Oval Definition:oval:org.mitre.oval:def:25177
Revision Date:2015-03-16Version:6
Title:SUSE-SU-2014:0638-1 -- Security update for Mozilla Firefox
Description:This Mozilla Firefox and Mozilla NSS update to 24.5.0esr fixes thefollowing several security and non-security issues: * MFSA 2014-34/CVE-2014-1518 Miscellaneous memory safety hazards * MFSA 2014-37/CVE-2014-1523 Out of bounds read while decoding JPGimages * MFSA 2014-38/CVE-2014-1524 Buffer overflow when using non-XBL objectas XBL * MFSA 2014-42/CVE-2014-1529 Privilege escalation through WebNotification API * MFSA 2014-43/CVE-2014-1530 Cross-site scripting (XSS) using historynavigations * MFSA 2014-44/CVE-2014-1531 Use-after-free in imgLoader whileresizing images * MFSA 2014-46/CVE-2014-1532 Use-after-free in nsHostResolverMozilla NSS has been updated to 3.16: * required for Firefox 29 * CVE-2014-1492: In a wildcard certificate, the wildcard charactershould not be embedded within the U-label of an internationalized domainname. See the last bullet point in RFC 6125, Section 7.2. * Update of root certificates.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-1492
CVE-2014-1518
CVE-2014-1520
CVE-2014-1523
CVE-2014-1524
CVE-2014-1529
CVE-2014-1530
CVE-2014-1531
CVE-2014-1532
SUSE-SU-2014:0638-1
Platform(s):SUSE Linux Enterprise Desktop 11
SUSE Linux Enterprise Server 11
Product(s):Mozilla Firefox
Definition Synopsis
  • Operation system section
  • SUSE Linux Enterprise Server 11.x is installed
  • OR SUSE Linux Enterprise Desktop 11.x is installed
  • AND Packages match section
  • MozillaFirefox RPM is earlier than 0:24.5.0esr-0.8.1
  • OR MozillaFirefox-branding-SLED RPM is earlier than 0:24-0.7.36
  • OR MozillaFirefox-translations RPM is earlier than 0:24.5.0esr-0.8.1
  • OR libfreebl3 RPM is earlier than 0:3.16-0.8.1
  • OR libsoftokn3 RPM is earlier than 0:3.16-0.8.1
  • OR mozilla-nspr RPM is earlier than 0:4.10.4-0.3.1
  • OR mozilla-nss RPM is earlier than 0:3.16-0.8.1
  • OR mozilla-nss-tools RPM is earlier than 0:3.16-0.8.1
  • OR libfreebl3-32bit RPM is earlier than 0:3.16-0.8.1
  • OR libsoftokn3-32bit RPM is earlier than 0:3.16-0.8.1
  • OR mozilla-nspr-32bit RPM is earlier than 0:4.10.4-0.3.1
  • OR mozilla-nss-32bit RPM is earlier than 0:3.16-0.8.1
  • BACK