Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0928-1

Опубликовано: 06 апр. 2020
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

  • Mozilla Firefox 68.6.1esr MFSA 2020-11 (bsc#1168630)
    • CVE-2020-6819 (bmo#1620818) Use-after-free while running the nsDocShell destructor
    • CVE-2020-6820 (bmo#1626728) Use-after-free when handling a ReadableStream

Список пакетов

HPE Helion OpenStack 8
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Enterprise Storage 5
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server 12 SP1-LTSS
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-devel-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server 12 SP2-BCL
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-devel-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server 12 SP2-LTSS
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-devel-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server 12 SP3-BCL
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server 12 SP3-LTSS
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server 12 SP4
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server 12 SP5
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-devel-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-devel-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Linux Enterprise Software Development Kit 12 SP4
MozillaFirefox-devel-68.6.1-109.113.1
SUSE Linux Enterprise Software Development Kit 12 SP5
MozillaFirefox-devel-68.6.1-109.113.1
SUSE OpenStack Cloud 7
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-devel-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE OpenStack Cloud 8
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE OpenStack Cloud Crowbar 8
MozillaFirefox-68.6.1-109.113.1
MozillaFirefox-translations-common-68.6.1-109.113.1

Описание

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-68.6.1-109.113.1
HPE Helion OpenStack 8:MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Enterprise Storage 5:MozillaFirefox-68.6.1-109.113.1
SUSE Enterprise Storage 5:MozillaFirefox-translations-common-68.6.1-109.113.1

Ссылки

Описание

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-68.6.1-109.113.1
HPE Helion OpenStack 8:MozillaFirefox-translations-common-68.6.1-109.113.1
SUSE Enterprise Storage 5:MozillaFirefox-68.6.1-109.113.1
SUSE Enterprise Storage 5:MozillaFirefox-translations-common-68.6.1-109.113.1

Ссылки