to version 49.0 (boo#999701)

- New features

* Updated Firefox Login Manager to allow HTTPS pages to use saved HTTP

logins.

* Added features to Reader Mode that make it easier on the eyes and the

ears * Improved video performance for users on systems that support SSE3

without hardware acceleration

* Added context menu controls to HTML5 audio and video that let users loops files or play files at 1.25x speed

* Improvements in about:memory reports for tracking font memory usage

- Security related fixes

* MFSA 2016-85 CVE-2016-2827 (bmo#1289085) - Out-of-bounds read in

mozilla::net::IsValidReferrerPolicy CVE-2016-5270 (bmo#1291016) -

Heap-buffer-overflow in nsCaseTransformTextRunFactory::TransformString

CVE-2016-5271 (bmo#1288946) - Out-of-bounds read in

PropertyProvider::GetSpacingInternal...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-1119=1

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-1119=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

MozillaFirefox-49.0-33.1

MozillaFirefox-branding-upstream-49.0-33.1

MozillaFirefox-buildsymbols-49.0-33.1

MozillaFirefox-debuginfo-49.0-33.1

MozillaFirefox-debugsource-49.0-33.1

MozillaFirefox-devel-49.0-33.1

MozillaFirefox-translations-common-49.0-33.1

MozillaFirefox-translations-other-49.0-33.1

libfreebl3-3.25-29.1

libfreebl3-debuginfo-3.25-29.1

libsoftokn3-3.25-29.1

libsoftokn3-debuginfo-3.25-29.1

mozilla-nss-3.25-29.1

mozilla-nss-certs-3.25-29.1

mozilla-nss-certs-debuginfo-3.25-29.1

mozilla-nss-debuginfo-3.25-29.1

mozilla-nss-debugsource-3.25-29.1

mozilla-nss-devel-3.25-29.1

mozilla-nss-sysinit-3.25-29.1

mozilla-nss-sysinit-debuginfo-3.25-29.1

mozilla-nss-tools-3.25-29.1

mozilla-nss-tools-debuginfo-3.25-29.1

- openSUSE Leap 42.1 (x86_64):

libfreebl3-32bit-3.25-29.1

libfreebl3-debuginfo-32bit-3.25-29.1

libsoftokn3-32bit-3.25-29.1

libsoftokn3-debuginfo-32bit-3.25-29.1

mozilla-nss-32bit-3.25-29.1

mozilla-nss-certs-32bit-3.25-29.1

mozilla-nss-certs-debuginfo-32bit-3.25-29.1

mozill...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2016-2827.html

https://www.suse.com/security/cve/CVE-2016-5256.html

https://www.suse.com/security/cve/CVE-2016-5257.html

https://www.suse.com/security/cve/CVE-2016-5270.html

https://www.suse.com/security/cve/CVE-2016-5271.html

https://www.suse.com/security/cve/CVE-2016-5272.html

https://www.suse.com/security/cve/CVE-2016-5273.html

https://www.suse.com/security/cve/CVE-2016-5274.html

https://www.suse.com/security/cve/CVE-2016-5275.html

https://www.suse.com/security/cve/CVE-2016-5276.html

https://www.suse.com/security/cve/CVE-2016-5277.html

https://www.suse.com/security/cve/CVE-2016-5278.html

https://www.suse.com/security/cve/CVE-2016-5279.html

https://www.suse.com/security/cve/CVE-2016-5280.html

https://www.suse.com/security/cve/CVE-2016-5281.html

https://www.suse.com/security/cve/CVE-2016-5282.html

https://www.suse.com/security/cve/CVE-2016-5283.html

https://www.suse.com/security/cve/CVE-2016-5284.html

https://bugzilla.suse.com/999701

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2368-1
Rating: important
Affected Products: openSUSE Leap 42.1 openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here