SUSE-SU-2015:0706-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0706-1
SUSE-SU-2015:0706-1
Summary: Security update for Mozilla Firefox
Details: Mozilla Firefox was updated to 31.6.0 ESR to fix five security issues. The following vulnerabilities have been fixed: * Miscellaneous memory safety hazards (MFSA 2015-30/CVE-2015-0814/CVE-2015-0815) * Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA 2015-31/CVE-2015-0813) * resource:// documents can load privileged pages (MFSA 2015-33/CVE-2015-0816) * CORS requests should not follow 30x redirections after preflight (MFSA 2015-37/CVE-2015-0807) * Same-origin bypass through anchor navigation (MFSA 2015-40/CVE-2015-0801) Security Issues: * CVE-2015-0801 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0801> * CVE-2015-0807 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0807> * CVE-2015-0813 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0813> * CVE-2015-0814 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0814> * CVE-2015-0816 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0816>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150706-1/, https://bugzilla.suse.com/925368, https://www.suse.com/security/cve/CVE-2015-0801, https://www.suse.com/security/cve/CVE-2015-0807, https://www.suse.com/security/cve/CVE-2015-0813, https://www.suse.com/security/cve/CVE-2015-0814, https://www.suse.com/security/cve/CVE-2015-0816
