Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 438
Alerts This Week
Warning Icon 1 438

SUSE: 2012:0425-1 Critical: Mozilla Firefox Memory Safety Exploits

suse
Calendar Grey March 29, 2012
Scroller Suse
SUSE Security Patch for Mozilla Firefox tackling urgent vulnerabilities. This update encompasses security enhancements and stability improvements.
An update that contains security fixes can now be An update that contains security fixes can now be An update that contains security fixes can now be installed

Summary

Mozilla Firefox was updated to 3.6.28 to fix various bugs and security issues. The following security issues have been fixed: * MFSA 2012-19: Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. In general these flaws cannot be exploited through email in the Thunderbird and SeaMonkey products because scripting is disabled, but are potentially a risk in browser or browser-like contexts in those products. References Bob Clary reported two bugs that causes crashes that affected Firefox 3.6, Firefox ESR, and Firefox 10. CVE-2012-0461

References

#752168

Affected Products:

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0425-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.