Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE Linux 11 SP2: 2013:0710-1 Critical: Firefox Memory Handling Flaws

suse
Calendar Grey April 8, 2013
Scroller Suse
SUSE releases new enhancements for Mozilla Firefox, addressing significant security vulnerabilities while improving overall browser reliability.
An update that fixes 12 vulnerabilities is now available

Summary

MozillaFirefox has been updated to the 17.0.5ESR release fixing bugs and security issues. Also Mozilla NSS has been updated to version 3.14.3 and Mozilla NSPR to 4.9.6. * MFSA 2013-30: Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan Sreckovic, and Joe Drew reported memory safety problems and crashes that affect Firefox ESR 17, and Firefox 19. (CVE-2013-0788) Andrew McCreight, Randell Jesup, Gary Kwong, Jesse Ruderman, Christian Holler, and Mats Palmgren reported

References

#813026

Cross- CVE-2013-0788 CVE-2013-0789 CVE-2013-0790

CVE-2013-0791 CVE-2013-0792 CVE-2013-0794

CVE-2013-0795 CVE-2013-0796 CVE-2013-0797

CVE-2013-0798 CVE-2013-0799 CVE-2013-0800

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 11 SP2

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://www.suse.com/security/cve/CVE-2013-0788.html

https://www.suse.com/security/cve/CVE-2013-0789.html

https://www.suse.com/security/cve/CVE-2013-0790.html

https://www.suse.com/security/cve/CVE-2013-0791.html

https://www.suse.com/security/cve/CVE-2013-0792.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0645-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.