Oval Definition:oval:org.opensuse.security:def:55574
Revision Date:2020-12-01Version:1
Title:Security update for MozillaFirefox, mozilla-nss (Important)
Description:



Mozilla Firefox was updated to version 38.2.1 ESR to fix several critical and non critical security vulnerabilities.

- Firefox was updated to 38.2.1 ESR (bsc#943608) * MFSA 2015-94/CVE-2015-4497 (bsc#943557) Use-after-free when resizing canvas element during restyling * MFSA 2015-95/CVE-2015-4498 (bsc#943558) Add-on notification bypass through data URLs

- Firefox was updated to 38.2.0 ESR (bsc#940806) * MFSA 2015-78/CVE-2015-4495 (bmo#1178058, bmo#1179262) Same origin violation and local file stealing via PDF reader * MFSA 2015-79/CVE-2015-4473/CVE-2015-4474 (bmo#1143130, bmo#1161719, bmo#1177501, bmo#1181204, bmo#1184068, bmo#1188590, bmo#1146213, bmo#1178890, bmo#1182711) Miscellaneous memory safety hazards (rv:40.0 / rv:38.2) * MFSA 2015-80/CVE-2015-4475 (bmo#1175396) Out-of-bounds read with malformed MP3 file * MFSA 2015-82/CVE-2015-4478 (bmo#1105914) Redefinition of non-configurable JavaScript object properties * MFSA 2015-83/CVE-2015-4479 (bmo#1185115, bmo#1144107, bmo#1170344, bmo#1186718) Overflow issues in libstagefright * MFSA 2015-87/CVE-2015-4484 (bmo#1171540) Crash when using shared memory in JavaScript * MFSA 2015-88/CVE-2015-4491 (bmo#1184009) Heap overflow in gdk-pixbuf when scaling bitmap images * MFSA 2015-89/CVE-2015-4485/CVE-2015-4486 (bmo#1177948, bmo#1178148) Buffer overflows on Libvpx when decoding WebM video * MFSA 2015-90/CVE-2015-4487/CVE-2015-4488/CVE-2015-4489 (bmo#1176270, bmo#1182723, bmo#1171603) Vulnerabilities found through code inspection * MFSA 2015-92/CVE-2015-4492 (bmo#1185820) Use-after-free in XMLHttpRequest with shared workers

Mozilla NSS switched the CKBI ABI from 1.98 to 2.4, which is what Firefox 38ESR uses.
Family:unixClass:patch
Status:Reference(s):1035596
1048942
1051510
1053153
1063671
1064392
1066471
1066472
1069708
1076962
1078248
1079730
1081741
1082635
1089644
1091041
1096890
1098403
1099720
1103411
1106222
1108043
1108474
1110910
1111006
1111010
1111013
1111025
1113722
1114279
1114422
1114529
1117169
1124357
1127077
1131107
1134880
1135902
1136528
1136777
1138039
1139926
1140402
1140948
1141043
1143706
1143794
1144333
1149448
1150466
1151548
1151900
1152782
1153628
1153681
1153811
1154043
1154058
1154124
1154355
1154526
1154956
1155021
1155689
1155692
1155836
1155897
1155921
1155982
1156187
1156258
1156429
1156466
1156471
1156494
1156609
1156700
1156729
1156882
1157038
1157042
1157070
1157143
1157145
1157158
1157162
1157171
1157173
1157178
1157180
1157182
1157183
1157184
1157191
1157193
1157197
1157298
1157307
1157324
1157333
1157424
1157463
1157499
1157678
1157698
1157778
1157908
1158049
1158063
1158064
1158065
1158066
1158067
1158068
1158082
676471
790140
880007
880984
889207
899908
903279
919959
926159
928390
928547
931448
936923
940413
940806
943557
943558
943608
943989
944309
945345
947337
947780
953233
954847
956491
956852
957805
957986
960857
961305
962336
962846
962872
963193
963572
963762
964461
964727
965319
966054
966245
966573
966822
966831
967251
967292
967299
967903
968010
968141
968448
968512
968667
968670
968687
968812
968813
969439
969571
969655
969690
969735
969785
969992
969993
970062
970114
970504
970506
970604
970892
970909
970911
970948
970955
970956
970958
970970
971049
971124
971125
971126
971159
971170
971360
971600
971628
971947
972003
972174
972844
972891
972933
972951
973378
973556
973570
973855
974165
974308
974406
974418
974646
975371
975488
975533
975945
976739
976868
977582
977685
978401
978822
979169
979213
979419
979485
979548
979867
979879
980348
980371
981143
981344
982354
982698
983213
983318
983394
983904
984456
CVE-2012-4201
CVE-2012-4202
CVE-2012-4203
CVE-2012-4204
CVE-2012-4205
CVE-2012-4206
CVE-2012-4207
CVE-2012-4208
CVE-2012-4209
CVE-2012-4210
CVE-2012-4212
CVE-2012-4213
CVE-2012-4214
CVE-2012-4215
CVE-2012-4216
CVE-2012-4217
CVE-2012-4218
CVE-2012-5829
CVE-2012-5830
CVE-2012-5833
CVE-2012-5835
CVE-2012-5836
CVE-2012-5837
CVE-2012-5838
CVE-2012-5839
CVE-2012-5840
CVE-2012-5841
CVE-2012-5842
CVE-2012-5843
CVE-2013-0211
CVE-2014-4038
CVE-2014-4039
CVE-2014-9717
CVE-2015-2304
CVE-2015-4473
CVE-2015-4474
CVE-2015-4475
CVE-2015-4478
CVE-2015-4479
CVE-2015-4484
CVE-2015-4485
CVE-2015-4486
CVE-2015-4487
CVE-2015-4488
CVE-2015-4489
CVE-2015-4491
CVE-2015-4492
CVE-2015-4495
CVE-2015-4497
CVE-2015-4498
CVE-2015-8605
CVE-2015-8816
CVE-2015-8845
CVE-2016-0729
CVE-2016-0758
CVE-2016-2053
CVE-2016-2143
CVE-2016-2184
CVE-2016-2185
CVE-2016-2186
CVE-2016-2188
CVE-2016-2782
CVE-2016-2847
CVE-2016-2851
CVE-2016-3134
CVE-2016-3136
CVE-2016-3137
CVE-2016-3138
CVE-2016-3139
CVE-2016-3140
CVE-2016-3156
CVE-2016-3672
CVE-2016-3689
CVE-2016-3951
CVE-2016-4482
CVE-2016-4486
CVE-2016-4565
CVE-2016-4569
CVE-2016-4578
CVE-2016-4805
CVE-2016-5244
CVE-2017-10661
CVE-2017-13080
CVE-2017-15649
CVE-2017-16939
CVE-2017-8054
CVE-2018-1050
CVE-2018-10839
CVE-2018-10858
CVE-2018-11255
CVE-2018-12982
CVE-2018-15746
CVE-2018-16847
CVE-2018-17958
CVE-2018-17962
CVE-2018-17963
CVE-2018-18849
CVE-2018-20751
CVE-2018-5783
CVE-2019-12155
CVE-2019-13164
CVE-2019-14378
CVE-2019-14895
CVE-2019-15916
CVE-2019-16231
CVE-2019-17055
CVE-2019-18660
CVE-2019-18683
CVE-2019-18805
CVE-2019-18809
CVE-2019-19049
CVE-2019-19052
CVE-2019-19056
CVE-2019-19057
CVE-2019-19058
CVE-2019-19060
CVE-2019-19062
CVE-2019-19063
CVE-2019-19065
CVE-2019-19067
CVE-2019-19068
CVE-2019-19073
CVE-2019-19074
CVE-2019-19075
CVE-2019-19077
CVE-2019-19227
SUSE-SU-2015:1476-1
SUSE-SU-2016:0481-1
SUSE-SU-2016:0706-1
SUSE-SU-2016:1026-1
SUSE-SU-2016:1690-1
SUSE-SU-2017:3158-1
SUSE-SU-2017:3323-1
SUSE-SU-2017:3332-1
SUSE-SU-2018:4185-1
SUSE-SU-2019:1849-1
SUSE-SU-2019:2353-1
SUSE-SU-2019:3371-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.0 NonFree
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • cracklib-2.9.6-lp150.2 is installed
  • OR libcrack2-2.9.6-lp150.2 is installed
  • OR libcrack2-32bit-2.9.6-lp150.2 is installed
  • Definition Synopsis
  • openSUSE Leap 15.0 NonFree is installed
  • AND opera-54.0.2952.41-lp150.2.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • gvim-8.0.1568-lp151.5.3 is installed
  • OR vim-8.0.1568-lp151.5.3 is installed
  • OR vim-data-8.0.1568-lp151.5.3 is installed
  • OR vim-data-common-8.0.1568-lp151.5.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • MozillaFirefox-10.0.11-0.3 is installed
  • OR MozillaFirefox-translations-10.0.11-0.3 is installed
  • OR libfreebl3-3.14-0.3 is installed
  • OR libfreebl3-32bit-3.14-0.3 is installed
  • OR mozilla-nss-3.14-0.3 is installed
  • OR mozilla-nss-32bit-3.14-0.3 is installed
  • OR mozilla-nss-tools-3.14-0.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • dhcp-4.2.4.P2-0.24 is installed
  • OR dhcp-client-4.2.4.P2-0.24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • libotr-3.2.0-10.5 is installed
  • OR libotr2-3.2.0-10.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • MozillaFirefox-38.2.1esr-45 is installed
  • OR MozillaFirefox-branding-SLE-31.0-14 is installed
  • OR MozillaFirefox-translations-38.2.1esr-45 is installed
  • OR libfreebl3-3.19.2.0-26 is installed
  • OR libfreebl3-32bit-3.19.2.0-26 is installed
  • OR libsoftokn3-3.19.2.0-26 is installed
  • OR libsoftokn3-32bit-3.19.2.0-26 is installed
  • OR mozilla-nss-3.19.2.0-26 is installed
  • OR mozilla-nss-32bit-3.19.2.0-26 is installed
  • OR mozilla-nss-certs-3.19.2.0-26 is installed
  • OR mozilla-nss-certs-32bit-3.19.2.0-26 is installed
  • OR mozilla-nss-tools-3.19.2.0-26 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • qemu-2.11.2-5.5 is installed
  • OR qemu-block-curl-2.11.2-5.5 is installed
  • OR qemu-ipxe-1.0.0+-5.5 is installed
  • OR qemu-kvm-2.11.2-5.5 is installed
  • OR qemu-seabios-1.11.0-5.5 is installed
  • OR qemu-sgabios-8-5.5 is installed
  • OR qemu-tools-2.11.2-5.5 is installed
  • OR qemu-vgabios-1.11.0-5.5 is installed
  • OR qemu-x86-2.11.2-5.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND libarchive13-3.1.2-9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_74-60_64_60-default-3-2 is installed
  • OR kgraft-patch-3_12_74-60_64_60-xen-3-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_21-3-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND chrony-2.3-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND ppp-2.4.7-4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND gdb-8.3.1-1.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_74-92_38-default-12-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_13-12-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libfreetype6-2.6.3-7.10 is installed
  • OR libfreetype6-32bit-2.6.3-7.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • freeradius-server-3.0.15-2.14 is installed
  • OR freeradius-server-doc-3.0.15-2.14 is installed
  • OR freeradius-server-krb5-3.0.15-2.14 is installed
  • OR freeradius-server-ldap-3.0.15-2.14 is installed
  • OR freeradius-server-libs-3.0.15-2.14 is installed
  • OR freeradius-server-mysql-3.0.15-2.14 is installed
  • OR freeradius-server-perl-3.0.15-2.14 is installed
  • OR freeradius-server-postgresql-3.0.15-2.14 is installed
  • OR freeradius-server-python-3.0.15-2.14 is installed
  • OR freeradius-server-sqlite-3.0.15-2.14 is installed
  • OR freeradius-server-utils-3.0.15-2.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libsolv-0.6.36-2.27.19 is installed
  • OR libsolv-tools-0.6.36-2.27.19 is installed
  • OR libzypp-16.20.2-27.60 is installed
  • OR perl-solv-0.6.36-2.27.19 is installed
  • OR python-solv-0.6.36-2.27.19 is installed
  • OR zypper-1.13.54-18.40 is installed
  • OR zypper-log-1.13.54-18.40 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.85 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.85 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.85 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • gstreamer-plugins-good-1.8.3-15 is installed
  • OR gstreamer-plugins-good-lang-1.8.3-15 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND Package Information
  • ctdb-4.2.4-28.29 is installed
  • OR libdcerpc-binding0-4.2.4-28.29 is installed
  • OR libdcerpc-binding0-32bit-4.2.4-28.29 is installed
  • OR libdcerpc0-4.2.4-28.29 is installed
  • OR libdcerpc0-32bit-4.2.4-28.29 is installed
  • OR libgensec0-4.2.4-28.29 is installed
  • OR libgensec0-32bit-4.2.4-28.29 is installed
  • OR libndr-krb5pac0-4.2.4-28.29 is installed
  • OR libndr-krb5pac0-32bit-4.2.4-28.29 is installed
  • OR libndr-nbt0-4.2.4-28.29 is installed
  • OR libndr-nbt0-32bit-4.2.4-28.29 is installed
  • OR libndr-standard0-4.2.4-28.29 is installed
  • OR libndr-standard0-32bit-4.2.4-28.29 is installed
  • OR libndr0-4.2.4-28.29 is installed
  • OR libndr0-32bit-4.2.4-28.29 is installed
  • OR libnetapi0-4.2.4-28.29 is installed
  • OR libnetapi0-32bit-4.2.4-28.29 is installed
  • OR libregistry0-4.2.4-28.29 is installed
  • OR libsamba-credentials0-4.2.4-28.29 is installed
  • OR libsamba-credentials0-32bit-4.2.4-28.29 is installed
  • OR libsamba-hostconfig0-4.2.4-28.29 is installed
  • OR libsamba-hostconfig0-32bit-4.2.4-28.29 is installed
  • OR libsamba-passdb0-4.2.4-28.29 is installed
  • OR libsamba-passdb0-32bit-4.2.4-28.29 is installed
  • OR libsamba-util0-4.2.4-28.29 is installed
  • OR libsamba-util0-32bit-4.2.4-28.29 is installed
  • OR libsamdb0-4.2.4-28.29 is installed
  • OR libsamdb0-32bit-4.2.4-28.29 is installed
  • OR libsmbclient-raw0-4.2.4-28.29 is installed
  • OR libsmbclient-raw0-32bit-4.2.4-28.29 is installed
  • OR libsmbclient0-4.2.4-28.29 is installed
  • OR libsmbclient0-32bit-4.2.4-28.29 is installed
  • OR libsmbconf0-4.2.4-28.29 is installed
  • OR libsmbconf0-32bit-4.2.4-28.29 is installed
  • OR libsmbldap0-4.2.4-28.29 is installed
  • OR libsmbldap0-32bit-4.2.4-28.29 is installed
  • OR libtevent-util0-4.2.4-28.29 is installed
  • OR libtevent-util0-32bit-4.2.4-28.29 is installed
  • OR libwbclient0-4.2.4-28.29 is installed
  • OR libwbclient0-32bit-4.2.4-28.29 is installed
  • OR samba-4.2.4-28.29 is installed
  • OR samba-32bit-4.2.4-28.29 is installed
  • OR samba-client-4.2.4-28.29 is installed
  • OR samba-client-32bit-4.2.4-28.29 is installed
  • OR samba-doc-4.2.4-28.29 is installed
  • OR samba-libs-4.2.4-28.29 is installed
  • OR samba-libs-32bit-4.2.4-28.29 is installed
  • OR samba-winbind-4.2.4-28.29 is installed
  • OR samba-winbind-32bit-4.2.4-28.29 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • nodejs-common-1.0-2 is installed
  • OR nodejs6-6.11.1-11.5 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • evince-3.20.2-6.27 is installed
  • OR evince-browser-plugin-3.20.2-6.27 is installed
  • OR evince-lang-3.20.2-6.27 is installed
  • OR evince-plugin-djvudocument-3.20.2-6.27 is installed
  • OR evince-plugin-dvidocument-3.20.2-6.27 is installed
  • OR evince-plugin-pdfdocument-3.20.2-6.27 is installed
  • OR evince-plugin-psdocument-3.20.2-6.27 is installed
  • OR evince-plugin-tiffdocument-3.20.2-6.27 is installed
  • OR evince-plugin-xpsdocument-3.20.2-6.27 is installed
  • OR libevdocument3-4-3.20.2-6.27 is installed
  • OR libevview3-3-3.20.2-6.27 is installed
  • OR nautilus-evince-3.20.2-6.27 is installed
  • BACK