Описание
Security update for MozillaFirefox
This update to MozillaFirefox 38.8.0 ESR fixes the following issues (bsc#977333):
- CVE-2016-2805: Miscellaneous memory safety hazards - MFSA 2016-39 (bsc#977374)
- CVE-2016-2807: Miscellaneous memory safety hazards - MFSA 2016-39 (bsc#977376)
- CVE-2016-2814: Buffer overflow in libstagefright with CENC offsets - MFSA 2016-44 (bsc#977381)
- CVE-2016-2808: Write to invalid HashMap entry through JavaScript.watch() - MFSA 2016-47 (bsc#977386)
Список пакетов
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Software Development Kit 12 SP1
Ссылки
- Link for SUSE-SU-2016:1258-1
- E-Mail link for SUSE-SU-2016:1258-1
- SUSE Security Ratings
- SUSE Bug 977333
- SUSE Bug 977374
- SUSE Bug 977376
- SUSE Bug 977381
- SUSE Bug 977386
- SUSE CVE CVE-2016-2805 page
- SUSE CVE CVE-2016-2807 page
- SUSE CVE CVE-2016-2808 page
- SUSE CVE CVE-2016-2814 page
Описание
Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Затронутые продукты
Ссылки
- CVE-2016-2805
- SUSE Bug 977333
- SUSE Bug 977374
Описание
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Затронутые продукты
Ссылки
- CVE-2016-2807
- SUSE Bug 977333
- SUSE Bug 977376
Описание
The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code or cause a denial of service (generation-count overflow, out-of-bounds HashMap write access, and application crash) via a crafted web site.
Затронутые продукты
Ссылки
- CVE-2016-2808
- SUSE Bug 977333
- SUSE Bug 977386
Описание
Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table.
Затронутые продукты
Ссылки
- CVE-2016-2814
- SUSE Bug 977333
- SUSE Bug 977381