Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2014:1624-1 Important: Mozilla Firefox DoS and Safety Issues

suse
Calendar Grey December 12, 2014
Scroller Suse
SUSE launches critical patches for Google Chrome tackling various significant vulnerabilities. Keep your system secure.
An update that fixes 9 vulnerabilities is now available

Summary

Mozilla Firefox has been updated to the 31.3ESR release fixing bugs and security issues. * MFSA 2014-83 / CVE-2014-1588 / CVE-2014-1587: Mozilla developers and community identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. * MFSA 2014-85 / CVE-2014-1590: Security researcher Joe Vennix from Rapid7 reported that passing a JavaScript object to XMLHttpRequest that mimics an input stream will a crash. This crash is not exploitable and can only be used for denial of service attacks. * MFSA 2014-87 / CVE-2014-1592: Security researcher Berend-Jan Wever

References

#908009

Cross- CVE-2014-1587 CVE-2014-1588 CVE-2014-1589

CVE-2014-1590 CVE-2014-1591 CVE-2014-1592

CVE-2014-1593 CVE-2014-1594 CVE-2014-1595

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Server 11 SP2 LTSS

SUSE Linux Enterprise Server 11 SP1 LTSS

SUSE Linux Enterprise Server 10 SP4 LTSS

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-1587.html

https://www.suse.com/security/cve/CVE-2014-1588.html

https://www.suse.com/security/cve/CVE-2014-1589.html

https://www.suse.com/security/cve/CVE-2014-1590.html

https://www.suse.com/security/cve/CVE-2014-1591.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1624-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.