Описание
Security update for MozillaFirefox
This update to Firefox 31.7.0 ESR fixes the following issues:
Security Issues:
Список пакетов
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP3
Ссылки
- Link for SUSE-SU-2015:0978-1
- E-Mail link for SUSE-SU-2015:0978-1
- SUSE Security Ratings
- SUSE Bug 930622
- SUSE CVE CVE-2015-0797 page
- SUSE CVE CVE-2015-2708 page
- SUSE CVE CVE-2015-2709 page
- SUSE CVE CVE-2015-2710 page
- SUSE CVE CVE-2015-2713 page
- SUSE CVE CVE-2015-2716 page
Описание
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
Затронутые продукты
Ссылки
- CVE-2015-0797
- SUSE Bug 927559
- SUSE Bug 930622
Описание
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Затронутые продукты
Ссылки
- CVE-2015-2708
- SUSE Bug 930622
Описание
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Затронутые продукты
Ссылки
- CVE-2015-2709
- SUSE Bug 930622
Описание
Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
Затронутые продукты
Ссылки
- CVE-2015-2710
- SUSE Bug 930622
Описание
Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text.
Затронутые продукты
Ссылки
- CVE-2015-2713
- SUSE Bug 930622
Описание
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
Затронутые продукты
Ссылки
- CVE-2015-2716
- SUSE Bug 930622
- SUSE Bug 939077
- SUSE Bug 980391
- SUSE Bug 983985