Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

openSUSE 15.0: 2018:1616-1 Important: MozillaFirefox Buffer Overflow

opensuse
Calendar Grey June 8, 2018
Scroller Opensuse
A recent security enhancement for Mozilla Firefox and mozilla-nss targets a critical memory overflow vulnerability, integrating vital corrections.
An update that solves one vulnerability and has three fixes is now available.

Description

This update for MozillaFirefox, mozilla-nss fixes the following issues:

Security issue fixed in Mozilla Firefox 60.0.2 ESR:

- CVE-2018-6126: Heap buffer overflow rasterizing paths in SVG with Skia

(MFSA 2018-14, boo#1096449)

The following bugs were fixed:

- In KDE Open with option in download dialog has no effect with

kmozillahelper (boo#1094747)

- Startup crashes on aarch64 (boo#1093059)

Mozilla Firefox now requires NSS 3.36.4 (boo#1096515). The following

changes are included in NSS:

- Fix issues connecting to servers recently upgraded to TLS 1.3

(SSL_RX_MALFORMED_SERVER_HELLO error)

- Fix a rare bug with PKCS#12 files

- Apply additional harding (relro linker option)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-575=1

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-575=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

libfreebl3-3.36.4-50.1

libfreebl3-debuginfo-3.36.4-50.1

libsoftokn3-3.36.4-50.1

libsoftokn3-debuginfo-3.36.4-50.1

mozilla-nss-3.36.4-50.1

mozilla-nss-certs-3.36.4-50.1

mozilla-nss-certs-debuginfo-3.36.4-50.1

mozilla-nss-debuginfo-3.36.4-50.1

mozilla-nss-debugsource-3.36.4-50.1

mozilla-nss-devel-3.36.4-50.1

mozilla-nss-sysinit-3.36.4-50.1

mozilla-nss-sysinit-debuginfo-3.36.4-50.1

mozilla-nss-tools-3.36.4-50.1

mozilla-nss-tools-debuginfo-3.36.4-50.1

- openSUSE Leap 42.3 (x86_64):

MozillaFirefox-60.0.2-101.1

MozillaFirefox-branding-upstream-60.0.2-101.1

MozillaFirefox-buildsymbols-60.0.2-101.1

MozillaFirefox-debuginfo-60.0.2-101.1

MozillaFirefox-debugsource-60.0.2-101.1

MozillaFirefox-devel-60.0.2-101.1

MozillaFirefox-translations-common-60.0.2-101.1

MozillaFirefox-translations-other-60.0.2-101.1

libfreebl3-32bit-3.36.4-50.1

libfreebl3-debuginfo-32bit-3.36.4-50.1

libsoftokn3-32bit-3.36.4-50.1

libsoftokn3-debuginfo-32bit-3.36.4-50.1

mozilla-nss-32bit-3.36.4-50.1

mozilla-nss-certs-32...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-6126.html

https://bugzilla.suse.com/1093059

https://bugzilla.suse.com/1094747

https://bugzilla.suse.com/1096449

https://bugzilla.suse.com/1096515

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:1616-1
Rating: important
Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.