Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE 12 SP4: Important Update - Mozilla Firefox Security Flaw Alert

suse
Calendar Grey June 1, 2015
Dist Suse Esm H88
New version of Mozilla Firefox launched to tackle various bugs, bolster security measures, and optimize performance on SUSE platforms.
An update that fixes 6 vulnerabilities is now available

Summary

This update to Firefox 31.7.0 ESR fixes the following issues: * MFSA 2015-46 (CVE-2015-2708, CVE-2015-2709): Miscellaneous memory safety hazards (rv:38.0 / rv:31.7). Upstream references: bmo#1120655, bmo#1143299, bmo#1151139, bmo#1152177, bmo#1111251, bmo#1117977, bmo#1128064, bmo#1135066, bmo#1143194, bmo#1146101, bmo#1149526, bmo#1153688, bmo#1155474. * MFSA 2015-47 (CVE-2015-0797): Buffer overflow parsing H.264 video with Linux Gstreamer. Upstream references: bmo#1080995. * MFSA 2015-48 (CVE-2015-2710): Buffer overflow with SVG content and CSS. Upstream references: bmo#1149542. * MFSA 2015-51 (CVE-2015-2713): Use-after-free during text processing with vertical text enabled. Upstream references: bmo#1153478. * MFSA 2015-54 (CVE-2015-2716): Buffer overflow when parsing

References

#930622

Cross- CVE-2015-0797 CVE-2015-2708 CVE-2015-2709

CVE-2015-2710 CVE-2015-2713 CVE-2015-2716

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2015-0797.html

https://www.suse.com/security/cve/CVE-2015-2708.html

https://www.suse.com/security/cve/CVE-2015-2709.html

https://www.suse.com/security/cve/CVE-2015-2710.html

https://www.suse.com/security/cve/CVE-2015-2713.html

https://www.suse.com/security/cve/CVE-2015-2716.html

https://bugzilla.suse.com/show_bug.cgi?id=930622

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0978-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here