Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2019:1629-1 Important: Type Confusion in MozillaFirefox

suse
Calendar Grey June 21, 2019
Dist Suse Esm H88
SUSE Security Update for GoogleChrome resolves critical remote code execution vulnerability, refer to advisory SUSE-SU-2021:2045-1.
An update that solves one vulnerability and has one errata is now available

Summary

This update for MozillaFirefox to version 60.7.1 fixes the following issues: Security issue fixed: - CVE-2019-11707: Fixed a type confusion vulnerability in Arrary.pop (bsc#1138614) Other issues addressed: - Added the new Mozilla's GPG key expiring on 2021-05-29 to the mozilla.keyring file - Fixed broken language plugins (bsc#1137792) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-1629=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15:

References

#1137792 #1138614

Cross- CVE-2019-11707

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2019-11707.html

https://bugzilla.suse.com/1137792

https://bugzilla.suse.com/1138614

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1629-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here