Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2023:0523-1 Critical: MozillaFirefox Security Enhancement

suse
Calendar Grey February 18, 2014
Scroller Suse
SUSE patches address 14 vulnerabilities in MozillaFirefox, improving security. Refer to the announcement ID for further information.
An update that fixes 14 vulnerabilities is now available

Summary

This updates the Mozilla Firefox browser to the 24.3.0ESR security release. The Mozilla NSS libraries are now on version 3.15.4. The following security issues have been fixed: * MFSA 2014-01: Memory safety bugs fixed in Firefox ESR 24.3 and Firefox 27.0 (CVE-2014-1477)(bnc#862345) * MFSA 2014-02: Using XBL scopes its possible to steal(clone) native anonymous content (CVE-2014-1479)(bnc#862348) * MFSA 2014-03: Download "open file" dialog delay is too quick, doesn't prevent clickjacking (CVE-2014-1480) * MFSA 2014-04: Image decoding causing FireFox to crash with Goo Create (CVE-2014-1482)(bnc#862356) * MFSA 2014-05: caretPositionFromPoint and elementFromPoint leak information about iframe contents via timing information (CVE-2014-1483)(bnc#862360) * MFSA 2014-06: Fennec leaks profile path to logcat

References

#859055 #861847

Cross- CVE-2014-1477 CVE-2014-1479 CVE-2014-1480

CVE-2014-1481 CVE-2014-1482 CVE-2014-1483

CVE-2014-1484 CVE-2014-1485 CVE-2014-1486

CVE-2014-1487 CVE-2014-1488 CVE-2014-1489

CVE-2014-1490 CVE-2014-1491

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-1477.html

https://www.suse.com/security/cve/CVE-2014-1479.html

https://www.suse.com/security/cve/CVE-2014-1480.html

https://www.suse.com/security/cve/CVE-2014-1481.html

https://www.suse.com/security/cve/CVE-2014-1482.html

https://www.suse.com/security/cve/CVE-2014-1483.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0248-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.