Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

SUSE: 2014:1458-2 Important: Mozilla Firefox Protocol Downgrade Fix

suse
Calendar Grey November 21, 2014
Scroller Suse
SUSE launched a new security patch for Mozilla Firefox, addressing several flaws and enhancing protection mechanisms against potential threats.
An update that fixes 9 vulnerabilities is now available

Summary

This version update of Mozilla Firefox to 31.2.0ESR brings improvements, stability fixes and also security fixes for the following CVEs: CVE-2014-1574, CVE-2014-1575, CVE-2014-1576 ,CVE-2014-1577, CVE-2014-1578, CVE-2014-1581, CVE-2014-1583, CVE-2014-1585, CVE-2014-1586 It also disables SSLv3 by default to mitigate the protocol downgrade attack known as POODLE. This update fixes some regressions introduced by the previously released update. Security Issues: * CVE-2014-1574 * CVE-2014-1575 * CVE-2014-1576 * CVE-2014-1577

References

#900941 #905056 #905528

Cross- CVE-2014-1574 CVE-2014-1575 CVE-2014-1576

CVE-2014-1577 CVE-2014-1578 CVE-2014-1581

CVE-2014-1583 CVE-2014-1585 CVE-2014-1586

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2014-1574.html

https://www.suse.com/security/cve/CVE-2014-1575.html

https://www.suse.com/security/cve/CVE-2014-1576.html

https://www.suse.com/security/cve/CVE-2014-1577.html

https://www.suse.com/security/cve/CVE-2014-1578.html

https://www.suse.com/security/cve/CVE-2014-1581.html

https://www.suse.com/security/cve/CVE-2014-1583.html

https://www.suse.com/security/cve/CVE-2014-1585.html

https://www.suse.com/security/cve/CVE-2014-1586.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1458-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.