Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2017:0521-2 Critical: Mozilla Firefox Buffer Overflow

suse
Calendar Grey March 11, 2016
Scroller Suse
A significant update from SUSE rectifies several security flaws in Mozilla software, delivering essential patches. Ensure to upgrade your systems promptly.
An update that fixes 29 vulnerabilities is now available

Summary

This update for MozillaFirefox, mozilla-nspr, mozilla-nss fixes the following issues: Mozilla Firefox was updated to 38.7.0 ESR (bsc#969894), fixing following security issues: * MFSA 2016-16/CVE-2016-1952/CVE-2016-1953 Miscellaneous memory safety hazards (rv:45.0 / rv:38.7) * MFSA 2016-17/CVE-2016-1954 Local file overwriting and potential privilege escalation through CSP reports * MFSA 2016-20/CVE-2016-1957 Memory leak in libstagefright when deleting an array during MP4 processing * MFSA 2016-21/CVE-2016-1958 Displayed page address can be overridden * MFSA 2016-23/CVE-2016-1960 Use-after-free in HTML5 string parser * MFSA 2016-24/CVE-2016-1961 Use-after-free in SetBody * MFSA 2016-25/CVE-2016-1962 Use-after-free when using multiple WebRTC data channels

References

#969894

Cross- CVE-2016-1950 CVE-2016-1952 CVE-2016-1953

CVE-2016-1954 CVE-2016-1957 CVE-2016-1958

CVE-2016-1960 CVE-2016-1961 CVE-2016-1962

CVE-2016-1964 CVE-2016-1965 CVE-2016-1966

CVE-2016-1974 CVE-2016-1977 CVE-2016-1978

CVE-2016-1979 CVE-2016-2790 CVE-2016-2791

CVE-2016-2792 CVE-2016-2793 CVE-2016-2794

CVE-2016-2795 CVE-2016-2796 CVE-2016-2797

CVE-2016-2798 CVE-2016-2799 CVE-2016-2800

CVE-2016-2801 CVE-2016-2802

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP1

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12-SP1

SUSE Linux Enterprise Desktop 12

https://www.suse.c...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0727-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.