SUSE-SU-2015:0704-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0704-1
SUSE-SU-2015:0704-1
Summary: Security update for MozillaFirefox
Details: Mozilla Firefox was updated to 31.6.0 ESR to fix five security issues. The following vulnerabilities were fixed: * Miscellaneous memory safety hazards (MFSA 2015-30/CVE-2015-0814/CVE-2015-0815) * Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA 2015-31/CVE-2015-0813) * resource:// documents can load privileged pages (MFSA 2015-33/CVE-2015-0816) * CORS requests should not follow 30x redirections after preflight (MFSA 2015-37/CVE-2015-0807) * Same-origin bypass through anchor navigation (MFSA 2015-40/CVE-2015-0801)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150704-1/, https://bugzilla.suse.com/925368, https://www.suse.com/security/cve/CVE-2015-0801, https://www.suse.com/security/cve/CVE-2015-0807, https://www.suse.com/security/cve/CVE-2015-0813, https://www.suse.com/security/cve/CVE-2015-0814, https://www.suse.com/security/cve/CVE-2015-0815, https://www.suse.com/security/cve/CVE-2015-0816
Affected packages
Package
Name: MozillaFirefox
Purl: pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012
Affected ranges
Type: ECOSYSTEM
Events:
