openSUSE-SU-2019:0248-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:0248-1
openSUSE-SU-2019:0248-1
Summary: Security update for MozillaFirefox
Details: This update for MozillaFirefox to version 60.5.1esr fixes the following issues: Security vulnerabilities addressed (MFSA-2019-05, boo#1125330): - CVE-2018-18356: Fixed a use-after-free vulnerability in the Skia library that could occur when creating a path, leading to a potentially exploitable crash. - CVE-2019-5785: Fixed an integer overflow vulnerability in the Skia library that could occur after specific transform operations, leading to a potentially exploitable crash.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/XMFECNQD7OR7OS7QMHOXX2IJDRTXXZP5/#XMFECNQD7OR7OS7QMHOXX2IJDRTXXZP5, https://bugzilla.suse.com/1125330, https://www.suse.com/security/cve/CVE-2018-18356, https://www.suse.com/security/cve/CVE-2019-5785
