Oval Definition:oval:org.opensuse.security:def:78707
Revision Date:2016-12-05Version:1
Title:Security update for MozillaFirefox, mozilla-nss (Important)
Description:

This update for MozillaFirefox, mozilla-nss fixes security issues and bugs.

The following vulnerabilities were fixed in Firefox ESR 45.5 (bsc#1009026):

- CVE-2016-5297: Incorrect argument length checking in Javascript (bsc#1010401) - CVE-2016-9066: Integer overflow leading to a buffer overflow in nsScriptLoadHandler (bsc#1010404) - CVE-2016-5296: Heap-buffer-overflow WRITE in rasterize_edges_1 (bsc#1010395) - CVE-2016-9064: Addons update must verify IDs match between current and new versions (bsc#1010402) - CVE-2016-5290: Memory safety bugs fixed in Firefox 50 and Firefox ESR 45.5 (bsc#1010427) - CVE-2016-5291: Same-origin policy violation using local HTML file and saved shortcut file (bsc#1010410)

The following vulnerabilities were fixed in mozilla-nss 3.21.3:

- CVE-2016-9074: Insufficient timing side-channel resistance in divSpoiler (bsc#1010422) - CVE-2016-5285: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash (bsc#1010517)

The following bugs were fixed:

- Firefox would fail to go into fullscreen mode with some window managers (bsc#992549)

The Mozilla Firefox changelog was amended to document patched dropped in a previous update.
Family:unixClass:patch
Status:Reference(s):1009026
1010395
1010401
1010402
1010404
1010410
1010422
1010427
1010517
992549
CVE-2016-5285
CVE-2016-5290
CVE-2016-5291
CVE-2016-5296
CVE-2016-5297
CVE-2016-9064
CVE-2016-9066
CVE-2016-9074
SUSE-SU-2016:3014-1
Platform(s):SUSE Linux Enterprise Desktop 12 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • MozillaFirefox-45.5.0esr-88.1 is installed
  • OR MozillaFirefox-translations-45.5.0esr-88.1 is installed
  • OR libfreebl3-3.21.3-50.1 is installed
  • OR libfreebl3-32bit-3.21.3-50.1 is installed
  • OR libsoftokn3-3.21.3-50.1 is installed
  • OR libsoftokn3-32bit-3.21.3-50.1 is installed
  • OR mozilla-nss-3.21.3-50.1 is installed
  • OR mozilla-nss-32bit-3.21.3-50.1 is installed
  • OR mozilla-nss-certs-3.21.3-50.1 is installed
  • OR mozilla-nss-certs-32bit-3.21.3-50.1 is installed
  • OR mozilla-nss-sysinit-3.21.3-50.1 is installed
  • OR mozilla-nss-sysinit-32bit-3.21.3-50.1 is installed
  • OR mozilla-nss-tools-3.21.3-50.1 is installed
  • BACK