Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2024:4074-1 important: MozillaFirefox security issues

suse
Calendar Grey November 27, 2024
Dist Suse Esm H88
Vital Mozilla Firefox security patches address multiple weaknesses impacting SUSE Linux systems proficiently.
* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692

Summary

## This update for MozillaFirefox fixes the following issues: Firefox Extended Support Release 128.5.0 ESR, fixed various security fixes and other quality improvements, MFSA 2024-64 (bsc#1233695): * CVE-2024-11691: Memory corruption in Apple GPU drivers * CVE-2024-11692: Select list elements could be shown over another site * CVE-2024-11693: Download Protections were bypassed by .library-ms files on Windows * CVE-2024-11694: CSP Bypass and XSS Exposure via Web Compatibility Shims * CVE-2024-11695: URL Bar Spoofing via Manipulated Punycode and Whitespace Characters * CVE-2024-11696: Unhandled Exception in Add-on Signature Verification * CVE-2024-11697: Inproper Keypress Handling in Executable File Confirmation Dialog * CVE-2024-11698: Fullscreen Lock-Up When Modal Dialog Interrupts Transition

References

* bsc#1233695

Cross-

* CVE-2024-11691

* CVE-2024-11692

* CVE-2024-11693

* CVE-2024-11694

* CVE-2024-11695

* CVE-2024-11696

* CVE-2024-11697

* CVE-2024-11698

* CVE-2024-11699

CVSS scores:

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server 12 SP5 LTSS

* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

An update that solves nine vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-11691.html

* https://www.suse.com/security/cve/CVE-2024-11692.html

* https://www.suse.com/security/cve/CVE-2024-11693.html

* https://www.suse.com/security/cve/CVE-2024-11694.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:4074-1
Release Date: 2024-11-27T08:34:27Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here