Oval Definition:oval:org.opensuse.security:def:57327
Revision Date:2020-12-01Version:1
Title:Security update for Mozilla Firefox
Description:



Mozilla Firefox has been updated to the 17.0.10ESR release, which fixes various bugs and security issues:

*

MFSA 2013-93: Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code.

* Jesse Ruderman and Christoph Diehl reported memory safety problems and crashes that affect Firefox ESR 17, Firefox ESR 24, and Firefox 24. (CVE-2013-5590)

* Carsten Book reported a crash fixed in the NSS library used by Mozilla-based products fixed in Firefox 25, Firefox ESR 24.1, and Firefox ESR 17.0.10.(CVE-2013-1739)

*

MFSA 2013-95 / CVE-2013-5604: Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover an access violation due to uninitialized data during Extensible Stylesheet Language Transformation (XSLT) processing. This leads to a potentially exploitable crash.

*

MFSA 2013-96 / CVE-2013-5595: Compiler Engineer Dan Gohman of Google discovered a flaw in the JavaScript engine where memory was being incorrectly allocated for some functions and the calls for allocations were not always properly checked for overflow, leading to potential buffer overflows. When combined with other vulnerabilities, these flaws could be potentially exploitable.

*

MFSA 2013-98 / CVE-2013-5597: Security researcher Byoungyoung Lee of Georgia Tech Information Security Center (GTISC) used the Address Sanitizer tool to discover a use-after-free during state change events while updating the offline cache. This leads to a potentially exploitable crash.

*

MFSA 2013-100: Security researcher Nils used the Address Sanitizer tool while fuzzing to discover missing strong references in browsing engine leading to use-after-frees. This can lead to a potentially exploitable crash.

o ASAN heap-use-after-free in nsIPresShell::GetPresContext() with canvas, onresize and mozTextStyle (CVE-2013-5599) o ASAN use-after-free in nsIOService::NewChannelFromURIWithProxyFlags with Blob URL (CVE-2013-5600) o ASAN use-after free in GC allocation in nsEventListenerManager::SetEventHandler (CVE-2013-5601) *

MFSA 2013-101 / CVE-2013-5602: Security researcher Nils used the Address Sanitizer tool while fuzzing to discover a memory corruption issue with the JavaScript engine when using workers with direct proxies. This results in a potentially exploitable crash.

Security Issue reference:

* CVE-2013-1739

Family:unixClass:patch
Status:Reference(s):1006984
1006989
1025068
1037811
1082023
1082318
1090036
1097356
1097560
1097824
1103098
1103809
1103810
1104076
1112039
1120489
1128828
1138034
1138954
1142614
1144327
1144379
1150584
1152711
1153471
1155789
1155952
1157860
1158785
1158787
1158788
1158789
1158790
1158791
1158792
1158793
1158795
1159646
1173580
847708
856832
859158
977043
CVE-2013-1739
CVE-2013-4509
CVE-2013-4549
CVE-2017-2626
CVE-2017-6967
CVE-2018-1000199
CVE-2018-12470
CVE-2018-12471
CVE-2018-12472
CVE-2018-18386
CVE-2018-20217
CVE-2018-5391
CVE-2018-5848
CVE-2019-10164
CVE-2019-1348
CVE-2019-1349
CVE-2019-1350
CVE-2019-1351
CVE-2019-1352
CVE-2019-1353
CVE-2019-1354
CVE-2019-1387
CVE-2019-17571
CVE-2019-19604
CVE-2019-9893
CVE-2020-4044
SUSE-SU-2017:1835-1
SUSE-SU-2018:1550-1
SUSE-SU-2018:2898-1
SUSE-SU-2019:0113-1
SUSE-SU-2019:1783-1
SUSE-SU-2019:2941-1
SUSE-SU-2019:3311-1
SUSE-SU-2020:0054-1
SUSE-SU-2020:1943-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
openSUSE Leap 15.1 NonFree
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • cups-pk-helper-0.2.6-lp150.1 is installed
  • OR cups-pk-helper-lang-0.2.6-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • kconf_update5-5.32.0-7 is installed
  • OR kconfig-5.32.0-7 is installed
  • OR kconfig-devel-5.32.0-7 is installed
  • OR kconfig-devel-32bit-5.55.0-lp151.2.5 is installed
  • OR kconfig-devel-64bit-5.32.0-7 is installed
  • OR kdelibs4-4.14.33-7 is installed
  • OR kdelibs4-apidocs-4.14.33-7 is installed
  • OR kdelibs4-branding-upstream-4.14.33-7 is installed
  • OR kdelibs4-core-4.14.33-7 is installed
  • OR kdelibs4-doc-4.14.33-7 is installed
  • OR libKF5ConfigCore5-5.32.0-7 is installed
  • OR libKF5ConfigCore5-32bit-5.55.0-lp151.2.5 is installed
  • OR libKF5ConfigCore5-64bit-5.32.0-7 is installed
  • OR libKF5ConfigCore5-lang-5.32.0-7 is installed
  • OR libKF5ConfigGui5-5.32.0-7 is installed
  • OR libKF5ConfigGui5-32bit-5.55.0-lp151.2.5 is installed
  • OR libKF5ConfigGui5-64bit-5.32.0-7 is installed
  • OR libkde4-4.14.33-7 is installed
  • OR libkde4-32bit-4.14.38-lp151.9.5 is installed
  • OR libkde4-64bit-4.14.33-7 is installed
  • OR libkde4-devel-4.14.33-7 is installed
  • OR libkdecore4-4.14.33-7 is installed
  • OR libkdecore4-32bit-4.14.38-lp151.9.5 is installed
  • OR libkdecore4-64bit-4.14.33-7 is installed
  • OR libkdecore4-devel-4.14.33-7 is installed
  • OR libksuseinstall-devel-4.14.33-7 is installed
  • OR libksuseinstall1-4.14.33-7 is installed
  • OR libksuseinstall1-32bit-4.14.38-lp151.9.5 is installed
  • OR libksuseinstall1-64bit-4.14.33-7 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 NonFree is installed
  • AND opera-68.0.3618.104-lp151.2.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • MozillaFirefox-17.0.10esr-0.7 is installed
  • OR MozillaFirefox-branding-SLED-7-0.12 is installed
  • OR MozillaFirefox-translations-17.0.10esr-0.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_74-60_64_107-default-3-2 is installed
  • OR kgraft-patch-3_12_74-60_64_107-xen-3-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_32-3-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • ibus-chewing-1.4.14-4 is installed
  • OR ibus-pinyin-1.5.0-7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • libopenssl-devel-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-32bit-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-hmac-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.39 is installed
  • OR openssl-1.0.2j-60.39 is installed
  • OR openssl-doc-1.0.2j-60.39 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_114-92_67-default-8-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_19-8-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_121-92_80-default-2-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_22-2-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • accountsservice-0.6.42-14 is installed
  • OR accountsservice-lang-0.6.42-14 is installed
  • OR libaccountsservice0-0.6.42-14 is installed
  • OR typelib-1_0-AccountsService-1_0-0.6.42-14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • icu-52.1-8.10 is installed
  • OR libicu-doc-52.1-8.10 is installed
  • OR libicu52_1-52.1-8.10 is installed
  • OR libicu52_1-32bit-52.1-8.10 is installed
  • OR libicu52_1-data-52.1-8.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • MozillaFirefox-68.2.0-109.95 is installed
  • OR MozillaFirefox-translations-common-68.2.0-109.95 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.82 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.82 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.82 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • freeradius-server-3.0.15-2.14 is installed
  • OR freeradius-server-doc-3.0.15-2.14 is installed
  • OR freeradius-server-krb5-3.0.15-2.14 is installed
  • OR freeradius-server-ldap-3.0.15-2.14 is installed
  • OR freeradius-server-libs-3.0.15-2.14 is installed
  • OR freeradius-server-mysql-3.0.15-2.14 is installed
  • OR freeradius-server-perl-3.0.15-2.14 is installed
  • OR freeradius-server-postgresql-3.0.15-2.14 is installed
  • OR freeradius-server-python-3.0.15-2.14 is installed
  • OR freeradius-server-sqlite-3.0.15-2.14 is installed
  • OR freeradius-server-utils-3.0.15-2.14 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • res-signingkeys-3.0.37-52.23 is installed
  • OR smt-3.0.37-52.23 is installed
  • OR smt-support-3.0.37-52.23 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • libseccomp-2.4.1-11.3 is installed
  • OR libseccomp2-2.4.1-11.3 is installed
  • OR libseccomp2-32bit-2.4.1-11.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND clamav-0.100.3-33.29 is installed
  • BACK