Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE 12: 2015:0412-1 Important: Mozilla Firefox Denial of Service

suse
Calendar Grey March 3, 2015
Dist Suse Esm H88
SUSE Security Update concerning LibreOffice addresses several vulnerabilities categorized as critical. Please make sure your environment is refreshed quickly.
An update that fixes 5 vulnerabilities is now available

Summary

MozillaFirefox was updated to version 31.5.0 ESR to fix five security issues. These security issues were fixed: - CVE-2015-0836: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.5 allowed remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors (bnc#917597). - CVE-2015-0827: Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 31.5 allowed remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic (bnc#917597). - CVE-2015-0835: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allowed remote attackers to cause

References

#917597

Cross- CVE-2015-0822 CVE-2015-0827 CVE-2015-0831

CVE-2015-0835 CVE-2015-0836

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-0822.html

https://www.suse.com/security/cve/CVE-2015-0827.html

https://www.suse.com/security/cve/CVE-2015-0831.html

https://www.suse.com/security/cve/CVE-2015-0835.html

https://www.suse.com/security/cve/CVE-2015-0836.html

https://bugzilla.suse.com/show_bug.cgi?id=917597

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0412-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here