Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:2639-1

Опубликовано: 24 окт. 2016
Источник: suse-cvrf

Описание

Security update for Mozilla Firefox

Mozilla Firefox was updated to 49.0.2 to fix two security issues a some bugs.

The following vulnerabilities were fixed:

  • CVE-2016-5287: Crash in nsTArray_base (bsc#1006475)
  • CVE-2016-5288: Web content can read cache entries (bsc#1006476)

The following changes and fixes are included:

  • Asynchronous rendering of the Flash plugins is now enabled by default
  • Change D3D9 default fallback preference to prevent graphical artifacts
  • Network issue prevents some users from seeing the Firefox UI on startup
  • Web compatibility issue with file uploads
  • Web compatibility issue with Array.prototype.values
  • Diagnostic information on timing for tab switching
  • Fix a Canvas filters graphics issue affecting HTML5 apps

Список пакетов

openSUSE Leap 42.1
MozillaFirefox-49.0.2-36.1
MozillaFirefox-branding-upstream-49.0.2-36.1
MozillaFirefox-buildsymbols-49.0.2-36.1
MozillaFirefox-devel-49.0.2-36.1
MozillaFirefox-translations-common-49.0.2-36.1
MozillaFirefox-translations-other-49.0.2-36.1

Ссылки

Описание

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-devel-49.0.2-36.1

Ссылки

Описание

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-49.0.2-36.1
openSUSE Leap 42.1:MozillaFirefox-devel-49.0.2-36.1

Ссылки