Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE: 2020:3901-1 Critical: MozillaFirefox Buffer Overflow Risks

suse
Calendar Grey December 21, 2020
Scroller Suse
Important security enhancement for Firefox on SUSE tackling 8 vulnerabilities. Implement the update immediately for better protection.
An update that fixes 8 vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 78.6.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-55 (bsc#1180039) * CVE-2020-16042 (bmo#1679003) Operations on a BigInt could have caused uninitialized memory to be exposed * CVE-2020-26971 (bmo#1663466) Heap buffer overflow in WebGL * CVE-2020-26973 (bmo#1680084) CSS Sanitizer performed incorrect sanitization * CVE-2020-26974 (bmo#1681022) Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free * CVE-2020-26978 (bmo#1677047) Internal network hosts could have been probed by a malicious webpage * CVE-2020-35111 (bmo#1657916) The proxy.onRequest API did not catch view-source URLs * CVE-2020-35112 (bmo#1661365) Opening an extension-less download may

References

#1180039

Cross- CVE-2020-16042 CVE-2020-26971 CVE-2020-26973

CVE-2020-26974 CVE-2020-26978 CVE-2020-35111

CVE-2020-35112 CVE-2020-35113

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15-SP2

https://www.suse.com/security/cve/CVE-2020-16042.html

https://www.suse.com/security/cve/CVE-2020-26971.html

https://www.suse.com/security/cve/CVE-2020-26973.html

https://www.suse.com/security/cve/CVE-2020-26974.html

https://www.suse.com/security/cve/CVE-2020-26978.html

https://www.suse.com/security/cve/CVE-2020-35111.html

https://www.suse.com/security/cve/CVE-2020-35112.html

https://www.suse.com/security/cve/CVE-2020-35113.html

https://bugzilla.suse.com/1180039

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3901-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.