Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2013:1919-1 Important: Mozilla Firefox Memory Safety Fixes

suse
Calendar Grey December 19, 2013
Scroller Suse
Mozilla Firefox has rolled out an update addressing 13 vulnerabilities. This release includes critical security patches and introduces new package versions to enhance user protection.
An update that fixes 13 vulnerabilities is now available

Summary

MozillaFirefox has been updated to the 24.2.0 ESR security release. This is a major upgrade from the 17 ESR release branch. Security issues fixed: * CVE-2013-5611 Application Installation doorhanger persists on navigation (MFSA 2013-105) * CVE-2013-5609 Miscellaneous memory safety hazards (rv:24.2) (MFSA 2013-104) * CVE-2013-5610 Miscellaneous memory safety hazards (rv:26.0) (MFSA 2013-104) * CVE-2013-5612 Character encoding cross-origin XSS attack (MFSA 2013-106) * CVE-2013-5614 Sandbox restrictions not applied to nested object elements (MFSA 2013-107) * CVE-2013-5616 Use-after-free in event listeners (MFSA 2013-108) * CVE-2013-5619 Potential overflow in JavaScript binary search algorithms (MFSA 2013-110) * CVE-2013-6671 Segmentation violation when replacing

References

#854367 #854370

Cross- CVE-2013-5609 CVE-2013-5610 CVE-2013-5611

CVE-2013-5612 CVE-2013-5613 CVE-2013-5614

CVE-2013-5615 CVE-2013-5616 CVE-2013-5618

CVE-2013-5619 CVE-2013-6671 CVE-2013-6672

CVE-2013-6673

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2013-5609.html

https://www.suse.com/security/cve/CVE-2013-5610.html

https://www.suse.com/security/cve/CVE-2013-5611.html

https://www.suse.com/security/cve/CVE-2013-5612.html

https://www.suse.com/security/cve/CVE-2013-5613.html

https://www.suse.com/security/cve/CVE-2013-5614.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:1919-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.