Oval Definition:oval:org.mitre.oval:def:25088
Revision Date:2014-09-08Version:4
Title:SUSE-SU-2013:1497-1 -- Security update for Mozilla Firefox
Description:This update to Firefox 17.0.9esr (bnc#840485) addresses: * MFSA 2013-91 User-defined properties on DOM proxiesget the wrong "this" object o (CVE-2013-1737) * MFSA 2013-90 Memory corruption involving scrolling ouse-after-free in mozilla::layout::ScrollbarActivity(CVE-2013-1735) o Memory corruption innsGfxScrollFrameInner::IsLTR() (CVE-2013-1736) * MFSA 2013-89 Buffer overflow with multi-column,lists, and floats o buffer overflow atnsFloatManager::GetFlowArea() with multicol, list, floats(CVE-2013-1732) * MFSA 2013-88 compartment mismatch re-attachingXBL-backed nodes o compartment mismatch innsXBLBinding::DoInitJSClass (CVE-2013-1730) * MFSA 2013-83 Mozilla Updater does not lock MAR fileafter signature verification o MAR signature bypass inUpdater could lead to downgrade (CVE-2013-1726) * MFSA 2013-82 Calling scope for new Javascript objectscan lead to memory corruption o ABORT: bad scope for newJSObjects: ReparentWrapper / document.open (CVE-2013-1725) * MFSA 2013-79 Use-after-free in Animation Managerduring stylesheet cloning o Heap-use-after-free innsAnimationManager::BuildAnimations (CVE-2013-1722) * MFSA 2013-76 Miscellaneous memory safety hazards(rv:24.0 / rv:17.0.9) o Memory safety bugs fixed in Firefox17.0.9 and Firefox 24.0 (CVE-2013-1718) * MFSA 2013-65 Buffer underflow when generating CRMFrequests o ASAN heap-buffer-overflow (read 1) incryptojs_interpret_key_gen_type (CVE-2013-1705)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-1705
CVE-2013-1718
CVE-2013-1722
CVE-2013-1725
CVE-2013-1726
CVE-2013-1730
CVE-2013-1732
CVE-2013-1735
CVE-2013-1736
CVE-2013-1737
SUSE-SU-2013:1497-1
Platform(s):SUSE Linux Enterprise Desktop 11
SUSE Linux Enterprise Server 11
Product(s):Mozilla Firefox
Definition Synopsis
  • Operation system section
  • SUSE Linux Enterprise Server 11.x is installed
  • OR SUSE Linux Enterprise Desktop 11.x is installed
  • AND Packages match section
  • MozillaFirefox RPM is earlier than 0:17.0.9esr-0.7.1
  • OR MozillaFirefox-translations RPM is earlier than 0:17.0.9esr-0.7.1
  • OR MozillaFirefox RPM is earlier than 0:17.0.9esr-0.3.1
  • OR MozillaFirefox-translations RPM is earlier than 0:17.0.9esr-0.3.1
  • BACK