Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:1861-2 Important: MozillaFirefox Security Update

suse
Calendar Grey July 29, 2019
Dist Suse Esm H88
Update released by SUSE addresses 12 vulnerabilities in MozillaFirefox, strengthening protection for those using OpenStack. Take action now!
An update that fixes 10 vulnerabilities is now available

Summary

This update for MozillaFirefox, mozilla-nss fixes the following issues: MozillaFirefox to version ESR 60.8: - CVE-2019-9811: Sandbox escape via installation of malicious language pack (bsc#1140868). - CVE-2019-11711: Script injection within domain through inner window reuse (bsc#1140868). - CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects (bsc#1140868). - CVE-2019-11713: Use-after-free with HTTP/2 cached stream (bsc#1140868). - CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault (bsc#1140868). - CVE-2019-11715: HTML parsing error can contribute to content XSS (bsc#1140868). - CVE-2019-11717: Caret character improperly escaped in origins (bsc#1140868).

References

#1140868

Cross- CVE-2019-11709 CVE-2019-11711 CVE-2019-11712

CVE-2019-11713 CVE-2019-11715 CVE-2019-11717

CVE-2019-11719 CVE-2019-11729 CVE-2019-11730

CVE-2019-9811

Affected Products:

SUSE OpenStack Cloud Crowbar 8

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2019-11709.html

https://www.suse.com/security/cve/CVE-2019-11711.html

https://www.suse.com/security/cve/CVE-2019-11712.html

https://www.suse.com/security/cve/CVE-2019-11713.html

https://www.suse.com/security/cve/CVE-2019-11715.html

https://www.suse.com/security/cve/CVE-2019-11717.html

https://www.suse.com/security/cve/CVE-2019-11719.html

https://www.suse.com/security/cve/CVE-2019-11729.html

https://www.suse.com/security/cve/CVE-2019-11730.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1861-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here