This update for MozillaFirefox, mozilla-nspr, mozilla-nss fixes the following issues: Mozilla Firefox was updated to 38.7.0 ESR (bsc#969894) * MFSA 2016-16/CVE-2016-1952/CVE-2016-1953 Miscellaneous memory safety hazards (rv:45.0 / rv:38.7) * MFSA 2016-17/CVE-2016-1954 Local file overwriting and potential privilege escalation through CSP reports * MFSA 2016-20/CVE-2016-1957 A memory leak in libstagefright when deleting an array during MP4 processing was fixed. * MFSA 2016-21/CVE-2016-1958 The displayed page address can be overridden * MFSA 2016-23/CVE-2016-1960 A use-after-free in HTML5 string parser was fixed. * MFSA 2016-24/CVE-2016-1961 A use-after-free in SetBody was fixed. * MFSA 2016-25/CVE-2016-1962 A use-after-free when using multiple WebRTC data channels was fixed.
#969894
Cross- CVE-2016-1950 CVE-2016-1952 CVE-2016-1953
CVE-2016-1954 CVE-2016-1957 CVE-2016-1958
CVE-2016-1960 CVE-2016-1961 CVE-2016-1962
CVE-2016-1964 CVE-2016-1965 CVE-2016-1966
CVE-2016-1974 CVE-2016-1977 CVE-2016-1978
CVE-2016-1979 CVE-2016-2790 CVE-2016-2791
CVE-2016-2792 CVE-2016-2793 CVE-2016-2794
CVE-2016-2795 CVE-2016-2796 CVE-2016-2797
CVE-2016-2798 CVE-2016-2799 CVE-2016-2800
CVE-2016-2801 CVE-2016-2802
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Server 11-SP3-LTSS
SUSE Linux Enterprise Desktop 11-SP4
SUSE Linux Enterprise Debuginfo 11-SP4
SUSE Linux Enterprise Debuginfo 11-SP3
https://www.su...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.