Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE 2019:1682-1 Important: MozillaFirefox Sandbox Escape Issue

suse
Calendar Grey June 22, 2019
Dist Suse Esm H88
SUSE Security Update tackles a critical MozillaFirefox vulnerability, implementing significant improvements to safeguard users and mitigate potential threats.
An update that fixes one vulnerability is now available

Summary

This update for MozillaFirefox fixes the following issues: - Mozilla Firefox Firefox 60.7.2 MFSA 2019-19 (bsc#1138872) - CVE-2019-11708: Fix sandbox escape using Prompt:Open. * Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes could result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1:

References

#1138872

Cross- CVE-2019-11708

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2019-11708.html

https://bugzilla.suse.com/1138872

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1682-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here