Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:0383-1 Important: MozillaFirefox Security Issues Fixed

suse
Calendar Grey February 17, 2020
Dist Suse Esm H88
This release tackles several key vulnerabilities in GoogleChrome, emphasizing enhancements for resource integrity and prevention of unauthorized code deployment.
An update that fixes 5 vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 68.5.0 ESR * Fixed: Various stability and security fixes - Mozilla Firefox ESR68.5 MFSA 2020-06 (bsc#1163368) * CVE-2020-6796 (bmo#1610426) Missing bounds check on shared memory read in the parent process * CVE-2020-6797 (bmo#1596668) Extensions granted downloads.open permission could open arbitrary applications on Mac OSX * CVE-2020-6798 (bmo#1602944) Incorrect parsing of template tag could result in JavaScript injection * CVE-2020-6799 (bmo#1606596) Arbitrary code execution when opening pdf links from other applications, when Firefox is configured as default pdf reader * CVE-2020-6800 (bmo#1595786, bmo#1596706, bmo#1598543, bmo#1604851,

References

#1163368

Cross- CVE-2020-6796 CVE-2020-6797 CVE-2020-6798

CVE-2020-6799 CVE-2020-6800

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2020-6796.html

https://www.suse.com/security/cve/CVE-2020-6797.html

https://www.suse.com/security/cve/CVE-2020-6798.html

https://www.suse.com/security/cve/CVE-2020-6799.html

https://www.suse.com/security/cve/CVE-2020-6800.html

https://bugzilla.suse.com/1163368

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0383-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here