[SUSE-SU-2015:1476-1] Security update for MozillaFirefox, mozilla-nss
Severity
Important
Affected Packages
54
CVEs
16
Security update for MozillaFirefox, mozilla-nss
Mozilla Firefox was updated to version 38.2.1 ESR to fix several
critical and non critical security vulnerabilities.
Firefox was updated to 38.2.1 ESR (bsc#943608)
- MFSA 2015-94/CVE-2015-4497 (bsc#943557) Use-after-free when resizing canvas element during restyling
- MFSA 2015-95/CVE-2015-4498 (bsc#943558) Add-on notification bypass through data URLs
Firefox was updated to 38.2.0 ESR (bsc#940806)
- MFSA 2015-78/CVE-2015-4495 (bmo#1178058, bmo#1179262) Same origin violation and local file stealing via PDF reader
- MFSA 2015-79/CVE-2015-4473/CVE-2015-4474 (bmo#1143130, bmo#1161719, bmo#1177501, bmo#1181204, bmo#1184068, bmo#1188590, bmo#1146213, bmo#1178890, bmo#1182711) Miscellaneous memory safety hazards (rv:40.0 / rv:38.2)
- MFSA 2015-80/CVE-2015-4475 (bmo#1175396) Out-of-bounds read with malformed MP3 file
- MFSA 2015-82/CVE-2015-4478 (bmo#1105914) Redefinition of non-configurable JavaScript object properties
- MFSA 2015-83/CVE-2015-4479 (bmo#1185115, bmo#1144107, bmo#1170344, bmo#1186718) Overflow issues in libstagefright
- MFSA 2015-87/CVE-2015-4484 (bmo#1171540) Crash when using shared memory in JavaScript
- MFSA 2015-88/CVE-2015-4491 (bmo#1184009) Heap overflow in gdk-pixbuf when scaling bitmap images
- MFSA 2015-89/CVE-2015-4485/CVE-2015-4486 (bmo#1177948, bmo#1178148) Buffer overflows on Libvpx when decoding WebM video
- MFSA 2015-90/CVE-2015-4487/CVE-2015-4488/CVE-2015-4489 (bmo#1176270, bmo#1182723, bmo#1171603) Vulnerabilities found through code inspection
- MFSA 2015-92/CVE-2015-4492 (bmo#1185820) Use-after-free in XMLHttpRequest with shared workers
Mozilla NSS switched the CKBI ABI from 1.98 to 2.4, which is what Firefox 38ESR uses.
- ID
- SUSE-SU-2015:1476-1
- Severity
- important
- URL
- https://www.suse.com/support/update/announcement/2015/suse-su-20151476-1/
- Published
-
2015-09-01T17:33:17
(9 years ago) - Modified
-
2015-09-01T17:33:17
(9 years ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- CISA-2022:0525
- DSA-3333-1
- DSA-3337-1
- DSA-3337-2
- DSA-3345-1
- DSA-3410-1
- ELSA-2015-1581
- ELSA-2015-1586
- ELSA-2015-1682
- ELSA-2015-1693
- ELSA-2015-1694
- FEDORA-2015-13925
- FEDORA-2015-13926
- FEDORA-2015-14010
- FEDORA-2015-14011
- FREEBSD:237A201C-888B-487F-84D3-7D92266381D6
- FREEBSD:34E60332-2448-4ED6-93F0-12713749F250
- FREEBSD:8EEE06D4-C21D-4F07-A669-455151FF426F
- FREEBSD:C66A5632-708A-4727-8236-D65B2D5B2739
- FREEBSD:F5B8B670-465C-11E5-A49D-BCAEC565249C
- GLSA-201512-05
- GLSA-201512-10
- GLSA-201605-06
- RHSA-2015:1581
- RHSA-2015:1586
- RHSA-2015:1682
- RHSA-2015:1693
- RHSA-2015:1694
- SSA:2015-244-01
- SUSE-SU-2015:1379-1
- SUSE-SU-2015:1380-1
- SUSE-SU-2015:1449-1
- SUSE-SU-2015:1504-1
- SUSE-SU-2015:1528-1
- SUSE-SU-2015:1787-1
- SUSE-SU-2015:2195-1
- SUSE-SU-2015:2195-2
- SUSE-SU-2018:2145-1
- USN-2702-1
- USN-2707-1
- USN-2712-1
- USN-2722-1
- USN-2723-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12 | suse | MozillaFirefox | < 38.2.1esr-45.1 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sled-12 | suse | MozillaFirefox | < 38.2.1esr-45.1 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-12 | suse | MozillaFirefox | < 38.2.1esr-45.1 | sles-12 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-12 | suse | MozillaFirefox | < 38.2.1esr-45.1 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sles-12 | suse | MozillaFirefox-translations | < 38.2.1esr-45.1 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations?arch=x86_64&distro=sled-12 | suse | MozillaFirefox-translations | < 38.2.1esr-45.1 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations?arch=s390x&distro=sles-12 | suse | MozillaFirefox-translations | < 38.2.1esr-45.1 | sles-12 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations?arch=ppc64le&distro=sles-12 | suse | MozillaFirefox-translations | < 38.2.1esr-45.1 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-SLE?arch=x86_64&distro=sles-12 | suse | MozillaFirefox-branding-SLE | < 31.0-14.1 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-SLE?arch=x86_64&distro=sled-12 | suse | MozillaFirefox-branding-SLE | < 31.0-14.1 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-SLE?arch=s390x&distro=sles-12 | suse | MozillaFirefox-branding-SLE | < 31.0-14.1 | sles-12 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-SLE?arch=ppc64le&distro=sles-12 | suse | MozillaFirefox-branding-SLE | < 31.0-14.1 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/mozilla-nss?arch=x86_64&distro=sles-12 | suse | mozilla-nss | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss?arch=x86_64&distro=sled-12 | suse | mozilla-nss | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss?arch=s390x&distro=sles-12 | suse | mozilla-nss | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/mozilla-nss?arch=ppc64le&distro=sles-12 | suse | mozilla-nss | < 3.19.2.0-26.2 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/mozilla-nss-tools?arch=x86_64&distro=sles-12 | suse | mozilla-nss-tools | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-tools?arch=x86_64&distro=sled-12 | suse | mozilla-nss-tools | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-tools?arch=s390x&distro=sles-12 | suse | mozilla-nss-tools | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/mozilla-nss-tools?arch=ppc64le&distro=sles-12 | suse | mozilla-nss-tools | < 3.19.2.0-26.2 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/mozilla-nss-certs?arch=x86_64&distro=sles-12 | suse | mozilla-nss-certs | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-certs?arch=x86_64&distro=sled-12 | suse | mozilla-nss-certs | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-certs?arch=s390x&distro=sles-12 | suse | mozilla-nss-certs | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/mozilla-nss-certs?arch=ppc64le&distro=sles-12 | suse | mozilla-nss-certs | < 3.19.2.0-26.2 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/mozilla-nss-certs-32bit?arch=x86_64&distro=sles-12 | suse | mozilla-nss-certs-32bit | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-certs-32bit?arch=x86_64&distro=sled-12 | suse | mozilla-nss-certs-32bit | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-certs-32bit?arch=s390x&distro=sles-12 | suse | mozilla-nss-certs-32bit | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/mozilla-nss-32bit?arch=x86_64&distro=sles-12 | suse | mozilla-nss-32bit | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-32bit?arch=x86_64&distro=sled-12 | suse | mozilla-nss-32bit | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/mozilla-nss-32bit?arch=s390x&distro=sles-12 | suse | mozilla-nss-32bit | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libsoftokn3?arch=x86_64&distro=sles-12 | suse | libsoftokn3 | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libsoftokn3?arch=x86_64&distro=sled-12 | suse | libsoftokn3 | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/libsoftokn3?arch=s390x&distro=sles-12 | suse | libsoftokn3 | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libsoftokn3?arch=ppc64le&distro=sles-12 | suse | libsoftokn3 | < 3.19.2.0-26.2 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/libsoftokn3-hmac?arch=x86_64&distro=sles-12 | suse | libsoftokn3-hmac | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libsoftokn3-hmac?arch=s390x&distro=sles-12 | suse | libsoftokn3-hmac | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libsoftokn3-hmac?arch=ppc64le&distro=sles-12 | suse | libsoftokn3-hmac | < 3.19.2.0-26.2 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/libsoftokn3-hmac-32bit?arch=x86_64&distro=sles-12 | suse | libsoftokn3-hmac-32bit | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libsoftokn3-hmac-32bit?arch=s390x&distro=sles-12 | suse | libsoftokn3-hmac-32bit | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libsoftokn3-32bit?arch=x86_64&distro=sles-12 | suse | libsoftokn3-32bit | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libsoftokn3-32bit?arch=x86_64&distro=sled-12 | suse | libsoftokn3-32bit | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/libsoftokn3-32bit?arch=s390x&distro=sles-12 | suse | libsoftokn3-32bit | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libfreebl3?arch=x86_64&distro=sles-12 | suse | libfreebl3 | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libfreebl3?arch=x86_64&distro=sled-12 | suse | libfreebl3 | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/libfreebl3?arch=s390x&distro=sles-12 | suse | libfreebl3 | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libfreebl3?arch=ppc64le&distro=sles-12 | suse | libfreebl3 | < 3.19.2.0-26.2 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/libfreebl3-hmac?arch=x86_64&distro=sles-12 | suse | libfreebl3-hmac | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libfreebl3-hmac?arch=s390x&distro=sles-12 | suse | libfreebl3-hmac | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libfreebl3-hmac?arch=ppc64le&distro=sles-12 | suse | libfreebl3-hmac | < 3.19.2.0-26.2 | sles-12 | ppc64le | |
Affected | pkg:rpm/suse/libfreebl3-hmac-32bit?arch=x86_64&distro=sles-12 | suse | libfreebl3-hmac-32bit | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libfreebl3-hmac-32bit?arch=s390x&distro=sles-12 | suse | libfreebl3-hmac-32bit | < 3.19.2.0-26.2 | sles-12 | s390x | |
Affected | pkg:rpm/suse/libfreebl3-32bit?arch=x86_64&distro=sles-12 | suse | libfreebl3-32bit | < 3.19.2.0-26.2 | sles-12 | x86_64 | |
Affected | pkg:rpm/suse/libfreebl3-32bit?arch=x86_64&distro=sled-12 | suse | libfreebl3-32bit | < 3.19.2.0-26.2 | sled-12 | x86_64 | |
Affected | pkg:rpm/suse/libfreebl3-32bit?arch=s390x&distro=sles-12 | suse | libfreebl3-32bit | < 3.19.2.0-26.2 | sles-12 | s390x |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |