Описание
Security update for Mozilla Firefox
Mozilla Firefox was updated to 49.0.2 to fix two security issues a some bugs.
The following vulnerabilities were fixed:
- CVE-2016-5287: Crash in nsTArray_base (bsc#1006475)
- CVE-2016-5288: Web content can read cache entries (bsc#1006476)
The following changes and fixes are included:
- Asynchronous rendering of the Flash plugins is now enabled by default
- Change D3D9 default fallback preference to prevent graphical artifacts
- Network issue prevents some users from seeing the Firefox UI on startup
- Web compatibility issue with file uploads
- Web compatibility issue with Array.prototype.values
- Diagnostic information on timing for tab switching
- Fix a Canvas filters graphics issue affecting HTML5 apps
Список пакетов
openSUSE Leap 42.1
MozillaFirefox-49.0.2-36.1
MozillaFirefox-branding-upstream-49.0.2-36.1
MozillaFirefox-buildsymbols-49.0.2-36.1
MozillaFirefox-devel-49.0.2-36.1
MozillaFirefox-translations-common-49.0.2-36.1
MozillaFirefox-translations-other-49.0.2-36.1
Ссылки
- Link for SUSE-SU-2016:2639-1
- E-Mail link for SUSE-SU-2016:2639-1
- SUSE Security Ratings
Описание
A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.
Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-devel-49.0.2-36.1
Ссылки
- CVE-2016-5287
- SUSE Bug 1006475
Описание
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-devel-49.0.2-36.1
Ссылки
- CVE-2016-5288
- SUSE Bug 1006476