Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

openSUSE Leap 42.3: 2018:0737-1 Important: Mozilla Firefox Out Of Bounds

opensuse
Calendar Grey March 18, 2018
Dist Opensuse Esm H88
A fresh update for openSUSE Leap 42.3 has been released, targeting critical security vulnerabilities in MozillaFirefox.
An update that fixes one vulnerability is now available.

Description

This update for Mozilla Firefox to version 52.7.2esr fixes security issues

and bugs.

Security issues fixed:

- CVE-2018-5146: Specially crafted vorbis files could have been used to

execute arbitrary code via an Out of bounds memory write (bsc#1085671,

MFSA 2018-08)

- CVE-2018-5147: Specially crafted vorbis files could have been used to

execute arbitrary code via an Out of bounds memory write - used on ARM

platforms (bsc#1085671, MFSA 2018-08)

The following bug fixes are included:

- Stability improvements in the Italian locale

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-278=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (x86_64):

MozillaFirefox-52.7.2-81.1

MozillaFirefox-branding-upstream-52.7.2-81.1

MozillaFirefox-buildsymbols-52.7.2-81.1

MozillaFirefox-debuginfo-52.7.2-81.1

MozillaFirefox-debugsource-52.7.2-81.1

MozillaFirefox-devel-52.7.2-81.1

MozillaFirefox-translations-common-52.7.2-81.1

MozillaFirefox-translations-other-52.7.2-81.1

References

https://www.suse.com/security/cve/CVE-2018-5146.html

https://bugzilla.suse.com/1085671

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0737-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here