Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: 2019:14246-1 Important: Mozilla Firefox Patch and Fixes

suse
Calendar Grey December 11, 2019
Dist Suse Esm H88
A significant SUSE upgrade for Mozilla Firefox addresses 118 vulnerabilities and improves internet safety. Find the update guidelines here.
An update that fixes 118 vulnerabilities is now available

Summary

This update contains the Mozilla Firefox ESR 68.2 release. Mozilla Firefox was updated to ESR 68.2 release: * Enterprise: New administrative policies were added. More information and templates are available at the Policy Templates page. * Various security fixes: MFSA 2019-33 (bsc#1154738) * CVE-2019-15903: Heap overflow in expat library in XML_GetCurrentLineNumber * CVE-2019-11757: Use-after-free when creating index updates in IndexedDB * CVE-2019-11758: Potentially exploitable crash due to 360 Total Security * CVE-2019-11759: Stack buffer overflow in HKDF output * CVE-2019-11760: Stack buffer overflow in WebRTC networking * CVE-2019-11761: Unintended access to a privileged JSONView object * CVE-2019-11762: document.domain-based origin isolation has same-origin- property violation

References

#1000036 #1001652 #1025108 #1029377 #1029902

#1040164 #104105 #1042670 #1043008 #1044946

#1047925 #1047936 #1048299 #1049186 #1050653

#1056058 #1058013 #1066242 #1066953 #1070738

#1070853 #1072320 #1072322 #1073796 #1073798

#1073799 #1073803 #1073808 #1073818 #1073823

#1073829 #1073830 #1073832 #1073846 #1074235

#1077230 #1079761 #1081750 #1082318 #1087453

#1087459 #1087463 #1088573 #1091764 #1094814

#1097158 #1097375 #1097401 #1097404 #1097748

#1104841 #1105019 #1107030 #1109465 #1117473

#1117626 #1117627 #1117629 #1117630 #1120644

#1122191 #1123482 #1124525 #1127532 #1129346

#1130694 #1130840 #1133452 #1133810 #1134209

#1138459 #1140290 #1140868 #1141853 #1144919

#1145665 #1146...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:14246-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here