Oval Definition:oval:org.mitre.oval:def:24995
Revision Date:2014-09-08Version:4
Title:SUSE-SU-2013:1382-1 -- Security update for Mozilla Firefox
Description:Update to Firefox 17.0.8esr (bnc#833389) to address: * MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 (bmo#855331,bmo#844088, bmo#858060, bmo#870200, bmo#874974, bmo#861530,bmo#854157, bmo#893684, bmo#878703, bmo#862185, bmo#879139,bmo#888107, bmo#880734) Miscellaneous memory safety hazards(rv:23.0 / rv:17.0.8) * MFSA 2013-66/CVE-2013-1706/CVE-2013-1707 (bmo#888314,bmo#888361) Buffer overflow in Mozilla Maintenance Serviceand Mozilla Updater * MFSA 2013-68/CVE-2013-1709 (bmo#848253) Document URImisrepresentation and masquerading * MFSA 2013-69/CVE-2013-1710 (bmo#871368) CRMF requestsallow for code execution and XSS attacks * MFSA 2013-71/CVE-2013-1712 (bmo#859072) FurtherPrivilege escalation through Mozilla Updater * MFSA 2013-72/CVE-2013-1713 (bmo#887098) Wrongprincipal used for validating URI for some Javascriptcomponents * MFSA 2013-73/CVE-2013-1714 (bmo#879787) Same-originbypass with web workers and XMLHttpRequest * MFSA 2013-75/CVE-2013-1717 (bmo#406541) Local Javaapplets may read contents of local file system
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-1701
CVE-2013-1702
CVE-2013-1706
CVE-2013-1707
CVE-2013-1709
CVE-2013-1710
CVE-2013-1712
CVE-2013-1713
CVE-2013-1714
CVE-2013-1717
SUSE-SU-2013:1382-1
Platform(s):SUSE Linux Enterprise Server 10
Product(s):Mozilla Firefox
Definition Synopsis
  • SUSE Linux Enterprise Server 10 is installed
  • AND Packages match section
  • MozillaFirefox RPM is earlier than 0:17.0.8esr-0.5.1
  • OR MozillaFirefox-translations RPM is earlier than 0:17.0.8esr-0.5.1
  • BACK