Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

openSUSE: 2018:0681-1 Important: Mozilla Firefox Memory Safety Fixes

opensuse
Calendar Grey March 15, 2018
Dist Opensuse Esm H88
openSUSE Security Update: Security update for MozillaFirefox _______________________________________
An update that fixes 7 vulnerabilities is now available.

Description

This update for Mozilla Firefox to version 52.7.0esr fixes multiple issues.

Security issues fixed (bsc#1085130, MFSA 2018-07):

- CVE-2018-5127: Buffer overflow manipulating SVG animatedPathSegList

- CVE-2018-5129: Out-of-bounds write with malformed IPC messages

- CVE-2018-5130: Mismatched RTP payload type can trigger memory corruption

- CVE-2018-5131: Fetch API improperly returns cached copies of

no-store/no-cache resources

- CVE-2018-5144: Integer overflow during Unicode conversion

- CVE-2018-5125: Memory safety bugs fixed in Firefox 59 and Firefox ESR

52.7

- CVE-2018-5145: Memory safety bugs fixed in Firefox ESR 52.7

The following bug fixes are included:

- bsc#1076907: provide mimehandler(text/html)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-255=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (x86_64):

MozillaFirefox-52.7-78.1

MozillaFirefox-branding-upstream-52.7-78.1

MozillaFirefox-buildsymbols-52.7-78.1

MozillaFirefox-debuginfo-52.7-78.1

MozillaFirefox-debugsource-52.7-78.1

MozillaFirefox-devel-52.7-78.1

MozillaFirefox-translations-common-52.7-78.1

MozillaFirefox-translations-other-52.7-78.1

References

https://www.suse.com/security/cve/CVE-2018-5125.html

https://www.suse.com/security/cve/CVE-2018-5127.html

https://www.suse.com/security/cve/CVE-2018-5129.html

https://www.suse.com/security/cve/CVE-2018-5130.html

https://www.suse.com/security/cve/CVE-2018-5131.html

https://www.suse.com/security/cve/CVE-2018-5144.html

https://www.suse.com/security/cve/CVE-2018-5145.html

https://bugzilla.suse.com/1076907

https://bugzilla.suse.com/1085130

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0681-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here