Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:0203-1

Опубликовано: 24 янв. 2018
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

  • update to Firefox 52.6esr (boo#1077291) MFSA 2018-01

    • Speculative execution side-channel attack ('Spectre') MFSA 2018-03
    • CVE-2018-5091 (bmo#1423086) Use-after-free with DTMF timers
    • CVE-2018-5095 (bmo#1418447) Integer overflow in Skia library during edge builder allocation
    • CVE-2018-5096 (bmo#1418922) Use-after-free while editing form elements
    • CVE-2018-5097 (bmo#1387427) Use-after-free when source document is manipulated during XSLT
    • CVE-2018-5098 (bmo#1399400) Use-after-free while manipulating form input elements
    • CVE-2018-5099 (bmo#1416878) Use-after-free with widget listener
    • CVE-2018-5102 (bmo#1419363) Use-after-free in HTML media elements
    • CVE-2018-5103 (bmo#1423159) Use-after-free during mouse event handling
    • CVE-2018-5104 (bmo#1425000) Use-after-free during font face manipulation
    • CVE-2018-5117 (bmo#1395508) URL spoofing with right-to-left text aligned left-to-right
    • CVE-2018-5089 Memory safety bugs fixed in Firefox 58 and Firefox ESR 52.6
  • Added additional patches and configurations to fix builds on s390 and PowerPC.

    • Added firefox-glibc-getrandom.patch effecting builds on s390 and PowerPC
    • Added mozilla-s390-bigendian.patch along with icudt58b.dat bigendian ICU data file for running Firefox on bigendian architectures (bmo#1322212 and bmo#1264836)
    • Added mozilla-s390-nojit.patch to enable atomic operations used by the JS engine when JIT is disabled on s390
    • Build configuration options specific to s390
    • Requires NSS >= 3.29.5

Список пакетов

openSUSE Leap 42.2
MozillaFirefox-52.6-75.1
MozillaFirefox-branding-upstream-52.6-75.1
MozillaFirefox-buildsymbols-52.6-75.1
MozillaFirefox-devel-52.6-75.1
MozillaFirefox-translations-common-52.6-75.1
MozillaFirefox-translations-other-52.6-75.1
openSUSE Leap 42.3
MozillaFirefox-52.6-75.1
MozillaFirefox-branding-upstream-52.6-75.1
MozillaFirefox-buildsymbols-52.6-75.1
MozillaFirefox-devel-52.6-75.1
MozillaFirefox-translations-common-52.6-75.1
MozillaFirefox-translations-other-52.6-75.1

Описание

Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки

Описание

If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.


Затронутые продукты
openSUSE Leap 42.2:MozillaFirefox-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-branding-upstream-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-buildsymbols-52.6-75.1
openSUSE Leap 42.2:MozillaFirefox-devel-52.6-75.1

Ссылки