Description: | This Mozilla Firefox and Mozilla NSS update to 24.5.0esr fixes thefollowing several security and non-security issues: * MFSA 2014-34/CVE-2014-1518 Miscellaneous memory safety hazards * MFSA 2014-37/CVE-2014-1523 Out of bounds read while decoding JPGimages * MFSA 2014-38/CVE-2014-1524 Buffer overflow when using non-XBL objectas XBL * MFSA 2014-42/CVE-2014-1529 Privilege escalation through WebNotification API * MFSA 2014-43/CVE-2014-1530 Cross-site scripting (XSS) using historynavigations * MFSA 2014-44/CVE-2014-1531 Use-after-free in imgLoader whileresizing images * MFSA 2014-46/CVE-2014-1532 Use-after-free in nsHostResolverMozilla NSS has been updated to 3.16: * required for Firefox 29 * CVE-2014-1492: In a wildcard certificate, the wildcard charactershould not be embedded within the U-label of an internationalized domainname. See the last bullet point in RFC 6125, Section 7.2. * Update of root certificates. |