[security-announce] SUSE-SU-2013:1325-2: important: Security update for Mozilla Firefox
SUSE Security Update: Security update for Mozilla Firefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2013:1325-2 Rating: important References: #833389 Affected Products: SUSE Linux Enterprise Server 11 SP1 for VMware LTSS SUSE Linux Enterprise Server 11 SP1 LTSS SUSE Linux Enterprise Server 10 SP3 LTSS ______________________________________________________________________________ An update that contains security fixes can now be installed. It includes four new package versions. Description: This update to Firefox 17.0.8esr (bnc#833389) addresses the following issues: * MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 (bmo#855331, bmo#844088, bmo#858060, bmo#870200, bmo#874974, bmo#861530, bmo#854157, bmo#893684, bmo#878703, bmo#862185, bmo#879139, bmo#888107, bmo#880734) Miscellaneous memory safety hazards (rv:23.0 / rv:17.0.8) * MFSA 2013-66/CVE-2013-1706/CVE-2013-1707 (bmo#888314, bmo#888361) Buffer overflow in Mozilla Maintenance Service and Mozilla Updater * MFSA 2013-68/CVE-2013-1709 (bmo#848253) Document URI misrepresentation and masquerading * MFSA 2013-69/CVE-2013-1710 (bmo#871368) CRMF requests allow for code execution and XSS attacks * MFSA 2013-71/CVE-2013-1712 (bmo#859072) Further Privilege escalation through Mozilla Updater * MFSA 2013-72/CVE-2013-1713 (bmo#887098) Wrong principal used for validating URI for some Javascript components * MFSA 2013-73/CVE-2013-1714 (bmo#879787) Same-origin bypass with web workers and XMLHttpRequest * MFSA 2013-75/CVE-2013-1717 (bmo#406541) Local Java applets may read contents of local file system Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP1 for VMware LTSS: zypper in -t patch slessp1-MozillaFirefox-8188 - SUSE Linux Enterprise Server 11 SP1 LTSS: zypper in -t patch slessp1-MozillaFirefox-8188 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP1 for VMware LTSS (i586 x86_64) [New Version: 17.0.8esr]: MozillaFirefox-17.0.8esr-0.4.2.1 MozillaFirefox-translations-17.0.8esr-0.4.2.1 - SUSE Linux Enterprise Server 11 SP1 LTSS (i586 s390x x86_64) [New Version: 17.0.8esr]: MozillaFirefox-17.0.8esr-0.4.2.1 MozillaFirefox-translations-17.0.8esr-0.4.2.1 - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x x86_64) [New Version: 3.14.3 and 4.9.6]: mozilla-nspr-4.9.6-0.5.7 mozilla-nspr-devel-4.9.6-0.5.7 mozilla-nss-3.14.3-0.5.7 mozilla-nss-devel-3.14.3-0.5.7 mozilla-nss-tools-3.14.3-0.5.7 - SUSE Linux Enterprise Server 10 SP3 LTSS (s390x x86_64) [New Version: 3.14.3 and 4.9.6]: mozilla-nspr-32bit-4.9.6-0.5.7 mozilla-nss-32bit-3.14.3-0.5.7 - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x) [New Version: 17.0.8esr and 7]: MozillaFirefox-17.0.8esr-0.5.3 MozillaFirefox-branding-SLED-7-0.10.34 MozillaFirefox-translations-17.0.8esr-0.5.3 References: https://bugzilla.novell.com/833389 http://download.novell.com/patch/finder/?keywords=27187876975cda4d472350efca... http://download.novell.com/patch/finder/?keywords=6795b3750d821e23eeba3d00c9... -- To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
participants (1)
-
opensuse-security@opensuse.org