Oval Definition:oval:org.opensuse.security:def:65141
Revision Date:2020-12-21Version:1
Title:Security update for MozillaFirefox (Critical)
Description:

This update for MozillaFirefox fixes the following issues:

- Firefox Extended Support Release 78.6.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-55 (bsc#1180039) * CVE-2020-16042 (bmo#1679003) Operations on a BigInt could have caused uninitialized memory to be exposed * CVE-2020-26971 (bmo#1663466) Heap buffer overflow in WebGL * CVE-2020-26973 (bmo#1680084) CSS Sanitizer performed incorrect sanitization * CVE-2020-26974 (bmo#1681022) Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free * CVE-2020-26978 (bmo#1677047) Internal network hosts could have been probed by a malicious webpage * CVE-2020-35111 (bmo#1657916) The proxy.onRequest API did not catch view-source URLs * CVE-2020-35112 (bmo#1661365) Opening an extension-less download may have inadvertently launched an executable instead * CVE-2020-35113 (bmo#1664831, bmo#1673589) Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6
Family:unixClass:patch
Status:Reference(s):1172410
1172524
1173576
1180039
CVE-2020-10749
CVE-2020-12417
CVE-2020-12418
CVE-2020-12419
CVE-2020-12420
CVE-2020-12421
CVE-2020-12861
CVE-2020-12862
CVE-2020-12863
CVE-2020-12864
CVE-2020-12865
CVE-2020-12866
CVE-2020-12867
CVE-2020-16042
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35112
CVE-2020-35113
openSUSE-SU-2020:0982-1
SUSE-SU-2020:1957-1
SUSE-SU-2020:3065-1
SUSE-SU-2020:3902-1
Platform(s):openSUSE Leap 15.2
SUSE Linux Enterprise Desktop 15 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Module for Containers 15 SP1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • MozillaThunderbird-68.10.0-lp152.2.4 is installed
  • OR MozillaThunderbird-translations-common-68.10.0-lp152.2.4 is installed
  • OR MozillaThunderbird-translations-other-68.10.0-lp152.2.4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed
  • AND Package Information
  • MozillaFirefox-78.6.0-3.122.1 is installed
  • OR MozillaFirefox-devel-78.6.0-3.122.1 is installed
  • OR MozillaFirefox-translations-common-78.6.0-3.122.1 is installed
  • OR MozillaFirefox-translations-other-78.6.0-3.122.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Containers 15 SP1 is installed
  • AND cni-plugins-0.8.6-3.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed
  • AND Package Information
  • sane-backends-1.0.31-6.3 is installed
  • OR sane-backends-autoconfig-1.0.31-6.3 is installed
  • OR sane-backends-devel-1.0.31-6.3 is installed
  • BACK