Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2023:0105-1 Critical: Mozilla Firefox Vulnerability Fix

suse
Calendar Grey March 8, 2013
Scroller Suse
SUSE has rolled out a critical security update for Mozilla Firefox, implementing essential patches aimed at improving both safety and overall functionality.
An update that fixes 9 vulnerabilities is now available

Summary

MozillaFirefox has been updated to the 17.0.3ESR release. Important: due to compatibility issues, the Beagle plug-in for MozillaFirefox is temporarily disabled by this update. Besides the major version update from the 10ESR stable release line to the 17ESR stable release line, this update brings critical security and bugfixes: * MFSA 2013-28: Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover a series of use-after-free, out of bounds read, and buffer overflow problems rated as low to critical security issues in shipped software. Some of these issues are potentially exploitable, allowing for remote code execution. We would also like to thank Abhishek for reporting four additional use-after-free and out of bounds write flaws introduced

References

#804248 #806669

Cross- CVE-2013-0765 CVE-2013-0772 CVE-2013-0773

CVE-2013-0774 CVE-2013-0775 CVE-2013-0776

CVE-2013-0780 CVE-2013-0782 CVE-2013-0783

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2013-0765.html

https://www.suse.com/security/cve/CVE-2013-0772.html

https://www.suse.com/security/cve/CVE-2013-0773.html

https://www.suse.com/security/cve/CVE-2013-0774.html

https://www.suse.com/security/cve/CVE-2013-0775.html

https://www.suse.com/security/cve/CVE-2013-0776.html

https://www.suse.com/security/cve/CVE-2013-0780.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0410-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.