Oval Definition:oval:org.mitre.oval:def:25227
Revision Date:2015-03-16Version:7
Title:SUSE-SU-2014:0638-2 -- Security update for Mozilla Firefox
Description:This MozillaFirefox and mozilla-nss update fixes several security andnon-security issues.MozillaFirefox has been updated to version 24.5.0esr which fixes thefollowing issues: * MFSA 2014-34/CVE-2014-1518 Miscellaneous memory safety hazards * MFSA 2014-37/CVE-2014-1523 Out of bounds read while decoding JPG images * MFSA 2014-38/CVE-2014-1524 Buffer overflow when using non-XBL object as XBL * MFSA 2014-42/CVE-2014-1529 Privilege escalation through Web Notification API * MFSA 2014-43/CVE-2014-1530 Cross-site scripting (XSS) using history navigations * MFSA 2014-44/CVE-2014-1531 Use-after-free in imgLoader while resizing images * MFSA 2014-46/CVE-2014-1532 Use-after-free in nsHostResolverMozilla NSS has been updated to version 3.16 * required for Firefox 29 * CVE-2014-1492_ In a wildcard certificate, the wildcard character should not be embedded within the U-label of an internationalized domain name. See the last bullet point in RFC 6125, Section 7.2. * Update of root certificates.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-1492
CVE-2014-1518
CVE-2014-1520
CVE-2014-1523
CVE-2014-1524
CVE-2014-1529
CVE-2014-1530
CVE-2014-1531
CVE-2014-1532
SUSE-SU-2014:0638-2
Platform(s):SUSE Linux Enterprise Server 11
Product(s):Mozilla Firefox
Definition Synopsis
  • SUSE Linux Enterprise Server 11.x is installed
  • AND Packages match section
  • MozillaFirefox RPM is earlier than 0:24.5.0esr-0.3.1
  • OR MozillaFirefox-branding-SLED RPM is earlier than 0:24-0.4.10.14
  • OR MozillaFirefox-translations RPM is earlier than 0:24.5.0esr-0.3.1
  • OR libfreebl3 RPM is earlier than 0:3.16-0.3.1
  • OR mozilla-nspr RPM is earlier than 0:4.10.4-0.3.1
  • OR mozilla-nspr-devel RPM is earlier than 0:4.10.4-0.3.1
  • OR mozilla-nss RPM is earlier than 0:3.16-0.3.1
  • OR mozilla-nss-devel RPM is earlier than 0:3.16-0.3.1
  • OR mozilla-nss-tools RPM is earlier than 0:3.16-0.3.1
  • OR libfreebl3-32bit RPM is earlier than 0:3.16-0.3.1
  • OR mozilla-nspr-32bit RPM is earlier than 0:4.10.4-0.3.1
  • OR mozilla-nss-32bit RPM is earlier than 0:3.16-0.3.1
  • BACK