Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2015:0446-1 Important: Mozilla Firefox Denial of Service Risk

suse
Calendar Grey March 7, 2015
Dist Suse Esm H88
SUSE issues important security updates for Mozilla Firefox to resolve multiple issues and enhance stability.
An update that fixes four vulnerabilities is now available

Summary

MozillaFirefox has been updated to version 31.5.0 ESR to fix five security issues. These security issues have been fixed: * CVE-2015-0836: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.5 allowed remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors (bnc#917597). * CVE-2015-0827: Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 31.5 allowed remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic (bnc#917597). * CVE-2015-0835: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allowed remote attackers to

References

#916196 #917100 #917300 #917597

Cross- CVE-2015-0822 CVE-2015-0827 CVE-2015-0831

CVE-2015-0836

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2015-0822.html

https://www.suse.com/security/cve/CVE-2015-0827.html

https://www.suse.com/security/cve/CVE-2015-0831.html

https://www.suse.com/security/cve/CVE-2015-0836.html

https://bugzilla.suse.com/show_bug.cgi?id=916196

https://bugzilla.suse.com/show_bug.cgi?id=917100

https://bugzilla.suse.com/show_bug.cgi?id=917300

https://bugzilla.suse.com/show_bug.cgi?id=917597

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0446-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here