SUSE-SU-2015:0978-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0978-1
SUSE-SU-2015:0978-1
Summary: Security update for MozillaFirefox
Details: This update to Firefox 31.7.0 ESR fixes the following issues: * MFSA 2015-46 (CVE-2015-2708, CVE-2015-2709): Miscellaneous memory safety hazards (rv:38.0 / rv:31.7). Upstream references: bmo#1120655, bmo#1143299, bmo#1151139, bmo#1152177, bmo#1111251, bmo#1117977, bmo#1128064, bmo#1135066, bmo#1143194, bmo#1146101, bmo#1149526, bmo#1153688, bmo#1155474. * MFSA 2015-47 (CVE-2015-0797): Buffer overflow parsing H.264 video with Linux Gstreamer. Upstream references: bmo#1080995. * MFSA 2015-48 (CVE-2015-2710): Buffer overflow with SVG content and CSS. Upstream references: bmo#1149542. * MFSA 2015-51 (CVE-2015-2713): Use-after-free during text processing with vertical text enabled. Upstream references: bmo#1153478. * MFSA 2015-54 (CVE-2015-2716): Buffer overflow when parsing compressed XML. Upstream references: bmo#1140537. Security Issues: * CVE-2015-0797 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0797> * CVE-2015-2708 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2708> * CVE-2015-2709 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2709> * CVE-2015-2710 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2710> * CVE-2015-2713 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2713> * CVE-2015-2716 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2716>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150978-1/, https://bugzilla.suse.com/930622, https://www.suse.com/security/cve/CVE-2015-0797, https://www.suse.com/security/cve/CVE-2015-2708, https://www.suse.com/security/cve/CVE-2015-2709, https://www.suse.com/security/cve/CVE-2015-2710, https://www.suse.com/security/cve/CVE-2015-2713, https://www.suse.com/security/cve/CVE-2015-2716
