Описание
Security update for Mozilla Firefox
Mozilla Firefox was updated to Firefox 52.1.0esr.
The following vulnerabilities were fixed (bsc#1035082):
- CVE-2017-5443: Out-of-bounds write during BinHex decoding
- CVE-2017-5429: Memory safety bugs fixed in Firefox 53, Firefox ESR 45.9, and Firefox ESR 52.1
- CVE-2017-5464: Memory corruption with accessibility and DOM manipulation
- CVE-2017-5465: Out-of-bounds read in ConvolvePixel
- CVE-2017-5466: Origin confusion when reloading isolated data:text/html URL
- CVE-2017-5467: Memory corruption when drawing Skia content
- CVE-2017-5460: Use-after-free in frame selection
- CVE-2017-5461: Out-of-bounds write in Base64 encoding in NSS
- CVE-2017-5448: Out-of-bounds write in ClearKeyDecryptor
- CVE-2017-5449: Crash during bidirectional unicode manipulation with animation
- CVE-2017-5446: Out-of-bounds read when HTTP/2 DATA frames are sent with incorrect data
- CVE-2017-5447: Out-of-bounds read during glyph processing
- CVE-2017-5444: Buffer overflow while parsing application/http-index-format content
The package is now following the ESR 52 branch:
- Enable plugin support by default
- service workers are disabled by default
- push notifications are disabled by default
- WebAssembly (wasm) is disabled
- Less use of multiprocess architecture Electrolysis (e10s)
Список пакетов
openSUSE Leap 42.1
openSUSE Leap 42.2
Ссылки
- E-Mail link for openSUSE-SU-2017:1099-1
- SUSE Security Ratings
Описание
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5429
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5443
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5444
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5446
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5447
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5448
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5449
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5460
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
Затронутые продукты
Ссылки
- CVE-2017-5461
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5464
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5465
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5466
- SUSE Bug 1035082
- SUSE Bug 1035209
Описание
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
Затронутые продукты
Ссылки
- CVE-2017-5467
- SUSE Bug 1035082
- SUSE Bug 1035209