Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2017:1669-1 Important: MozillaFirefox Security Update

suse
Calendar Grey June 26, 2017
Dist Suse Esm H88
SUSE Security Advisory: Critical MozillaFirefox patch addressing 50 vulnerabilities impacting numerous SUSE offerings.
An update that fixes 50 vulnerabilities is now available

Summary

The MozillaFirefox was updated to the new ESR 52.2 release, which fixes the following issues (bsc#1043960): * MFSA 2017-16/CVE-2017-7758 Out-of-bounds read in Opus encoder * MFSA 2017-16/CVE-2017-7749 Use-after-free during docshell reloading * MFSA 2017-16/CVE-2017-7751 Use-after-free with content viewer listeners * MFSA 2017-16/CVE-2017-5472 Use-after-free using destroyed node when regenerating trees * MFSA 2017-16/CVE-2017-5470 Memory safety bugs fixed in Firefox 54 and Firefox ESR 52.2 * MFSA 2017-16/CVE-2017-7752 Use-after-free with IME input * MFSA 2017-16/CVE-2017-7750 Use-after-free with track elements * MFSA 2017-16/CVE-2017-7768 32 byte arbitrary file read through Mozilla Maintenance Service * MFSA 2017-16/CVE-2017-7778 Vulnerabilities in the Graphite 2 library

References

#1035082 #1043960

Cross- CVE-2016-10196 CVE-2017-5429 CVE-2017-5430

CVE-2017-5432 CVE-2017-5433 CVE-2017-5434

CVE-2017-5435 CVE-2017-5436 CVE-2017-5438

CVE-2017-5439 CVE-2017-5440 CVE-2017-5441

CVE-2017-5442 CVE-2017-5443 CVE-2017-5444

CVE-2017-5445 CVE-2017-5446 CVE-2017-5447

CVE-2017-5448 CVE-2017-5449 CVE-2017-5451

CVE-2017-5454 CVE-2017-5455 CVE-2017-5456

CVE-2017-5459 CVE-2017-5460 CVE-2017-5461

CVE-2017-5462 CVE-2017-5464 CVE-2017-5465

CVE-2017-5466 CVE-2017-5467 CVE-2017-5469

CVE-2017-5470 CVE-2017-5472 CVE-2017-7749

CVE-2017-7750 CVE-2017-7751 CVE-2017-7752

CVE-2017-7754 CVE-2017-7755 CVE-2017-7756

CVE-2017-7757 CVE-2017-7758 CVE-2017-7761

CVE-2017-7763 CVE-2017-7764 CVE-2017-7765

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1669-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here