Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2018:3476-1 Important: MozillaFirefox Remote Code Execution Fix

suse
Calendar Grey October 26, 2018
Dist Suse Esm H88
SUSE has rolled out a Security Update addressing four major vulnerabilities in Mozilla Firefox, providing necessary patches for all affected users.
An update that solves four vulnerabilities and has two fixes is now available

Summary

This update for MozillaFirefox to 60.2.2ESR fixes the following issues: Security issues fixed: MFSA 2018-24: - CVE-2018-12386: A Type confusion in JavaScript allowed remote code execution (bsc#1110506) - CVE-2018-12387: Array.prototype.push stack pointer vulnerability may have enabled exploits in the sandboxed content process (bsc#1110507) MFSA 2018-23: - CVE-2018-12385: Fixed a crash in TransportSecurityInfo due to cached data (bsc#1109363) - CVE-2018-12383: Setting a master password did not delete unencrypted previously stored passwords (bsc#1107343) Non security issues fixed: - Avoid undefined behavior in IPC fd-passing code (bsc#1094767) - Fixed a startup crash affecting users migrating from older ESR releases - Clean up old NSS DB files after upgrading

References

#1094767 #1107343 #1109363 #1109465 #1110506

#1110507

Cross- CVE-2018-12383 CVE-2018-12385 CVE-2018-12386

CVE-2018-12387

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2018-12383.html

https://www.suse.com/security/cve/CVE-2018-12385.html

https://www.suse.com/security/cve/CVE-2018-12386.html

https://www.suse.com/security/cve/CVE-2018-12387.html

https://bugzilla.suse.com/1094767

https://bugzilla.suse.com/1107343

https://bugzilla.suse.com/1109363

https://bugzilla.suse.com/1109465

https://bugzilla.suse.com/1110506

https://bugzilla.suse.com/1110507

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:3476-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here