SUSE-SU-2015:0446-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0446-1
SUSE-SU-2015:0446-1
Summary: Security update for Mozilla Firefox
Details: This update to Firefox 17.0.9esr (bnc#840485) addresses: * MFSA 2013-91 User-defined properties on DOM proxies get the wrong 'this' object o (CVE-2013-1737) * MFSA 2013-90 Memory corruption involving scrolling o use-after-free in mozilla::layout::ScrollbarActivity (CVE-2013-1735) o Memory corruption in nsGfxScrollFrameInner::IsLTR() (CVE-2013-1736) * MFSA 2013-89 Buffer overflow with multi-column, lists, and floats o buffer overflow at nsFloatManager::GetFlowArea() with multicol, list, floats (CVE-2013-1732) * MFSA 2013-88 compartment mismatch re-attaching XBL-backed nodes o compartment mismatch in nsXBLBinding::DoInitJSClass (CVE-2013-1730) * MFSA 2013-83 Mozilla Updater does not lock MAR file after signature verification o MAR signature bypass in Updater could lead to downgrade (CVE-2013-1726) * MFSA 2013-82 Calling scope for new Javascript objects can lead to memory corruption o ABORT: bad scope for new JSObjects: ReparentWrapper / document.open (CVE-2013-1725) * MFSA 2013-79 Use-after-free in Animation Manager during stylesheet cloning o Heap-use-after-free in nsAnimationManager::BuildAnimations (CVE-2013-1722) * MFSA 2013-76 Miscellaneous memory safety hazards (rv:24.0 / rv:17.0.9) o Memory safety bugs fixed in Firefox 17.0.9 and Firefox 24.0 (CVE-2013-1718) * MFSA 2013-65 Buffer underflow when generating CRMF requests o ASAN heap-buffer-overflow (read 1) in cryptojs_interpret_key_gen_type (CVE-2013-1705) Security Issue references: * CVE-2013-1737 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737> * CVE-2013-1735 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735> * CVE-2013-1736 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736> * CVE-2013-1732 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732> * CVE-2013-1730 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730> * CVE-2013-1726 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1726> * CVE-2013-1725 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725> * CVE-2013-1722 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722> * CVE-2013-1718 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718> * CVE-2013-1705 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1705>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150446-1/, https://bugzilla.suse.com/833389, https://bugzilla.suse.com/840485, https://bugzilla.suse.com/916196, https://bugzilla.suse.com/917100, https://bugzilla.suse.com/917300, https://bugzilla.suse.com/917597, https://www.suse.com/security/cve/CVE-2013-1701, https://www.suse.com/security/cve/CVE-2013-1702, https://www.suse.com/security/cve/CVE-2013-1705, https://www.suse.com/security/cve/CVE-2013-1706, https://www.suse.com/security/cve/CVE-2013-1707, https://www.suse.com/security/cve/CVE-2013-1709, https://www.suse.com/security/cve/CVE-2013-1710, https://www.suse.com/security/cve/CVE-2013-1712, https://www.suse.com/security/cve/CVE-2013-1713, https://www.suse.com/security/cve/CVE-2013-1714, https://www.suse.com/security/cve/CVE-2013-1717, https://www.suse.com/security/cve/CVE-2013-1718, https://www.suse.com/security/cve/CVE-2013-1722, https://www.suse.com/security/cve/CVE-2013-1725, https://www.suse.com/security/cve/CVE-2013-1726, https://www.suse.com/security/cve/CVE-2013-1730, https://www.suse.com/security/cve/CVE-2013-1732, https://www.suse.com/security/cve/CVE-2013-1735, https://www.suse.com/security/cve/CVE-2013-1736, https://www.suse.com/security/cve/CVE-2013-1737, https://www.suse.com/security/cve/CVE-2015-0822, https://www.suse.com/security/cve/CVE-2015-0827, https://www.suse.com/security/cve/CVE-2015-0831, https://www.suse.com/security/cve/CVE-2015-0836
