SUSE-SU-2017:2872-2
Dashboard / Vulnerabilities / SUSE-SU-2017:2872-2
SUSE-SU-2017:2872-2
Summary: Security update for MozillaFirefox, mozilla-nss
Details: This update for MozillaFirefox and mozilla-nss fixes the following issues: Mozilla Firefox was updated to ESR 52.4 (bsc#1060445) * MFSA 2017-22/CVE-2017-7825: OS X fonts render some Tibetan and Arabic unicode characters as spaces * MFSA 2017-22/CVE-2017-7805: Use-after-free in TLS 1.2 generating handshake hashes * MFSA 2017-22/CVE-2017-7819: Use-after-free while resizing images in design mode * MFSA 2017-22/CVE-2017-7818: Use-after-free during ARIA array manipulation * MFSA 2017-22/CVE-2017-7793: Use-after-free with Fetch API * MFSA 2017-22/CVE-2017-7824: Buffer overflow when drawing and validating elements with ANGLE * MFSA 2017-22/CVE-2017-7810: Memory safety bugs fixed in Firefox 56 and Firefox ESR 52.4 * MFSA 2017-22/CVE-2017-7823: CSP sandbox directive did not create a unique origin * MFSA 2017-22/CVE-2017-7814: Blob and data URLs bypass phishing and malware protection warnings Mozilla Network Security Services (Mozilla NSS) received a security fix: * MFSA 2017-22/CVE-2017-7805: Use-after-free in TLS 1.2 generating handshake hashes (bsc#1061005, bsc#1060445)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20172872-2/, https://bugzilla.suse.com/1060445, https://bugzilla.suse.com/1061005, https://www.suse.com/security/cve/CVE-2017-7793, https://www.suse.com/security/cve/CVE-2017-7805, https://www.suse.com/security/cve/CVE-2017-7810, https://www.suse.com/security/cve/CVE-2017-7814, https://www.suse.com/security/cve/CVE-2017-7818, https://www.suse.com/security/cve/CVE-2017-7819, https://www.suse.com/security/cve/CVE-2017-7823, https://www.suse.com/security/cve/CVE-2017-7824, https://www.suse.com/security/cve/CVE-2017-7825
Affected packages
Package
Name: MozillaFirefox
Purl: pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
