Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:1099-1

Опубликовано: 24 апр. 2017
Источник: suse-cvrf

Описание

Security update for Mozilla Firefox

Mozilla Firefox was updated to Firefox 52.1.0esr.

The following vulnerabilities were fixed (bsc#1035082):

  • CVE-2017-5443: Out-of-bounds write during BinHex decoding
  • CVE-2017-5429: Memory safety bugs fixed in Firefox 53, Firefox ESR 45.9, and Firefox ESR 52.1
  • CVE-2017-5464: Memory corruption with accessibility and DOM manipulation
  • CVE-2017-5465: Out-of-bounds read in ConvolvePixel
  • CVE-2017-5466: Origin confusion when reloading isolated data:text/html URL
  • CVE-2017-5467: Memory corruption when drawing Skia content
  • CVE-2017-5460: Use-after-free in frame selection
  • CVE-2017-5461: Out-of-bounds write in Base64 encoding in NSS
  • CVE-2017-5448: Out-of-bounds write in ClearKeyDecryptor
  • CVE-2017-5449: Crash during bidirectional unicode manipulation with animation
  • CVE-2017-5446: Out-of-bounds read when HTTP/2 DATA frames are sent with incorrect data
  • CVE-2017-5447: Out-of-bounds read during glyph processing
  • CVE-2017-5444: Buffer overflow while parsing application/http-index-format content

The package is now following the ESR 52 branch:

  • Enable plugin support by default
  • service workers are disabled by default
  • push notifications are disabled by default
  • WebAssembly (wasm) is disabled
  • Less use of multiprocess architecture Electrolysis (e10s)

Список пакетов

openSUSE Leap 42.1
MozillaFirefox-52.1.0-57.6.1
MozillaFirefox-branding-upstream-52.1.0-57.6.1
MozillaFirefox-buildsymbols-52.1.0-57.6.1
MozillaFirefox-devel-52.1.0-57.6.1
MozillaFirefox-translations-common-52.1.0-57.6.1
MozillaFirefox-translations-other-52.1.0-57.6.1
openSUSE Leap 42.2
MozillaFirefox-52.1.0-57.6.1
MozillaFirefox-branding-upstream-52.1.0-57.6.1
MozillaFirefox-buildsymbols-52.1.0-57.6.1
MozillaFirefox-devel-52.1.0-57.6.1
MozillaFirefox-translations-common-52.1.0-57.6.1
MozillaFirefox-translations-other-52.1.0-57.6.1

Описание

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки

Описание

A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.


Затронутые продукты
openSUSE Leap 42.1:MozillaFirefox-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-branding-upstream-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-buildsymbols-52.1.0-57.6.1
openSUSE Leap 42.1:MozillaFirefox-devel-52.1.0-57.6.1

Ссылки