Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

SUSE: 2020:3902-1 Critical: MozillaFirefox Buffer Overflow

suse
Calendar Grey December 21, 2020
Scroller Suse
An important patch for MozillaFirefox released by SUSE tackles multiple security flaws. It is essential to take steps to safeguard your device.
An update that fixes 8 vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 78.6.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-55 (bsc#1180039) * CVE-2020-16042 (bmo#1679003) Operations on a BigInt could have caused uninitialized memory to be exposed * CVE-2020-26971 (bmo#1663466) Heap buffer overflow in WebGL * CVE-2020-26973 (bmo#1680084) CSS Sanitizer performed incorrect sanitization * CVE-2020-26974 (bmo#1681022) Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free * CVE-2020-26978 (bmo#1677047) Internal network hosts could have been probed by a malicious webpage * CVE-2020-35111 (bmo#1657916) The proxy.onRequest API did not catch view-source URLs * CVE-2020-35112 (bmo#1661365) Opening an extension-less download may

References

#1180039

Cross- CVE-2020-16042 CVE-2020-26971 CVE-2020-26973

CVE-2020-26974 CVE-2020-26978 CVE-2020-35111

CVE-2020-35112 CVE-2020-35113

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

https://www.suse.com/security/cve/CVE-2020-16042.html

https://www.suse.com/security/cve/CVE-2020-26971.html

https://www.suse.com/security/cve/CVE-2020-26973.html

https://www.suse.com/security/cve/CVE-2020-26974.html

https://www.suse.com/security/cve/CVE-2020-26978.html

https://www.suse.com/security/cve/CVE-2020-35111.html

https://www.suse.com/security/cve/CVE-2020-35112.html

https://www.suse.com/security/cve/CVE-2020-35113.html

https://bugzilla.suse.com/1180039

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3902-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.