Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE 2017:2688-1 Important Update: MozillaFirefox and NSS Security Issues

suse
Calendar Grey October 10, 2017
Dist Suse Esm H88
Critical update for SUSE addressing multiple issues in Mozilla Firefox and NSS. Immediate action required.
An update that fixes 9 vulnerabilities is now available

Summary

This update for MozillaFirefox to ESR 52.4, mozilla-nss fixes the following issues: This security issue was fixed for mozilla-nss: - CVE-2017-7805: Prevent use-after-free in TLS 1.2 when generating handshake hashes (bsc#1061005) These security issues were fixed for Firefox - CVE-2017-7825: Fixed some Tibetan and Arabic unicode characters rendering (bsc#1060445). - CVE-2017-7805: Prevent Use-after-free in TLS 1.2 generating handshake hashes (bsc#1060445). - CVE-2017-7819: Prevent Use-after-free while resizing images in design mode (bsc#1060445). - CVE-2017-7818: Prevent Use-after-free during ARIA array manipulation (bsc#1060445). - CVE-2017-7793: Prevent Use-after-free with Fetch API (bsc#1060445). - CVE-2017-7824: Prevent Buffer overflow when drawing and validating

References

#1060445 #1061005

Cross- CVE-2017-7793 CVE-2017-7805 CVE-2017-7810

CVE-2017-7814 CVE-2017-7818 CVE-2017-7819

CVE-2017-7823 CVE-2017-7824 CVE-2017-7825

Affected Products:

SUSE OpenStack Cloud 6

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP3

SUSE Linux Enterprise Desktop 12-SP2

SUSE Container as a Service Platform ALL

https://www.suse.com/security/cve/CVE...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2688-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here