Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0929-1

Опубликовано: 06 апр. 2020
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

  • Mozilla Firefox 68.6.1esr MFSA 2020-11 (bsc#1168630)
    • CVE-2020-6819 (bmo#1620818) Use-after-free while running the nsDocShell destructor
    • CVE-2020-6820 (bmo#1626728) Use-after-free when handling a ReadableStream

Список пакетов

SUSE Linux Enterprise Module for Desktop Applications 15 SP1
MozillaFirefox-68.6.1-3.81.1
MozillaFirefox-devel-68.6.1-3.81.1
MozillaFirefox-translations-common-68.6.1-3.81.1
MozillaFirefox-translations-other-68.6.1-3.81.1

Описание

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-68.6.1-3.81.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-devel-68.6.1-3.81.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-translations-common-68.6.1-3.81.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-translations-other-68.6.1-3.81.1

Ссылки

Описание

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-68.6.1-3.81.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-devel-68.6.1-3.81.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-translations-common-68.6.1-3.81.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP1:MozillaFirefox-translations-other-68.6.1-3.81.1

Ссылки