SUSE-SU-2018:1334-2
Dashboard / Vulnerabilities / SUSE-SU-2018:1334-2
SUSE-SU-2018:1334-2
Summary: Security update for MozillaFirefox
Details: This update for MozillaFirefox to the ESR 52.8 release fixes the following issues: Mozil to Firefox ESR 52.8 (bsc#1092548) Security issues fixed: - MFSA 2018-12/CVE-2018-5159: Integer overflow and out-of-bounds write in Skia - MFSA 2018-12/CVE-2018-5158: Malicious PDF can inject JavaScript into PDF Viewer - MFSA 2018-12/CVE-2018-5168: Lightweight themes can be installed without user interaction - MFSA 2018-12/CVE-2018-5150: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8 - MFSA 2018-12/CVE-2018-5155: Use-after-free with SVG animations and text paths - MFSA 2018-12/CVE-2018-5183: Backport critical security fixes in Skia - MFSA 2018-12/CVE-2018-5157: Same-origin bypass of PDF Viewer to view protected PDF files - MFSA 2018-12/CVE-2018-5154: Use-after-free with SVG animations and clip paths - MFSA 2018-12/CVE-2018-5178: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
References: https://www.suse.com/support/update/announcement/2018/suse-su-20181334-2/, https://bugzilla.suse.com/1092548, https://www.suse.com/security/cve/CVE-2018-5150, https://www.suse.com/security/cve/CVE-2018-5154, https://www.suse.com/security/cve/CVE-2018-5155, https://www.suse.com/security/cve/CVE-2018-5157, https://www.suse.com/security/cve/CVE-2018-5158, https://www.suse.com/security/cve/CVE-2018-5159, https://www.suse.com/security/cve/CVE-2018-5168, https://www.suse.com/security/cve/CVE-2018-5174, https://www.suse.com/security/cve/CVE-2018-5178, https://www.suse.com/security/cve/CVE-2018-5183
Affected packages
Package
Name: MozillaFirefox
Purl: pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL
Affected ranges
Type: ECOSYSTEM
Events:
