Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2021:0234-1 Urgent: Exploitation Risk from Mozilla Firefox Issues

suse
Calendar Grey March 15, 2016
Dist Suse Esm H88
Tackling 29 critical vulnerabilities in Google Chrome and associated elements to ensure systems remain protected and current.
An update that fixes 29 vulnerabilities is now available

Summary

This update for MozillaFirefox, mozilla-nspr, mozilla-nss fixes the following issues: Mozilla Firefox was updated to 38.7.0 ESR (bsc#969894) * MFSA 2016-16/CVE-2016-1952/CVE-2016-1953 Miscellaneous memory safety hazards (rv:45.0 / rv:38.7) * MFSA 2016-17/CVE-2016-1954 Local file overwriting and potential privilege escalation through CSP reports * MFSA 2016-20/CVE-2016-1957 A memory leak in libstagefright when deleting an array during MP4 processing was fixed. * MFSA 2016-21/CVE-2016-1958 The displayed page address can be overridden * MFSA 2016-23/CVE-2016-1960 A use-after-free in HTML5 string parser was fixed. * MFSA 2016-24/CVE-2016-1961 A use-after-free in SetBody was fixed. * MFSA 2016-25/CVE-2016-1962 A use-after-free when using multiple WebRTC data channels was fixed.

References

#969894

Cross- CVE-2016-1950 CVE-2016-1952 CVE-2016-1953

CVE-2016-1954 CVE-2016-1957 CVE-2016-1958

CVE-2016-1960 CVE-2016-1961 CVE-2016-1962

CVE-2016-1964 CVE-2016-1965 CVE-2016-1966

CVE-2016-1974 CVE-2016-1977 CVE-2016-1978

CVE-2016-1979 CVE-2016-2790 CVE-2016-2791

CVE-2016-2792 CVE-2016-2793 CVE-2016-2794

CVE-2016-2795 CVE-2016-2796 CVE-2016-2797

CVE-2016-2798 CVE-2016-2799 CVE-2016-2800

CVE-2016-2801 CVE-2016-2802

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Desktop 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.su...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0777-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here