[openSUSE-SU-2020:2031-1] Security update for MozillaFirefox

Severity Important
Affected Packages 6
CVEs 12

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

  • Firefox Extended Support Release 78.5.0 ESR (bsc#1178824)
    • CVE-2020-26951: Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code
    • CVE-2020-16012: Variable time processing of cross-origin images during drawImage calls
    • CVE-2020-26953: Fullscreen could be enabled without displaying the security UI
    • CVE-2020-26956: XSS through paste (manual and clipboard API)
    • CVE-2020-26958: Requests intercepted through ServiceWorkers lacked MIME type restrictions
    • CVE-2020-26959: Use-after-free in WebRequestService
    • CVE-2020-26960: Potential use-after-free in uses of nsTArray
    • CVE-2020-15999: Heap buffer overflow in freetype
    • CVE-2020-26961: DoH did not filter IPv4 mapped IP Addresses
    • CVE-2020-26965: Software keyboards may have remembered typed passwords
    • CVE-2020-26966: Single-word search queries were also broadcast to local network
    • CVE-2020-26968: Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5

This update was imported from the SUSE:SLE-15:Update update project.

ID
openSUSE-SU-2020:2031-1
Severity
important
URL
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KX646YBHO2LBCWJZORVE6CWXY2DMCYHR/
Published
2020-11-26T13:48:42
(3 years ago)
Modified
2020-11-26T13:48:42
(3 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2020_2031-1.json
Suse URL for openSUSE-SU-2020:2031-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KX646YBHO2LBCWJZORVE6CWXY2DMCYHR/
Suse E-Mail link for openSUSE-SU-2020:2031-1 https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KX646YBHO2LBCWJZORVE6CWXY2DMCYHR/
Bugzilla SUSE Bug 1178824 https://bugzilla.suse.com/1178824
CVE SUSE CVE CVE-2020-15999 page https://www.suse.com/security/cve/CVE-2020-15999/
CVE SUSE CVE CVE-2020-16012 page https://www.suse.com/security/cve/CVE-2020-16012/
CVE SUSE CVE CVE-2020-26951 page https://www.suse.com/security/cve/CVE-2020-26951/
CVE SUSE CVE CVE-2020-26953 page https://www.suse.com/security/cve/CVE-2020-26953/
CVE SUSE CVE CVE-2020-26956 page https://www.suse.com/security/cve/CVE-2020-26956/
CVE SUSE CVE CVE-2020-26958 page https://www.suse.com/security/cve/CVE-2020-26958/
CVE SUSE CVE CVE-2020-26959 page https://www.suse.com/security/cve/CVE-2020-26959/
CVE SUSE CVE CVE-2020-26960 page https://www.suse.com/security/cve/CVE-2020-26960/
CVE SUSE CVE CVE-2020-26961 page https://www.suse.com/security/cve/CVE-2020-26961/
CVE SUSE CVE CVE-2020-26965 page https://www.suse.com/security/cve/CVE-2020-26965/
CVE SUSE CVE CVE-2020-26966 page https://www.suse.com/security/cve/CVE-2020-26966/
CVE SUSE CVE CVE-2020-26968 page https://www.suse.com/security/cve/CVE-2020-26968/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/MozillaFirefox?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox < 78.5.0-lp151.2.79.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-translations-other < 78.5.0-lp151.2.79.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-translations-common < 78.5.0-lp151.2.79.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-devel?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-devel < 78.5.0-lp151.2.79.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-buildsymbols?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-buildsymbols < 78.5.0-lp151.2.79.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=x86_64&distro=opensuse-leap-15.1 opensuse MozillaFirefox-branding-upstream < 78.5.0-lp151.2.79.1 opensuse-leap-15.1 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...