[SUSE-SU-2015:0447-1] Security update for Mozilla Firefox

Severity Moderate
Affected Packages 31
CVEs 24

Security update for Mozilla Firefox

This update to Firefox 17.0.9esr (bnc#840485) addresses:

* MFSA 2013-91 User-defined properties on DOM proxies get the wrong
  'this' object
      o (CVE-2013-1737)
* MFSA 2013-90 Memory corruption involving scrolling
      o use-after-free in mozilla::layout::ScrollbarActivity
        (CVE-2013-1735)
      o Memory corruption in nsGfxScrollFrameInner::IsLTR()
        (CVE-2013-1736)
* MFSA 2013-89 Buffer overflow with multi-column, lists, and floats
      o buffer overflow at nsFloatManager::GetFlowArea() with multicol,
        list, floats (CVE-2013-1732)
* MFSA 2013-88 compartment mismatch re-attaching XBL-backed nodes
      o compartment mismatch in nsXBLBinding::DoInitJSClass
        (CVE-2013-1730)
* MFSA 2013-83 Mozilla Updater does not lock MAR file after signature
  verification
      o MAR signature bypass in Updater could lead to downgrade
        (CVE-2013-1726)
* MFSA 2013-82 Calling scope for new Javascript objects can lead to
  memory corruption
      o ABORT: bad scope for new JSObjects: ReparentWrapper /
        document.open (CVE-2013-1725)
* MFSA 2013-79 Use-after-free in Animation Manager during stylesheet
  cloning
      o Heap-use-after-free in nsAnimationManager::BuildAnimations
        (CVE-2013-1722)
* MFSA 2013-76 Miscellaneous memory safety hazards (rv:24.0 /
  rv:17.0.9)
      o Memory safety bugs fixed in Firefox 17.0.9 and Firefox 24.0
        (CVE-2013-1718)
* MFSA 2013-65 Buffer underflow when generating CRMF requests
      o ASAN heap-buffer-overflow (read 1) in
        cryptojs_interpret_key_gen_type (CVE-2013-1705)

Security Issue references:

* CVE-2013-1737
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1737>
* CVE-2013-1735
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1735>
* CVE-2013-1736
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1736>
* CVE-2013-1732
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1732>
* CVE-2013-1730
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1730>
* CVE-2013-1726
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1726>
* CVE-2013-1725
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1725>
* CVE-2013-1722
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1722>
* CVE-2013-1718
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1718>
* CVE-2013-1705
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1705>
Package Affected Version
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-11&sp=1 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-11&sp=1 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox?arch=ppc64&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox?arch=ia64&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox?arch=i586&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox?arch=i586&distro=sles-11&sp=1 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sles-11&sp=1 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=s390x&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=s390x&distro=sles-11&sp=1 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=ppc64&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=ia64&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=i586&distro=sles-11&sp=2 < 17.0.9esr-0.3.1
pkg:rpm/suse/MozillaFirefox-translations?arch=i586&distro=sles-11&sp=1 < 17.0.9esr-0.3.1
pkg:rpm/suse/mozilla-xulrunner192?arch=x86_64&distro=sles-11&sp=1 < 1.9.2.24-0.3.1
pkg:rpm/suse/mozilla-xulrunner192-translations?arch=x86_64&distro=sles-11&sp=1 < 1.9.2.24-0.3.1
pkg:rpm/suse/mozilla-xulrunner192-gnome?arch=x86_64&distro=sles-11&sp=1 < 1.9.2.24-0.3.1
pkg:rpm/suse/mozilla-xulrunner192-32bit?arch=x86_64&distro=sles-11&sp=1 < 1.9.2.24-0.3.1
pkg:rpm/suse/mozilla-xulrunner191?arch=x86_64&distro=sles-11&sp=1 < 1.9.1.11-0.1.1
pkg:rpm/suse/mozilla-xulrunner191-translations?arch=x86_64&distro=sles-11&sp=1 < 1.9.1.11-0.1.1
pkg:rpm/suse/mozilla-xulrunner191-gnomevfs?arch=x86_64&distro=sles-11&sp=1 < 1.9.1.11-0.1.1
pkg:rpm/suse/mozilla-xulrunner191-32bit?arch=x86_64&distro=sles-11&sp=1 < 1.9.1.11-0.1.1
pkg:rpm/suse/mozilla-nss?arch=x86_64&distro=sles-11&sp=1 < 3.13.5-0.4.2
pkg:rpm/suse/mozilla-nss-tools?arch=x86_64&distro=sles-11&sp=1 < 3.13.5-0.4.2
pkg:rpm/suse/mozilla-nss-32bit?arch=x86_64&distro=sles-11&sp=1 < 3.13.5-0.4.2
pkg:rpm/suse/mozilla-nspr?arch=x86_64&distro=sles-11&sp=1 < 4.9.1-0.5.1
pkg:rpm/suse/mozilla-nspr-32bit?arch=x86_64&distro=sles-11&sp=1 < 4.9.1-0.5.1
pkg:rpm/suse/libfreebl3?arch=x86_64&distro=sles-11&sp=1 < 3.13.5-0.4.2
pkg:rpm/suse/libfreebl3-32bit?arch=x86_64&distro=sles-11&sp=1 < 3.13.5-0.4.2
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/suse-su-2015_0447-1.json
Suse URL for SUSE-SU-2015:0447-1 https://www.suse.com/support/update/announcement/2015/suse-su-20150447-1/
Suse E-Mail link for SUSE-SU-2015:0447-1 https://lists.suse.com/pipermail/sle-security-updates/2015-March/001273.html
Bugzilla SUSE Bug 833389 https://bugzilla.suse.com/833389
Bugzilla SUSE Bug 840485 https://bugzilla.suse.com/840485
Bugzilla SUSE Bug 917597 https://bugzilla.suse.com/917597
CVE SUSE CVE CVE-2013-1701 page https://www.suse.com/security/cve/CVE-2013-1701/
CVE SUSE CVE CVE-2013-1702 page https://www.suse.com/security/cve/CVE-2013-1702/
CVE SUSE CVE CVE-2013-1705 page https://www.suse.com/security/cve/CVE-2013-1705/
CVE SUSE CVE CVE-2013-1706 page https://www.suse.com/security/cve/CVE-2013-1706/
CVE SUSE CVE CVE-2013-1707 page https://www.suse.com/security/cve/CVE-2013-1707/
CVE SUSE CVE CVE-2013-1709 page https://www.suse.com/security/cve/CVE-2013-1709/
CVE SUSE CVE CVE-2013-1710 page https://www.suse.com/security/cve/CVE-2013-1710/
CVE SUSE CVE CVE-2013-1712 page https://www.suse.com/security/cve/CVE-2013-1712/
CVE SUSE CVE CVE-2013-1713 page https://www.suse.com/security/cve/CVE-2013-1713/
CVE SUSE CVE CVE-2013-1714 page https://www.suse.com/security/cve/CVE-2013-1714/
CVE SUSE CVE CVE-2013-1717 page https://www.suse.com/security/cve/CVE-2013-1717/
CVE SUSE CVE CVE-2013-1718 page https://www.suse.com/security/cve/CVE-2013-1718/
CVE SUSE CVE CVE-2013-1722 page https://www.suse.com/security/cve/CVE-2013-1722/
CVE SUSE CVE CVE-2013-1725 page https://www.suse.com/security/cve/CVE-2013-1725/
CVE SUSE CVE CVE-2013-1726 page https://www.suse.com/security/cve/CVE-2013-1726/
CVE SUSE CVE CVE-2013-1730 page https://www.suse.com/security/cve/CVE-2013-1730/
CVE SUSE CVE CVE-2013-1732 page https://www.suse.com/security/cve/CVE-2013-1732/
CVE SUSE CVE CVE-2013-1735 page https://www.suse.com/security/cve/CVE-2013-1735/
CVE SUSE CVE CVE-2013-1736 page https://www.suse.com/security/cve/CVE-2013-1736/
CVE SUSE CVE CVE-2013-1737 page https://www.suse.com/security/cve/CVE-2013-1737/
CVE SUSE CVE CVE-2015-0822 page https://www.suse.com/security/cve/CVE-2015-0822/
CVE SUSE CVE CVE-2015-0827 page https://www.suse.com/security/cve/CVE-2015-0827/
CVE SUSE CVE CVE-2015-0831 page https://www.suse.com/security/cve/CVE-2015-0831/
CVE SUSE CVE CVE-2015-0836 page https://www.suse.com/security/cve/CVE-2015-0836/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-11&sp=2 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-11&sp=1 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-11&sp=2 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-11&sp=1 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64&distro=sles-11&sp=2 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 ppc64
Affected pkg:rpm/suse/MozillaFirefox?arch=ia64&distro=sles-11&sp=2 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 ia64
Affected pkg:rpm/suse/MozillaFirefox?arch=i586&distro=sles-11&sp=2 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 i586
Affected pkg:rpm/suse/MozillaFirefox?arch=i586&distro=sles-11&sp=1 suse MozillaFirefox < 17.0.9esr-0.3.1 sles-11 i586
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sles-11&sp=2 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sles-11&sp=1 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=s390x&distro=sles-11&sp=2 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=s390x&distro=sles-11&sp=1 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=ppc64&distro=sles-11&sp=2 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 ppc64
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=ia64&distro=sles-11&sp=2 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 ia64
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=i586&distro=sles-11&sp=2 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 i586
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=i586&distro=sles-11&sp=1 suse MozillaFirefox-translations < 17.0.9esr-0.3.1 sles-11 i586
Affected pkg:rpm/suse/mozilla-xulrunner192?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner192 < 1.9.2.24-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-xulrunner192-translations?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner192-translations < 1.9.2.24-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-xulrunner192-gnome?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner192-gnome < 1.9.2.24-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-xulrunner192-32bit?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner192-32bit < 1.9.2.24-0.3.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-xulrunner191?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner191 < 1.9.1.11-0.1.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-xulrunner191-translations?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner191-translations < 1.9.1.11-0.1.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-xulrunner191-gnomevfs?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner191-gnomevfs < 1.9.1.11-0.1.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-xulrunner191-32bit?arch=x86_64&distro=sles-11&sp=1 suse mozilla-xulrunner191-32bit < 1.9.1.11-0.1.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nss?arch=x86_64&distro=sles-11&sp=1 suse mozilla-nss < 3.13.5-0.4.2 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nss-tools?arch=x86_64&distro=sles-11&sp=1 suse mozilla-nss-tools < 3.13.5-0.4.2 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nss-32bit?arch=x86_64&distro=sles-11&sp=1 suse mozilla-nss-32bit < 3.13.5-0.4.2 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nspr?arch=x86_64&distro=sles-11&sp=1 suse mozilla-nspr < 4.9.1-0.5.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nspr-32bit?arch=x86_64&distro=sles-11&sp=1 suse mozilla-nspr-32bit < 4.9.1-0.5.1 sles-11 x86_64
Affected pkg:rpm/suse/libfreebl3?arch=x86_64&distro=sles-11&sp=1 suse libfreebl3 < 3.13.5-0.4.2 sles-11 x86_64
Affected pkg:rpm/suse/libfreebl3-32bit?arch=x86_64&distro=sles-11&sp=1 suse libfreebl3-32bit < 3.13.5-0.4.2 sles-11 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...