Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2020:14502-1 Important: MozillaFirefox Memory Safety Update

suse
Calendar Grey September 28, 2020
Dist Suse Esm H88
Debian Security Advisory tackles various vulnerabilities in Chrome; essential for users to apply updates without delay.
An update that fixes four vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: - Firefox was updated to 78.3.0 ESR (bsc#1176756, MFSA 2020-43) - CVE-2020-15677: Download origin spoofing via redirect - CVE-2020-15676: Fixed an XSS when pasting attacker-controlled data into a contenteditable element - CVE-2020-15678: When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free scenario - CVE-2020-15673: Fixed memory safety bugs - Attempt to fix langpack-parallelization by introducing separate obj-dirs for each lang (bsc#1173986, bsc#1167976) - Fixed problems with compiler builtins on SLE-11 (bsc#1175046) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1167976 #1173986 #1175046 #1176756

Cross- CVE-2020-15673 CVE-2020-15676 CVE-2020-15677

CVE-2020-15678

Affected Products:

SUSE Linux Enterprise Server 11-SP4-LTSS

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2020-15673.html

https://www.suse.com/security/cve/CVE-2020-15676.html

https://www.suse.com/security/cve/CVE-2020-15677.html

https://www.suse.com/security/cve/CVE-2020-15678.html

https://bugzilla.suse.com/1167976

https://bugzilla.suse.com/1173986

https://bugzilla.suse.com/1175046

https://bugzilla.suse.com/1176756

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:14502-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here