SUSE Security Update: Security update for Mozilla Firefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2013:1678-1 Rating: important References: #847708 Cross-References: CVE-2013-1739 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise Software Development Kit 11 SP2 SUSE Linux Enterprise Server 11 SP3 for VMware SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Server 11 SP2 for VMware SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP1 LTSS SUSE Linux Enterprise Server 10 SP4 LTSS SUSE Linux Enterprise Server 10 SP3 LTSS SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. It includes four new package versions. Description: Mozilla Firefox has been updated to the 17.0.10ESR release, which fixes various bugs and security issues: * MFSA 2013-93: Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Jesse Ruderman and Christoph Diehl reported memory safety problems and crashes that affect Firefox ESR 17, Firefox ESR 24, and Firefox 24. (CVE-2013-5590) Carsten Book reported a crash fixed in the NSS library used by Mozilla-based products fixed in Firefox 25, Firefox ESR 24.1, and Firefox ESR 17.0.10.(CVE-2013-1739) * MFSA 2013-95 / CVE-2013-5604: Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover an access violation due to uninitialized data during Extensible Stylesheet Language Transformation (XSLT) processing. This leads to a potentially exploitable crash. * MFSA 2013-96 / CVE-2013-5595: Compiler Engineer Dan Gohman of Google discovered a flaw in the JavaScript engine where memory was being incorrectly allocated for some functions and the calls for allocations were not always properly checked for overflow, leading to potential buffer overflows. When combined with other vulnerabilities, these flaws could be potentially exploitable. * MFSA 2013-98 / CVE-2013-5597: Security researcher Byoungyoung Lee of Georgia Tech Information Security Center (GTISC) used the Address Sanitizer tool to discover a use-after-free during state change events while updating the offline cache. This leads to a potentially exploitable crash. * MFSA 2013-100: Security researcher Nils used the Address Sanitizer tool while fuzzing to discover missing strong references in browsing engine leading to use-after-frees. This can lead to a potentially exploitable crash. o ASAN heap-use-after-free in nsIPresShell::GetPresContext() with canvas, onresize and mozTextStyle (CVE-2013-5599) o ASAN use-after-free in nsIOService::NewChannelFromURIWithProxyFlags with Blob URL (CVE-2013-5600) o ASAN use-after free in GC allocation in nsEventListenerManager::SetEventHandler (CVE-2013-5601) * MFSA 2013-101 / CVE-2013-5602: Security researcher Nils used the Address Sanitizer tool while fuzzing to discover a memory corruption issue with the JavaScript engine when using workers with direct proxies. This results in a potentially exploitable crash. Security Issue reference: * CVE-2013-1739 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1739
Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP3: zypper in -t patch sdksp3-firefox-201310-8491 sdksp3-mozilla-nss-201310-8485 - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-mozilla-nss-201310-8484 - SUSE Linux Enterprise Server 11 SP3 for VMware: zypper in -t patch slessp3-firefox-201310-8491 slessp3-mozilla-nss-201310-8485 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-firefox-201310-8491 slessp3-mozilla-nss-201310-8485 - SUSE Linux Enterprise Server 11 SP2 for VMware: zypper in -t patch slessp2-firefox-201310-8545 slessp2-mozilla-nss-201310-8484 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-firefox-201310-8545 slessp2-mozilla-nss-201310-8484 - SUSE Linux Enterprise Server 11 SP1 LTSS: zypper in -t patch slessp1-firefox-201310-8492 slessp1-mozilla-nss-201310-8486 - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-firefox-201310-8491 sledsp3-mozilla-nss-201310-8485 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-firefox-201310-8545 sledsp2-mozilla-nss-201310-8484 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]: MozillaFirefox-devel-17.0.10esr-0.7.4 mozilla-nspr-devel-4.10.1-0.3.1 mozilla-nss-devel-3.15.2-0.8.1 - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]: mozilla-nspr-devel-4.10.1-0.3.1 mozilla-nss-devel-3.15.2-0.3.1 - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]: MozillaFirefox-17.0.10esr-0.7.4 MozillaFirefox-translations-17.0.10esr-0.7.4 libfreebl3-3.15.2-0.8.1 libsoftokn3-3.15.2-0.8.1 mozilla-nspr-4.10.1-0.3.1 mozilla-nss-3.15.2-0.8.1 mozilla-nss-tools-3.15.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 for VMware (x86_64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-32bit-3.15.2-0.8.1 libsoftokn3-32bit-3.15.2-0.8.1 mozilla-nspr-32bit-4.10.1-0.3.1 mozilla-nss-32bit-3.15.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]: MozillaFirefox-17.0.10esr-0.7.4 MozillaFirefox-branding-SLED-7-0.12.41 MozillaFirefox-translations-17.0.10esr-0.7.4 libfreebl3-3.15.2-0.8.1 libsoftokn3-3.15.2-0.8.1 mozilla-nspr-4.10.1-0.3.1 mozilla-nss-3.15.2-0.8.1 mozilla-nss-tools-3.15.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 (ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-32bit-3.15.2-0.8.1 libsoftokn3-32bit-3.15.2-0.8.1 mozilla-nspr-32bit-4.10.1-0.3.1 mozilla-nss-32bit-3.15.2-0.8.1 - SUSE Linux Enterprise Server 11 SP3 (ia64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-x86-3.15.2-0.8.1 libsoftokn3-x86-3.15.2-0.8.1 mozilla-nspr-x86-4.10.1-0.3.1 mozilla-nss-x86-3.15.2-0.8.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]: MozillaFirefox-17.0.10esr-0.4.2.4 MozillaFirefox-translations-17.0.10esr-0.4.2.4 libfreebl3-3.15.2-0.3.1 mozilla-nspr-4.10.1-0.3.1 mozilla-nss-3.15.2-0.3.1 mozilla-nss-tools-3.15.2-0.3.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (x86_64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-32bit-3.15.2-0.3.1 mozilla-nspr-32bit-4.10.1-0.3.1 mozilla-nss-32bit-3.15.2-0.3.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]: MozillaFirefox-17.0.10esr-0.4.2.4 MozillaFirefox-branding-SLED-7-0.6.9.62 MozillaFirefox-translations-17.0.10esr-0.4.2.4 libfreebl3-3.15.2-0.3.1 mozilla-nspr-4.10.1-0.3.1 mozilla-nss-3.15.2-0.3.1 mozilla-nss-tools-3.15.2-0.3.1 - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-32bit-3.15.2-0.3.1 mozilla-nspr-32bit-4.10.1-0.3.1 mozilla-nss-32bit-3.15.2-0.3.1 - SUSE Linux Enterprise Server 11 SP2 (ia64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-x86-3.15.2-0.3.1 mozilla-nspr-x86-4.10.1-0.3.1 mozilla-nss-x86-3.15.2-0.3.1 - SUSE Linux Enterprise Server 11 SP1 LTSS (i586 s390x x86_64) [New Version: 17.0.10esr,3.15.2,4.10.1 and 7]: MozillaFirefox-17.0.10esr-0.4.2.1 MozillaFirefox-branding-SLED-7-0.6.9.60 MozillaFirefox-translations-17.0.10esr-0.4.2.1 libfreebl3-3.15.2-0.3.1 mozilla-nspr-4.10.1-0.3.1 mozilla-nss-3.15.2-0.3.1 mozilla-nss-tools-3.15.2-0.3.1 - SUSE Linux Enterprise Server 11 SP1 LTSS (s390x x86_64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-32bit-3.15.2-0.3.1 mozilla-nspr-32bit-4.10.1-0.3.1 mozilla-nss-32bit-3.15.2-0.3.1 - SUSE Linux Enterprise Server 10 SP4 LTSS (i586 s390x x86_64) [New Version: 3.15.2 and 4.10.1]: mozilla-nspr-4.10.1-0.5.1 mozilla-nspr-devel-4.10.1-0.5.1 mozilla-nss-3.15.2-0.5.1 mozilla-nss-devel-3.15.2-0.5.1 mozilla-nss-tools-3.15.2-0.5.1 - SUSE Linux Enterprise Server 10 SP4 LTSS (s390x x86_64) [New Version: 3.15.2 and 4.10.1]: mozilla-nspr-32bit-4.10.1-0.5.1 mozilla-nss-32bit-3.15.2-0.5.1 - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x x86_64) [New Version: 3.15.2 and 4.10.1]: mozilla-nspr-4.10.1-0.5.1 mozilla-nspr-devel-4.10.1-0.5.1 mozilla-nss-3.15.2-0.5.1 mozilla-nss-devel-3.15.2-0.5.1 mozilla-nss-tools-3.15.2-0.5.1 - SUSE Linux Enterprise Server 10 SP3 LTSS (s390x x86_64) [New Version: 3.15.2 and 4.10.1]: mozilla-nspr-32bit-4.10.1-0.5.1 mozilla-nss-32bit-3.15.2-0.5.1 - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]: MozillaFirefox-17.0.10esr-0.7.4 MozillaFirefox-branding-SLED-7-0.12.41 MozillaFirefox-translations-17.0.10esr-0.7.4 libfreebl3-3.15.2-0.8.1 libsoftokn3-3.15.2-0.8.1 mozilla-nspr-4.10.1-0.3.1 mozilla-nss-3.15.2-0.8.1 mozilla-nss-tools-3.15.2-0.8.1 - SUSE Linux Enterprise Desktop 11 SP3 (x86_64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-32bit-3.15.2-0.8.1 libsoftokn3-32bit-3.15.2-0.8.1 mozilla-nspr-32bit-4.10.1-0.3.1 mozilla-nss-32bit-3.15.2-0.8.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]: MozillaFirefox-17.0.10esr-0.4.2.4 MozillaFirefox-branding-SLED-7-0.6.9.62 MozillaFirefox-translations-17.0.10esr-0.4.2.4 libfreebl3-3.15.2-0.3.1 mozilla-nspr-4.10.1-0.3.1 mozilla-nss-3.15.2-0.3.1 mozilla-nss-tools-3.15.2-0.3.1 - SUSE Linux Enterprise Desktop 11 SP2 (x86_64) [New Version: 3.15.2 and 4.10.1]: libfreebl3-32bit-3.15.2-0.3.1 mozilla-nspr-32bit-4.10.1-0.3.1 mozilla-nss-32bit-3.15.2-0.3.1 References: http://support.novell.com/security/cve/CVE-2013-1739.html https://bugzilla.novell.com/847708 http://download.novell.com/patch/finder/?keywords=07c7008fa5d3132fbafd48744a... http://download.novell.com/patch/finder/?keywords=1edf663f8550de4b96445d1cbc... http://download.novell.com/patch/finder/?keywords=30958073bccf2d3c9d16900439... http://download.novell.com/patch/finder/?keywords=574e354cc19e6404e0964c3b13... http://download.novell.com/patch/finder/?keywords=92ad00fe40f67f855b720f6d4a... http://download.novell.com/patch/finder/?keywords=96c6d994dc18c3fd7399e875d9... http://download.novell.com/patch/finder/?keywords=d36d3817c15a3112e57723f3b4... http://download.novell.com/patch/finder/?keywords=f4dc527883357fa1c73dfcbfaa... -- To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-security-announce+help@opensuse.org