gpp_maybe
Security update for mozillafirefox
SUSE-SLE-SAP-12-2017-392
This update for MozillaFirefox to ESR 45.8 fixes the following issues: Security issues fixed (bsc#1028391): - CVE-2017-5402: Use-after-free working with events in FontFace objects - CVE-2017-5410: Memory corruption during JavaScript garbage collection incremental sweeping - CVE-2017-5400: asm.js JIT-spray bypass of ASLR and DEP - CVE-2017-5401: Memory Corruption when handling ErrorResult - CVE-2017-5407: Pixel and history stealing via floating-point timing side channel with SVG filters - CVE-2017-5404: Use-after-free working with ranges in selections - CVE-2017-5405: FTP response codes can cause use of uninitialized values for ports - CVE-2017-5408: Cross-origin reading of video captions in violation of CORS - CVE-2017-5409: File deletion via callback parameter in Mozilla Windows Updater and Maintenance Service - CVE-2017-5398: Memory safety bugs fixed in Firefox 52 and Firefox ESR 45.8
-
Release DateMar 17 2017
-
ReferencesBugzilla: 1028391
CVEs: CVE-2017-5398, CVE-2017-5409, CVE-2017-5408, CVE-2017-5405, CVE-2017-5404, CVE-2017-5407, CVE-2017-5401, CVE-2017-5400, CVE-2017-5410, CVE-2017-5402 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12 x86_64
-
PackagesMozillaFirefox
Mozilla Firefox Web BrowserMozillaFirefox-translations45.8.0esr-102.1 lock rpm lock src
Translations for Firefox45.8.0esr-102.1 lock rpm