Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0446-1

Опубликовано: 19 сент. 2013
Источник: suse-cvrf

Описание

Security update for Mozilla Firefox

This update to Firefox 17.0.9esr (bnc#840485) addresses:

* MFSA 2013-91 User-defined properties on DOM proxies get the wrong 'this' object o (CVE-2013-1737) * MFSA 2013-90 Memory corruption involving scrolling o use-after-free in mozilla::layout::ScrollbarActivity (CVE-2013-1735) o Memory corruption in nsGfxScrollFrameInner::IsLTR() (CVE-2013-1736) * MFSA 2013-89 Buffer overflow with multi-column, lists, and floats o buffer overflow at nsFloatManager::GetFlowArea() with multicol, list, floats (CVE-2013-1732) * MFSA 2013-88 compartment mismatch re-attaching XBL-backed nodes o compartment mismatch in nsXBLBinding::DoInitJSClass (CVE-2013-1730) * MFSA 2013-83 Mozilla Updater does not lock MAR file after signature verification o MAR signature bypass in Updater could lead to downgrade (CVE-2013-1726) * MFSA 2013-82 Calling scope for new Javascript objects can lead to memory corruption o ABORT: bad scope for new JSObjects: ReparentWrapper / document.open (CVE-2013-1725) * MFSA 2013-79 Use-after-free in Animation Manager during stylesheet cloning o Heap-use-after-free in nsAnimationManager::BuildAnimations (CVE-2013-1722) * MFSA 2013-76 Miscellaneous memory safety hazards (rv:24.0 / rv:17.0.9) o Memory safety bugs fixed in Firefox 17.0.9 and Firefox 24.0 (CVE-2013-1718) * MFSA 2013-65 Buffer underflow when generating CRMF requests o ASAN heap-buffer-overflow (read 1) in cryptojs_interpret_key_gen_type (CVE-2013-1705)

Security Issue references:

* CVE-2013-1737 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737> * CVE-2013-1735 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735> * CVE-2013-1736 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736> * CVE-2013-1732 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732> * CVE-2013-1730 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730> * CVE-2013-1726 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1726> * CVE-2013-1725 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725> * CVE-2013-1722 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722> * CVE-2013-1718 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718> * CVE-2013-1705 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1705>

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
MozillaFirefox-17.0.9esr-0.7.1
MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3
MozillaFirefox-17.0.9esr-0.7.1
MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
MozillaFirefox-17.0.9esr-0.7.1
MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3
MozillaFirefox-17.0.9esr-0.7.1
MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Software Development Kit 11 SP3
MozillaFirefox-devel-17.0.9esr-0.7.1

Описание

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in a previously visited document.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message Format (CRMF) request generation.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update directory or (2) the current working directory.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons via a crafted web site.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspecified vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving stylesheet cloning.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion failure and application exit) via a crafted web site.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via vectors related to image-document scrolling.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to improperly establishing parent-child relationships of range-request nodes.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки

Описание

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Desktop 11 SP3:MozillaFirefox-translations-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-17.0.9esr-0.7.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:MozillaFirefox-translations-17.0.9esr-0.7.1

Ссылки
Уязвимость SUSE-SU-2015:0446-1