This update for MozillaFirefox to 68.1 fixes the following issues:
Security issues fixed:
- CVE-2019-9811: Fixed a sandbox escape via installation of malicious
language pack. (bsc#1140868)
- CVE-2019-9812: Fixed a sandbox escape through Firefox Sync. (bsc#1149294)
- CVE-2019-11710: Fixed several memory safety bugs. (bsc#1140868)
- CVE-2019-11714: Fixed a potentially exploitable crash in Necko.
(bsc#1140868)
- CVE-2019-11716: Fixed a sandbox bypass. (bsc#1140868)
- CVE-2019-11718: Fixed inadequate sanitation in the Activity Stream
component. (bsc#1140868)
- CVE-2019-11720: Fixed a character encoding XSS vulnerability.
(bsc#1140868)
- CVE-2019-11721: Fixed a homograph domain spoofing issue through unicode
latin 'kra' character. (bsc#1140868)
- CVE-2019-11723: Fixed a cookie leakage during add-on fetching across
private browsing boundaries. (bsc#1140868)
- CVE-2019-11724: Fixed an outdated permission, granting access to...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-2260=1
- openSUSE Leap 15.0 (x86_64):
MozillaFirefox-68.1.0-lp150.3.66.1
MozillaFirefox-branding-upstream-68.1.0-lp150.3.66.1
MozillaFirefox-buildsymbols-68.1.0-lp150.3.66.1
MozillaFirefox-debuginfo-68.1.0-lp150.3.66.1
MozillaFirefox-debugsource-68.1.0-lp150.3.66.1
MozillaFirefox-devel-68.1.0-lp150.3.66.1
MozillaFirefox-translations-common-68.1.0-lp150.3.66.1
MozillaFirefox-translations-other-68.1.0-lp150.3.66.1
https://www.suse.com/security/cve/CVE-2019-11710.html
https://www.suse.com/security/cve/CVE-2019-11714.html
https://www.suse.com/security/cve/CVE-2019-11716.html
https://www.suse.com/security/cve/CVE-2019-11718.html
https://www.suse.com/security/cve/CVE-2019-11720.html
https://www.suse.com/security/cve/CVE-2019-11721.html
https://www.suse.com/security/cve/CVE-2019-11723.html
https://www.suse.com/security/cve/CVE-2019-11724.html
https://www.suse.com/security/cve/CVE-2019-11725.html
https://www.suse.com/security/cve/CVE-2019-11727.html
https://www.suse.com/security/cve/CVE-2019-11728.html
https://www.suse.com/security/cve/CVE-2019-11733.html
https://www.suse.com/security/cve/CVE-2019-11735.html
https://www.suse.com/security/cve/CVE-2019-11736.html
https://www.suse.com/security/cve/CVE-2019-11738.html
https://www.suse.com/security/cve/CVE-2019-11740.html
https://www.suse.com/security/cve/CVE-2019-11742.html
https://www.suse.com/security/cve/CVE-2019-11743.html
https://www.suse.com/security/cve/CVE-2019-117...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.