Oval Definition:oval:org.opensuse.security:def:65202
Revision Date:2020-12-21Version:1
Title:Security update for MozillaFirefox (Critical)
Description:

This update for MozillaFirefox fixes the following issues:

- Firefox Extended Support Release 78.6.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2020-55 (bsc#1180039) * CVE-2020-16042 (bmo#1679003) Operations on a BigInt could have caused uninitialized memory to be exposed * CVE-2020-26971 (bmo#1663466) Heap buffer overflow in WebGL * CVE-2020-26973 (bmo#1680084) CSS Sanitizer performed incorrect sanitization * CVE-2020-26974 (bmo#1681022) Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free * CVE-2020-26978 (bmo#1677047) Internal network hosts could have been probed by a malicious webpage * CVE-2020-35111 (bmo#1657916) The proxy.onRequest API did not catch view-source URLs * CVE-2020-35112 (bmo#1661365) Opening an extension-less download may have inadvertently launched an executable instead * CVE-2020-35113 (bmo#1664831, bmo#1673589) Memory safety bugs fixed in Firefox 84 and Firefox ESR 78.6
Family:unixClass:patch
Status:Reference(s):1160611
1160612
1160613
1160614
1160615
1170771
1180039
CVE-2019-2126
CVE-2019-9232
CVE-2019-9325
CVE-2019-9371
CVE-2019-9433
CVE-2020-12243
CVE-2020-16042
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35112
CVE-2020-35113
SUSE-SU-2020:0143-1
SUSE-SU-2020:1219-1
SUSE-SU-2020:3901-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Module for Development Tools 15 SP1
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed
  • AND Package Information
  • libvpx-1.6.1-6.3 is installed
  • OR libvpx-devel-1.6.1-6.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Development Tools 15 SP1 is installed
  • AND Package Information
  • openldap2-2.4.46-9.28 is installed
  • OR openldap2-devel-32bit-2.4.46-9.28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • MozillaFirefox-78.6.0-8.20.2 is installed
  • OR MozillaFirefox-devel-78.6.0-8.20.2 is installed
  • OR MozillaFirefox-translations-common-78.6.0-8.20.2 is installed
  • OR MozillaFirefox-translations-other-78.6.0-8.20.2 is installed
  • BACK