Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2016:2195-1 Important: MozillaFirefox Buffer Overflow Fix

suse
Calendar Grey August 30, 2016
Dist Suse Esm H88
SUSE Security Patch tackles 12 critical vulnerabilities in MozillaFirefox, improving both resilience and protection for its users.
An update that fixes 15 vulnerabilities is now available

Summary

MozillaFirefox was updated to 45.3.0 ESR to fix the following issues (bsc#991809): * MFSA 2016-62/CVE-2016-2835/CVE-2016-2836 Miscellaneous memory safety hazards (rv:48.0 / rv:45.3) * MFSA 2016-63/CVE-2016-2830 Favicon network connection can persist when page is closed * MFSA 2016-64/CVE-2016-2838 Buffer overflow rendering SVG with bidirectional content * MFSA 2016-65/CVE-2016-2839 Cairo rendering crash due to memory allocation issue with FFmpeg 0.10 * MFSA 2016-67/CVE-2016-5252 Stack underflow during 2D graphics rendering * MFSA 2016-70/CVE-2016-5254 Use-after-free when using alt key and toplevel menus * MFSA 2016-72/CVE-2016-5258 Use-after-free in DTLS during WebRTC session shutdown * MFSA 2016-73/CVE-2016-5259 Use-after-free in service workers with nested sync events

References

#989196 #990628 #990856 #991809

Cross- CVE-2016-2830 CVE-2016-2835 CVE-2016-2836

CVE-2016-2837 CVE-2016-2838 CVE-2016-2839

CVE-2016-5252 CVE-2016-5254 CVE-2016-5258

CVE-2016-5259 CVE-2016-5262 CVE-2016-5263

CVE-2016-5264 CVE-2016-5265 CVE-2016-6354

Affected Products:

SUSE OpenStack Cloud 5

SUSE Manager Proxy 2.1

SUSE Manager 2.1

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2016-2830.html

https://www.suse.com/security/cve/CVE-2016-2835.html

https://www.suse.com/secur...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2195-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here