Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE 12-SP4: 2019:0852-1 Important: MozillaFirefox DoS Issues

suse
Calendar Grey April 3, 2019
Dist Suse Esm H88
SUSE has released a Security Update that brings vital patches for Mozilla Firefox, tackling various vulnerabilities found within the software.
An update that fixes 15 vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: Security issuess addressed: - update to Firefox ESR 60.6.1 (bsc#1130262): - CVE-2019-9813: Fixed Ionmonkey type confusion with __proto__ mutations - CVE-2019-9810: Fixed IonMonkey MArraySlice incorrect alias information - Update to Firefox ESR 60.6 (bsc#1129821): - CVE-2018-18506: Fixed an issue with Proxy Auto-Configuration file - CVE-2019-9801: Fixed an issue which could allow Windows programs to be exposed to web content - CVE-2019-9788: Fixed multiple memory safety bugs - CVE-2019-9790: Fixed a Use-after-free vulnerability when removing in-use DOM elements - CVE-2019-9791: Fixed an incorrect Type inference for constructors entered through on-stack replacement with IonMonkey

References

#1125330 #1127987 #1129821 #1130262

Cross- CVE-2018-18335 CVE-2018-18356 CVE-2018-18506

CVE-2019-5785 CVE-2019-9788 CVE-2019-9790

CVE-2019-9791 CVE-2019-9792 CVE-2019-9793

CVE-2019-9794 CVE-2019-9795 CVE-2019-9796

CVE-2019-9801 CVE-2019-9810 CVE-2019-9813

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Linux Enterprise Server 12-SP1-LTSS

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0852-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here