[openSUSE-SU-2020:0493-1] Security update for MozillaFirefox

Severity Important
Affected Packages 6
CVEs 5

Security update for MozillaFirefox

This update for MozillaFirefox to version 68.7.0 ESR fixes the following issues:

  • CVE-2020-6821: Uninitialized memory could be read when using the WebGL copyTexSubImage method (bsc#1168874).
  • CVE-2020-6822: Fixed out of bounds write in GMPDecodeData when processing large images (bsc#1168874).
  • CVE-2020-6825: Fixed Memory safety bugs (bsc#1168874).
  • CVE-2020-6827: Custom Tabs could have the URI spoofed (bsc#1168874).
  • CVE-2020-6828: Preference overwrite via crafted Intent (bsc#1168874).

This update was imported from the SUSE:SLE-15:Update update project.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/MozillaFirefox?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox < 68.7.0-lp151.2.42.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-translations-other < 68.7.0-lp151.2.42.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-translations-common < 68.7.0-lp151.2.42.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-devel?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-devel < 68.7.0-lp151.2.42.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-buildsymbols?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-buildsymbols < 68.7.0-lp151.2.42.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-branding-upstream < 68.7.0-lp151.2.42.1 opensuse-leap-15.1 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...