Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE 13.1: 2016:3310-1 Important: MozillaFirefox DoS Issues

opensuse
Calendar Grey December 31, 2016
Dist Opensuse Esm H88
openSUSE Security Enhancement: The recent MozillaFirefox patch addresses 13 vulnerabilities in openSUSE 13.1, improving both performance and security.
An update that fixes 13 vulnerabilities is now available

Description

This update to MozillaFirefox 50.1.0 fixes the following

vulnerabilities:

- CVE-2016-9894: Buffer overflow in SkiaGL

- CVE-2016-9899: Use-after-free while manipulating DOM events and audio

elements

- CVE-2016-9895: CSP bypass using marquee tag

- CVE-2016-9896: Use-after-free with WebVR

- CVE-2016-9897: Memory corruption in libGLES

- CVE-2016-9898: Use-after-free in Editor while manipulating DOM

subtrees

- CVE-2016-9900: Restricted external resources can be loaded by SVG

images through data URLs

- CVE-2016-9904: Cross-origin information leak in shared atoms

- CVE-2016-9901: Data from Pocket server improperly sanitized before

execution

- CVE-2016-9902: Pocket extension does not validate the origin of events

- CVE-2016-9903: XSS injection vulnerability in add-ons SDK

- CVE-2016-9080: Memory safety bugs fixed in Firefox 50.1

- CVE-2016-9893: Memory safety bugs fixed in...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch 2016-1534=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i586 x86_64):

MozillaFirefox-50.1.0-134.1

MozillaFirefox-branding-upstream-50.1.0-134.1

MozillaFirefox-buildsymbols-50.1.0-134.1

MozillaFirefox-debuginfo-50.1.0-134.1

MozillaFirefox-debugsource-50.1.0-134.1

MozillaFirefox-devel-50.1.0-134.1

MozillaFirefox-translations-common-50.1.0-134.1

MozillaFirefox-translations-other-50.1.0-134.1

References

https://www.suse.com/security/cve/CVE-2016-9080.html

https://www.suse.com/security/cve/CVE-2016-9893.html

https://www.suse.com/security/cve/CVE-2016-9894.html

https://www.suse.com/security/cve/CVE-2016-9895.html

https://www.suse.com/security/cve/CVE-2016-9896.html

https://www.suse.com/security/cve/CVE-2016-9897.html

https://www.suse.com/security/cve/CVE-2016-9898.html

https://www.suse.com/security/cve/CVE-2016-9899.html

https://www.suse.com/security/cve/CVE-2016-9900.html

https://www.suse.com/security/cve/CVE-2016-9901.html

https://www.suse.com/security/cve/CVE-2016-9902.html

https://www.suse.com/security/cve/CVE-2016-9903.html

https://www.suse.com/security/cve/CVE-2016-9904.html

https://bugzilla.suse.com/show_bug.cgi?id=1011922

https://bugzilla.suse.com/show_bug.cgi?id=1015422

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:3310-1
Rating: important
Affected Products: openSUSE 13.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here