Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:1504-1

Опубликовано: 04 сент. 2015
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

Mozilla Firefox was updated to 38.2.1 ESR, fixing two severe security bugs. (bsc#943608)

  • MFSA 2015-94/CVE-2015-4497 (bsc#943557): Use-after-free when resizing canvas element during restyling
  • MFSA 2015-95/CVE-2015-4498 (bsc#943558): Add-on notification bypass through data URLs

Список пакетов

SUSE Linux Enterprise Server 11 SP1-LTSS
MozillaFirefox-38.2.1esr-17.1
MozillaFirefox-translations-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP1-TERADATA
MozillaFirefox-38.2.1esr-17.1
MozillaFirefox-translations-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP2-LTSS
MozillaFirefox-38.2.1esr-17.1
MozillaFirefox-translations-38.2.1esr-17.1

Описание

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP1-LTSS:MozillaFirefox-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP1-LTSS:MozillaFirefox-translations-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP1-TERADATA:MozillaFirefox-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP1-TERADATA:MozillaFirefox-translations-38.2.1esr-17.1

Ссылки

Описание

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP1-LTSS:MozillaFirefox-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP1-LTSS:MozillaFirefox-translations-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP1-TERADATA:MozillaFirefox-38.2.1esr-17.1
SUSE Linux Enterprise Server 11 SP1-TERADATA:MozillaFirefox-translations-38.2.1esr-17.1

Ссылки