Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE 2016:3210-1 Critical: MozillaFirefox Memory Issues Resolved

suse
Calendar Grey December 21, 2016
Dist Suse Esm H88
A new release for MozillaFirefox from SUSE addresses 10 severe vulnerabilities, boosting user security and optimizing performance.
An update that fixes 10 vulnerabilities is now available

Summary

MozillaFirefox 45 ESR was updated to 45.6 to fix the following issues: * MFSA 2016-95/CVE-2016-9897: Memory corruption in libGLES * MFSA 2016-95/CVE-2016-9901: Data from Pocket server improperly sanitized before execution * MFSA 2016-95/CVE-2016-9898: Use-after-free in Editor while manipulating DOM subtrees * MFSA 2016-95/CVE-2016-9899: Use-after-free while manipulating DOM events and audio elements * MFSA 2016-95/CVE-2016-9904: Cross-origin information leak in shared atoms * MFSA 2016-95/CVE-2016-9905: Crash in EnumerateSubDocuments * MFSA 2016-95/CVE-2016-9895: CSP bypass using marquee tag * MFSA 2016-95/CVE-2016-9900: Restricted external resources can be loaded by SVG images through data URLs * MFSA 2016-95/CVE-2016-9893: Memory safety bugs fixed in Firefox 50.1 and Firefox ESR 45.6

References

#1000751 #1015422

Cross- CVE-2016-9893 CVE-2016-9895 CVE-2016-9897

CVE-2016-9898 CVE-2016-9899 CVE-2016-9900

CVE-2016-9901 CVE-2016-9902 CVE-2016-9904

CVE-2016-9905

Affected Products:

SUSE OpenStack Cloud 5

SUSE Manager Proxy 2.1

SUSE Manager 2.1

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2016-9893.html

https://www.suse.com/security/cve/CVE-2016-9895.html

https://www.suse.com/security/cve/CVE-2016-9897.html

https://www.suse.com/security/cve/CVE-2016-9898.html

https://www.suse.com/security/cve/CVE-...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:3210-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here