Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE: 2018:1334-1 Important: MozillaFirefox Security Update Overview

suse
Calendar Grey May 18, 2018
Scroller Suse
SUSE Security Patch for MozillaFirefox addresses 10 vulnerabilities. See Announcement ID: SUSE-SU-2018:1334-2 for further information.
An update that fixes 10 vulnerabilities is now available

Summary

This update for MozillaFirefox to the ESR 52.8 release fixes the following issues: Mozil to Firefox ESR 52.8 (bsc#1092548) Security issues fixed: - MFSA 2018-12/CVE-2018-5159: Integer overflow and out-of-bounds write in Skia - MFSA 2018-12/CVE-2018-5158: Malicious PDF can inject JavaScript into PDF Viewer - MFSA 2018-12/CVE-2018-5168: Lightweight themes can be installed without user interaction - MFSA 2018-12/CVE-2018-5150: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8 - MFSA 2018-12/CVE-2018-5155: Use-after-free with SVG animations and text paths - MFSA 2018-12/CVE-2018-5183: Backport critical security fixes in Skia - MFSA 2018-12/CVE-2018-5157: Same-origin bypass of PDF Viewer to view protected PDF files - MFSA 2018-12/CVE-2018-5154: Use-after-free with SVG animations and clip paths

References

#1092548

Cross- CVE-2018-5150 CVE-2018-5154 CVE-2018-5155

CVE-2018-5157 CVE-2018-5158 CVE-2018-5159

CVE-2018-5168 CVE-2018-5174 CVE-2018-5178

CVE-2018-5183

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP3

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2018-5150.html

https://www.suse.com/security/cve/CVE-2018-5154.html

https://www.suse.com/security/cve/CVE-2018-5155.html

https://www.sus...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:1334-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.