Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE: 2016:2862-1 Critical: MozillaFirefox, NSS Security Flaw

opensuse
Calendar Grey November 18, 2016
Dist Opensuse Esm H88
Critical update for MozillaFirefox and mozilla-nss addressing important security issues affecting openSUSE users.
An update that fixes 19 vulnerabilities is now available

Description

This update to Mozilla Firefox 50.0 fixes a number of security issues.

The following vulnerabilities were fixed in Mozilla Firefox (MFSA 2016-89):

- CVE-2016-5296: Heap-buffer-overflow WRITE in rasterize_edges_1

(bmo#1292443)

- CVE-2016-5292: URL parsing causes crash (bmo#1288482)

- CVE-2016-5297: Incorrect argument length checking in Javascript

(bmo#1303678)

- CVE-2016-9064: Addons update must verify IDs match between current and

new versions (bmo#1303418)

- CVE-2016-9066: Integer overflow leading to a buffer overflow in

nsScriptLoadHandler (bmo#1299686)

- CVE-2016-9067: heap-use-after-free in nsINode::ReplaceOrInsertBefore

(bmo#1301777, bmo#1308922 (CVE-2016-9069))

- CVE-2016-9068: heap-use-after-free in nsRefreshDriver (bmo#1302973)

- CVE-2016-9075: WebExtensions can access the mozAddonManager API and use

it to gain elevated privileges (bmo#1295324)

- CVE-2016-9077: Canvas filters allow feDisplacementMaps to be...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2016-1334=1

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-1334=1

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-1334=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.2 (i586 x86_64):

MozillaFirefox-50.0-39.2

MozillaFirefox-branding-upstream-50.0-39.2

MozillaFirefox-buildsymbols-50.0-39.2

MozillaFirefox-debuginfo-50.0-39.2

MozillaFirefox-debugsource-50.0-39.2

MozillaFirefox-devel-50.0-39.2

MozillaFirefox-translations-common-50.0-39.2

MozillaFirefox-translations-other-50.0-39.2

libfreebl3-3.26.2-32.1

libfreebl3-debuginfo-3.26.2-32.1

libsoftokn3-3.26.2-32.1

libsoftokn3-debuginfo-3.26.2-32.1

mozilla-nss-3.26.2-32.1

mozilla-nss-certs-3.26.2-32.1

mozilla-nss-certs-debuginfo-3.26.2-32.1

mozilla-nss-debuginfo-3.26.2-32.1

mozilla-nss-debugsource-3.26.2-32.1

mozilla-nss-devel-3.26.2-32.1

mozilla-nss-sysinit-3.26.2-32.1

mozilla-nss-sysinit-debuginfo-3.26.2-32.1

mozilla-nss-tools-3.26.2-32.1

mozilla-nss-tools-debuginfo-3.26.2-32.1

- openSUSE Leap 42.2 (x86_64):

libfreebl3-32bit-3.26.2-32.1

libfreebl3-debuginfo-32bit-3.26.2-32.1

libsoftokn3-32bit-3.26.2-32.1

libsoftokn3-debuginfo-32bit-3.26.2-32.1

mozilla-nss-32bit-3.26.2-32.1

mozilla-nss-certs-32bit-3.26.2-32.1

mozilla-n...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2016-5289.html

https://www.suse.com/security/cve/CVE-2016-5290.html

https://www.suse.com/security/cve/CVE-2016-5291.html

https://www.suse.com/security/cve/CVE-2016-5292.html

https://www.suse.com/security/cve/CVE-2016-5296.html

https://www.suse.com/security/cve/CVE-2016-5297.html

https://www.suse.com/security/cve/CVE-2016-9063.html

https://www.suse.com/security/cve/CVE-2016-9064.html

https://www.suse.com/security/cve/CVE-2016-9066.html

https://www.suse.com/security/cve/CVE-2016-9067.html

https://www.suse.com/security/cve/CVE-2016-9068.html

https://www.suse.com/security/cve/CVE-2016-9069.html

https://www.suse.com/security/cve/CVE-2016-9070.html

https://www.suse.com/security/cve/CVE-2016-9071.html

https://www.suse.com/security/cve/CVE-2016-9073.html

https://www.suse.com/security/cve/CVE-2016-9074.html

https://www.suse.com/security/cve/CVE-2016-9075.html

https://www.suse.com/security/cve/CVE-2016-9076.html

https://www.suse.com/security/cve/CVE-2016-9077.html

https://bugz...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2861-1
Rating: important
Affected Products: openSUSE Leap 42.2 openSUSE Leap 42.1 openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here