[SUSE-SU-2015:1268-1] Security update for MozillaFirefox, mozilla-nspr, mozilla-nss

Severity Important
Affected Packages 51
CVEs 17

Security update for MozillaFirefox, mozilla-nspr, mozilla-nss

MozillaFirefox, mozilla-nspr and mozilla-nss were updated to fix 17 security issues.

For more details please check the changelogs.

These security issues were fixed:
- CVE-2015-2724/CVE-2015-2725/CVE-2015-2726: Miscellaneous memory safety hazards (bsc#935979).
- CVE-2015-2728: Type confusion in Indexed Database Manager (bsc#935979).
- CVE-2015-2730: ECDSA signature validation fails to handle some signatures correctly (bsc#935979).
- CVE-2015-2722/CVE-2015-2733: Use-after-free in workers while using XMLHttpRequest (bsc#935979).
- CVE-2015-2734/CVE-2015-2735/CVE-2015-2736/CVE-2015-2737/CVE-2015-2738/CVE-2015-2739/CVE-2015-2740: Vulnerabilities found through code inspection (bsc#935979).
- CVE-2015-2743: Privilege escalation in PDF.js (bsc#935979).
- CVE-2015-4000: NSS accepts export-length DHE keys with regular DHE cipher suites (bsc#935033).
- CVE-2015-2721: NSS incorrectly permits skipping of ServerKeyExchange (bsc#935979).

This non-security issue was fixed:
- bsc#908275: Firefox did not print in landscape orientation.

Package Affected Version
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox?arch=ppc64&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox?arch=ia64&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox?arch=i586&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox-translations?arch=s390x&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox-translations?arch=ppc64&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox-translations?arch=ia64&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/MozillaFirefox-translations?arch=i586&distro=sles-11&sp=4 < 31.8.0esr-0.10.1
pkg:rpm/suse/mozilla-nss?arch=x86_64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss?arch=s390x&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss?arch=ppc64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss?arch=ia64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss?arch=i586&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-x86?arch=ia64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-tools?arch=x86_64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-tools?arch=s390x&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-tools?arch=ppc64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-tools?arch=ia64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-tools?arch=i586&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-32bit?arch=x86_64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-32bit?arch=s390x&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nss-32bit?arch=ppc64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/mozilla-nspr?arch=x86_64&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr?arch=s390x&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr?arch=ppc64&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr?arch=ia64&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr?arch=i586&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr-x86?arch=ia64&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr-32bit?arch=x86_64&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr-32bit?arch=s390x&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/mozilla-nspr-32bit?arch=ppc64&distro=sles-11&sp=4 < 4.10.8-0.5.1
pkg:rpm/suse/libsoftokn3?arch=x86_64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3?arch=s390x&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3?arch=ppc64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3?arch=ia64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3?arch=i586&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3-x86?arch=ia64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3-32bit?arch=x86_64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3-32bit?arch=s390x&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libsoftokn3-32bit?arch=ppc64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3?arch=x86_64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3?arch=s390x&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3?arch=ppc64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3?arch=ia64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3?arch=i586&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3-x86?arch=ia64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3-32bit?arch=x86_64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3-32bit?arch=s390x&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
pkg:rpm/suse/libfreebl3-32bit?arch=ppc64&distro=sles-11&sp=4 < 3.19.2_CKBI_1.98-0.10.1
ID
SUSE-SU-2015:1268-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2015/suse-su-20151268-1/
Published
2015-07-15T18:13:44
(9 years ago)
Modified
2015-07-15T18:13:44
(9 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/suse-su-2015_1268-1.json
Suse URL for SUSE-SU-2015:1268-1 https://www.suse.com/support/update/announcement/2015/suse-su-20151268-1/
Suse E-Mail link for SUSE-SU-2015:1268-1 https://lists.suse.com/pipermail/sle-security-updates/2015-July/001501.html
Bugzilla SUSE Bug 908275 https://bugzilla.suse.com/908275
Bugzilla SUSE Bug 935033 https://bugzilla.suse.com/935033
Bugzilla SUSE Bug 935979 https://bugzilla.suse.com/935979
CVE SUSE CVE CVE-2015-2721 page https://www.suse.com/security/cve/CVE-2015-2721/
CVE SUSE CVE CVE-2015-2722 page https://www.suse.com/security/cve/CVE-2015-2722/
CVE SUSE CVE CVE-2015-2724 page https://www.suse.com/security/cve/CVE-2015-2724/
CVE SUSE CVE CVE-2015-2725 page https://www.suse.com/security/cve/CVE-2015-2725/
CVE SUSE CVE CVE-2015-2726 page https://www.suse.com/security/cve/CVE-2015-2726/
CVE SUSE CVE CVE-2015-2728 page https://www.suse.com/security/cve/CVE-2015-2728/
CVE SUSE CVE CVE-2015-2730 page https://www.suse.com/security/cve/CVE-2015-2730/
CVE SUSE CVE CVE-2015-2733 page https://www.suse.com/security/cve/CVE-2015-2733/
CVE SUSE CVE CVE-2015-2734 page https://www.suse.com/security/cve/CVE-2015-2734/
CVE SUSE CVE CVE-2015-2735 page https://www.suse.com/security/cve/CVE-2015-2735/
CVE SUSE CVE CVE-2015-2736 page https://www.suse.com/security/cve/CVE-2015-2736/
CVE SUSE CVE CVE-2015-2737 page https://www.suse.com/security/cve/CVE-2015-2737/
CVE SUSE CVE CVE-2015-2738 page https://www.suse.com/security/cve/CVE-2015-2738/
CVE SUSE CVE CVE-2015-2739 page https://www.suse.com/security/cve/CVE-2015-2739/
CVE SUSE CVE CVE-2015-2740 page https://www.suse.com/security/cve/CVE-2015-2740/
CVE SUSE CVE CVE-2015-2743 page https://www.suse.com/security/cve/CVE-2015-2743/
CVE SUSE CVE CVE-2015-4000 page https://www.suse.com/security/cve/CVE-2015-4000/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-11&sp=4 suse MozillaFirefox < 31.8.0esr-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-11&sp=4 suse MozillaFirefox < 31.8.0esr-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64&distro=sles-11&sp=4 suse MozillaFirefox < 31.8.0esr-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/MozillaFirefox?arch=ia64&distro=sles-11&sp=4 suse MozillaFirefox < 31.8.0esr-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/MozillaFirefox?arch=i586&distro=sles-11&sp=4 suse MozillaFirefox < 31.8.0esr-0.10.1 sles-11 i586
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sles-11&sp=4 suse MozillaFirefox-translations < 31.8.0esr-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=s390x&distro=sles-11&sp=4 suse MozillaFirefox-translations < 31.8.0esr-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=ppc64&distro=sles-11&sp=4 suse MozillaFirefox-translations < 31.8.0esr-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=ia64&distro=sles-11&sp=4 suse MozillaFirefox-translations < 31.8.0esr-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/MozillaFirefox-translations?arch=i586&distro=sles-11&sp=4 suse MozillaFirefox-translations < 31.8.0esr-0.10.1 sles-11 i586
Affected pkg:rpm/suse/mozilla-nss?arch=x86_64&distro=sles-11&sp=4 suse mozilla-nss < 3.19.2_CKBI_1.98-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nss?arch=s390x&distro=sles-11&sp=4 suse mozilla-nss < 3.19.2_CKBI_1.98-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/mozilla-nss?arch=ppc64&distro=sles-11&sp=4 suse mozilla-nss < 3.19.2_CKBI_1.98-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/mozilla-nss?arch=ia64&distro=sles-11&sp=4 suse mozilla-nss < 3.19.2_CKBI_1.98-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/mozilla-nss?arch=i586&distro=sles-11&sp=4 suse mozilla-nss < 3.19.2_CKBI_1.98-0.10.1 sles-11 i586
Affected pkg:rpm/suse/mozilla-nss-x86?arch=ia64&distro=sles-11&sp=4 suse mozilla-nss-x86 < 3.19.2_CKBI_1.98-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/mozilla-nss-tools?arch=x86_64&distro=sles-11&sp=4 suse mozilla-nss-tools < 3.19.2_CKBI_1.98-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nss-tools?arch=s390x&distro=sles-11&sp=4 suse mozilla-nss-tools < 3.19.2_CKBI_1.98-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/mozilla-nss-tools?arch=ppc64&distro=sles-11&sp=4 suse mozilla-nss-tools < 3.19.2_CKBI_1.98-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/mozilla-nss-tools?arch=ia64&distro=sles-11&sp=4 suse mozilla-nss-tools < 3.19.2_CKBI_1.98-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/mozilla-nss-tools?arch=i586&distro=sles-11&sp=4 suse mozilla-nss-tools < 3.19.2_CKBI_1.98-0.10.1 sles-11 i586
Affected pkg:rpm/suse/mozilla-nss-32bit?arch=x86_64&distro=sles-11&sp=4 suse mozilla-nss-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nss-32bit?arch=s390x&distro=sles-11&sp=4 suse mozilla-nss-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/mozilla-nss-32bit?arch=ppc64&distro=sles-11&sp=4 suse mozilla-nss-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/mozilla-nspr?arch=x86_64&distro=sles-11&sp=4 suse mozilla-nspr < 4.10.8-0.5.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nspr?arch=s390x&distro=sles-11&sp=4 suse mozilla-nspr < 4.10.8-0.5.1 sles-11 s390x
Affected pkg:rpm/suse/mozilla-nspr?arch=ppc64&distro=sles-11&sp=4 suse mozilla-nspr < 4.10.8-0.5.1 sles-11 ppc64
Affected pkg:rpm/suse/mozilla-nspr?arch=ia64&distro=sles-11&sp=4 suse mozilla-nspr < 4.10.8-0.5.1 sles-11 ia64
Affected pkg:rpm/suse/mozilla-nspr?arch=i586&distro=sles-11&sp=4 suse mozilla-nspr < 4.10.8-0.5.1 sles-11 i586
Affected pkg:rpm/suse/mozilla-nspr-x86?arch=ia64&distro=sles-11&sp=4 suse mozilla-nspr-x86 < 4.10.8-0.5.1 sles-11 ia64
Affected pkg:rpm/suse/mozilla-nspr-32bit?arch=x86_64&distro=sles-11&sp=4 suse mozilla-nspr-32bit < 4.10.8-0.5.1 sles-11 x86_64
Affected pkg:rpm/suse/mozilla-nspr-32bit?arch=s390x&distro=sles-11&sp=4 suse mozilla-nspr-32bit < 4.10.8-0.5.1 sles-11 s390x
Affected pkg:rpm/suse/mozilla-nspr-32bit?arch=ppc64&distro=sles-11&sp=4 suse mozilla-nspr-32bit < 4.10.8-0.5.1 sles-11 ppc64
Affected pkg:rpm/suse/libsoftokn3?arch=x86_64&distro=sles-11&sp=4 suse libsoftokn3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/libsoftokn3?arch=s390x&distro=sles-11&sp=4 suse libsoftokn3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/libsoftokn3?arch=ppc64&distro=sles-11&sp=4 suse libsoftokn3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/libsoftokn3?arch=ia64&distro=sles-11&sp=4 suse libsoftokn3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/libsoftokn3?arch=i586&distro=sles-11&sp=4 suse libsoftokn3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 i586
Affected pkg:rpm/suse/libsoftokn3-x86?arch=ia64&distro=sles-11&sp=4 suse libsoftokn3-x86 < 3.19.2_CKBI_1.98-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/libsoftokn3-32bit?arch=x86_64&distro=sles-11&sp=4 suse libsoftokn3-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/libsoftokn3-32bit?arch=s390x&distro=sles-11&sp=4 suse libsoftokn3-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/libsoftokn3-32bit?arch=ppc64&distro=sles-11&sp=4 suse libsoftokn3-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/libfreebl3?arch=x86_64&distro=sles-11&sp=4 suse libfreebl3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/libfreebl3?arch=s390x&distro=sles-11&sp=4 suse libfreebl3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/libfreebl3?arch=ppc64&distro=sles-11&sp=4 suse libfreebl3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 ppc64
Affected pkg:rpm/suse/libfreebl3?arch=ia64&distro=sles-11&sp=4 suse libfreebl3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/libfreebl3?arch=i586&distro=sles-11&sp=4 suse libfreebl3 < 3.19.2_CKBI_1.98-0.10.1 sles-11 i586
Affected pkg:rpm/suse/libfreebl3-x86?arch=ia64&distro=sles-11&sp=4 suse libfreebl3-x86 < 3.19.2_CKBI_1.98-0.10.1 sles-11 ia64
Affected pkg:rpm/suse/libfreebl3-32bit?arch=x86_64&distro=sles-11&sp=4 suse libfreebl3-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 x86_64
Affected pkg:rpm/suse/libfreebl3-32bit?arch=s390x&distro=sles-11&sp=4 suse libfreebl3-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 s390x
Affected pkg:rpm/suse/libfreebl3-32bit?arch=ppc64&distro=sles-11&sp=4 suse libfreebl3-32bit < 3.19.2_CKBI_1.98-0.10.1 sles-11 ppc64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...