Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

SUSE Linux 12: SUSE-SU-2015:0704-2 Critical Security Update

suse
Calendar Grey April 10, 2015
Scroller Suse
Crucial SUSE upgrade for Mozilla Firefox addresses seven security vulnerabilities. Implement update to maintain system security and performance.
An update that fixes 6 vulnerabilities is now available

Summary

Mozilla Firefox was updated to 31.6.0 ESR to fix five security issues. The following vulnerabilities were fixed: * Miscellaneous memory safety hazards (MFSA 2015-30/CVE-2015-0814/CVE-2015-0815) * Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA 2015-31/CVE-2015-0813) * resource:// documents can load privileged pages (MFSA 2015-33/CVE-2015-0816) * CORS requests should not follow 30x redirections after preflight (MFSA 2015-37/CVE-2015-0807) * Same-origin bypass through anchor navigation (MFSA 2015-40/CVE-2015-0801) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2015-165=1

References

#925368

Cross- CVE-2015-0801 CVE-2015-0807 CVE-2015-0813

CVE-2015-0814 CVE-2015-0815 CVE-2015-0816

Affected Products:

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-0801.html

https://www.suse.com/security/cve/CVE-2015-0807.html

https://www.suse.com/security/cve/CVE-2015-0813.html

https://www.suse.com/security/cve/CVE-2015-0814.html

https://www.suse.com/security/cve/CVE-2015-0815.html

https://www.suse.com/security/cve/CVE-2015-0816.html

https://bugzilla.suse.com/show_bug.cgi?id=925368

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0704-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.