Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2024:0580-1 Important Update for MozillaFirefox Memory Issues

suse
Calendar Grey February 21, 2024
Dist Suse Esm H88
The recent MozillaFirefox security patch for SUSE addresses numerous vulnerabilities and enhances overall protection. Immediate installation is advised.
* bsc#1184272 * bsc#1220048 Cross-References: * CVE-2024-1546

Summary

## This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.8.0 ESR (MFSA 2024-06) (bsc#1220048): * CVE-2024-1546: Out-of-bounds memory read in networking channels * CVE-2024-1547: Alert dialog could have been spoofed on another site * CVE-2024-1548: Fullscreen Notification could have been hidden by select element * CVE-2024-1549: Custom cursor could obscure the permission dialog * CVE-2024-1550: Mouse cursor re-positioned unexpectedly could have led to unintended permission grants * CVE-2024-1551: Multipart HTTP Responses would accept the Set-Cookie header in response parts * CVE-2024-1552: Incorrect code generation on 32-bit ARM devices * CVE-2024-1553: Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8

References

* bsc#1184272

* bsc#1220048

Cross-

* CVE-2024-1546

* CVE-2024-1547

* CVE-2024-1548

* CVE-2024-1549

* CVE-2024-1550

* CVE-2024-1551

* CVE-2024-1552

* CVE-2024-1553

CVSS scores:

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

* SUSE Linux Enterprise Software Development Kit 12 SP5

An update that solves eight vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-1546.html

* https://www.suse.com/security/cve/CVE-2024-1547.html

* https://www.suse.com/security/cve/CVE-2024-1548.html

* https://www.suse.com/security/cve/CVE-2024-1549.html

* https://www.suse.com/security/cve/CVE-2024-1550.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:0580-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here