Revision Date: | 2019-10-31 | Version: | 1 |
Title: | Security update for MozillaFirefox, MozillaFirefox-branding-SLE (Important) |
Description: |
This update for MozillaFirefox, MozillaFirefox-branding-SLE fixes the following issues:
Changes in MozillaFirefox:
Security issues fixed:
- CVE-2019-15903: Fixed a heap overflow in the expat library (bsc#1149429). - CVE-2019-11757: Fixed a use-after-free when creating index updates in IndexedDB (bsc#1154738). - CVE-2019-11758: Fixed a potentially exploitable crash due to 360 Total Security (bsc#1154738). - CVE-2019-11759: Fixed a stack buffer overflow in HKDF output (bsc#1154738). - CVE-2019-11760: Fixed a stack buffer overflow in WebRTC networking (bsc#1154738). - CVE-2019-11761: Fixed an unintended access to a privileged JSONView object (bsc#1154738). - CVE-2019-11762: Fixed a same-origin-property violation (bsc#1154738). - CVE-2019-11763: Fixed an XSS bypass (bsc#1154738). - CVE-2019-11764: Fixed several memory safety bugs (bsc#1154738).
Non-security issues fixed:
- Added Provides-line for translations-common (bsc#1153423) . - Moved some settings from branding-package here (bsc#1153869). - Disabled DoH by default.
Changes in MozillaFirefox-branding-SLE:
- Moved extensions preferences to core package (bsc#1153869).
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1104841 1129528 1137990 1149429 1151186 1153423 1153869 1154738 CVE-2019-11757 CVE-2019-11758 CVE-2019-11759 CVE-2019-11760 CVE-2019-11761 CVE-2019-11762 CVE-2019-11763 CVE-2019-11764 CVE-2019-15903 SUSE-SU-2019:2871-1
|
Platform(s): | SUSE Linux Enterprise Desktop 15 SP1 SUSE Linux Enterprise High Performance Computing 15 SP1 SUSE Linux Enterprise Module for Desktop Applications 15 SP1 SUSE Linux Enterprise Server 15 SP1 SUSE Linux Enterprise Server for SAP Applications 15 SP1 SUSE Linux Enterprise Storage 6 SUSE Manager Proxy 4.0 SUSE Manager Server 4.0
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Module for Desktop Applications 15 SP1 is installed AND Package Information
MozillaFirefox-68.2.0-3.59.1 is installed
OR MozillaFirefox-branding-SLE-68-4.11.2 is installed
OR MozillaFirefox-devel-68.2.0-3.59.1 is installed
OR MozillaFirefox-translations-common-68.2.0-3.59.1 is installed
OR MozillaFirefox-translations-other-68.2.0-3.59.1 is installed
|