SUSE Security Update: Security update for Mozilla Firefox
______________________________________________________________________________

Announcement ID:    SUSE-SU-2012:1426-1
Rating:             important
References:         #786522 
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP2
                    SUSE Linux Enterprise Server 11 SP2 for VMware
                    SUSE Linux Enterprise Server 11 SP2
                    SUSE Linux Enterprise Server 10 SP4
                    SUSE Linux Enterprise Desktop 11 SP2
                    SUSE Linux Enterprise Desktop 10 SP4
                    SLE SDK 10 SP4
______________________________________________________________________________

   An update that contains security fixes can now be
   installed. It includes two new package versions.

Description:


   MozillaFirefox was updated to the 10.0.10ESR security
   release.

   The following issues have been fixed:

   *

   MFSA 2012-90: Mozilla has fixed a number of issues
   related to the Location object in order to enhance overall
   security. Details for each of the current fixed issues are
   below.

   Thunderbird is only affected by window.location
   issues through RSS feeds and extensions that load web
   content.

   *

   CVE-2012-4194: Security researcher Mariusz Mlynski
   reported that the true value of window.location could be
   shadowed by user content through the use of the valueOf
   method, which can be combined with some plugins to perform
   a cross-site scripting (XSS) attack on users.

   *

   CVE-2012-4195: Mozilla security researcher
   moz_bug_r_a4 discovered that the CheckURL function in
   window.location can be forced to return the wrong calling
   document and principal, allowing a cross-site scripting
   (XSS) attack. There is also the possibility of gaining
   arbitrary code execution if the attacker can take advantage
   of an add-on that interacts with the page content.

   *

   CVE-2012-4196: Security researcher Antoine
   Delignat-Lavaud of the PROSECCO research team at INRIA
   Paris reported the ability to use property injection by
   prototype to bypass security wrapper protections on the
   Location object, allowing the cross-origin reading of the
   Location object.


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP2:

      zypper in -t patch sdksp2-firefox-201210b-7004

   - SUSE Linux Enterprise Server 11 SP2 for VMware:

      zypper in -t patch slessp2-firefox-201210b-7004

   - SUSE Linux Enterprise Server 11 SP2:

      zypper in -t patch slessp2-firefox-201210b-7004

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-firefox-201210b-7004

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 4.9.3]:

      mozilla-nspr-devel-4.9.3-0.2.1

   - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 10.0.10 and 4.9.3]:

      MozillaFirefox-10.0.10-0.3.1
      MozillaFirefox-translations-10.0.10-0.3.1
      mozilla-nspr-4.9.3-0.2.1

   - SUSE Linux Enterprise Server 11 SP2 for VMware (x86_64) [New Version: 4.9.3]:

      mozilla-nspr-32bit-4.9.3-0.2.1

   - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 10.0.10 and 4.9.3]:

      MozillaFirefox-10.0.10-0.3.1
      MozillaFirefox-translations-10.0.10-0.3.1
      mozilla-nspr-4.9.3-0.2.1

   - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64) [New Version: 4.9.3]:

      mozilla-nspr-32bit-4.9.3-0.2.1

   - SUSE Linux Enterprise Server 11 SP2 (ia64) [New Version: 4.9.3]:

      mozilla-nspr-x86-4.9.3-0.2.1

   - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64) [New Version: 4.9.3]:

      mozilla-nspr-4.9.3-0.5.1
      mozilla-nspr-devel-4.9.3-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x):

      MozillaFirefox-10.0.10-0.5.2
      MozillaFirefox-translations-10.0.10-0.5.2

   - SUSE Linux Enterprise Server 10 SP4 (s390x x86_64) [New Version: 4.9.3]:

      mozilla-nspr-32bit-4.9.3-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (ia64) [New Version: 4.9.3]:

      mozilla-nspr-x86-4.9.3-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (ppc) [New Version: 4.9.3]:

      mozilla-nspr-64bit-4.9.3-0.5.1

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 10.0.10 and 4.9.3]:

      MozillaFirefox-10.0.10-0.3.1
      MozillaFirefox-translations-10.0.10-0.3.1
      mozilla-nspr-4.9.3-0.2.1

   - SUSE Linux Enterprise Desktop 11 SP2 (x86_64) [New Version: 4.9.3]:

      mozilla-nspr-32bit-4.9.3-0.2.1

   - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64) [New Version: 4.9.3]:

      mozilla-nspr-4.9.3-0.5.1
      mozilla-nspr-devel-4.9.3-0.5.1

   - SUSE Linux Enterprise Desktop 10 SP4 (x86_64) [New Version: 4.9.3]:

      mozilla-nspr-32bit-4.9.3-0.5.1

   - SUSE Linux Enterprise Desktop 10 SP4 (i586):

      MozillaFirefox-10.0.10-0.5.2
      MozillaFirefox-translations-10.0.10-0.5.2

   - SLE SDK 10 SP4 (i586 ia64 ppc s390x):

      MozillaFirefox-branding-upstream-10.0.10-0.5.2


References:

   https://bugzilla.novell.com/786522
   https://login.microfocus.com/nidp/app/login
   https://login.microfocus.com/nidp/app/login

SuSE: 2012:1426-1: important: Mozilla Firefox

October 31, 2012
An update that contains security fixes can now be An update that contains security fixes can now be An update that contains security fixes can now be installed

Summary

MozillaFirefox was updated to the 10.0.10ESR security release. The following issues have been fixed: * MFSA 2012-90: Mozilla has fixed a number of issues related to the Location object in order to enhance overall security. Details for each of the current fixed issues are below. Thunderbird is only affected by window.location issues through RSS feeds and extensions that load web content. * CVE-2012-4194: Security researcher Mariusz Mlynski reported that the true value of window.location could be shadowed by user content through the use of the valueOf method, which can be combined with some plugins to perform a cross-site scripting (XSS) attack on users. * CVE-2012-4195: Mozilla security researcher moz_bug_r_a4 discovered that the CheckURL function in window.location can be forced to return the wrong calling document and principal, allowing a cross-site scripting (XSS) attack. There is also the possibility of gaining arbitrary code execution if the attacker can take advantage of an add-on that interacts with the page content. * CVE-2012-4196: Security researcher Antoine Delignat-Lavaud of the PROSECCO research team at INRIA Paris reported the ability to use property injection by prototype to bypass security wrapper protections on the Location object, allowing the cross-origin reading of the Location object. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-firefox-201210b-7004 - SUSE Linux Enterprise Server 11 SP2 for VMware: zypper in -t patch slessp2-firefox-201210b-7004 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-firefox-201210b-7004 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-firefox-201210b-7004 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 4.9.3]: mozilla-nspr-devel-4.9.3-0.2.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 10.0.10 and 4.9.3]: MozillaFirefox-10.0.10-0.3.1 MozillaFirefox-translations-10.0.10-0.3.1 mozilla-nspr-4.9.3-0.2.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (x86_64) [New Version: 4.9.3]: mozilla-nspr-32bit-4.9.3-0.2.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 10.0.10 and 4.9.3]: MozillaFirefox-10.0.10-0.3.1 MozillaFirefox-translations-10.0.10-0.3.1 mozilla-nspr-4.9.3-0.2.1 - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64) [New Version: 4.9.3]: mozilla-nspr-32bit-4.9.3-0.2.1 - SUSE Linux Enterprise Server 11 SP2 (ia64) [New Version: 4.9.3]: mozilla-nspr-x86-4.9.3-0.2.1 - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64) [New Version: 4.9.3]: mozilla-nspr-4.9.3-0.5.1 mozilla-nspr-devel-4.9.3-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x): MozillaFirefox-10.0.10-0.5.2 MozillaFirefox-translations-10.0.10-0.5.2 - SUSE Linux Enterprise Server 10 SP4 (s390x x86_64) [New Version: 4.9.3]: mozilla-nspr-32bit-4.9.3-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (ia64) [New Version: 4.9.3]: mozilla-nspr-x86-4.9.3-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (ppc) [New Version: 4.9.3]: mozilla-nspr-64bit-4.9.3-0.5.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 10.0.10 and 4.9.3]: MozillaFirefox-10.0.10-0.3.1 MozillaFirefox-translations-10.0.10-0.3.1 mozilla-nspr-4.9.3-0.2.1 - SUSE Linux Enterprise Desktop 11 SP2 (x86_64) [New Version: 4.9.3]: mozilla-nspr-32bit-4.9.3-0.2.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64) [New Version: 4.9.3]: mozilla-nspr-4.9.3-0.5.1 mozilla-nspr-devel-4.9.3-0.5.1 - SUSE Linux Enterprise Desktop 10 SP4 (x86_64) [New Version: 4.9.3]: mozilla-nspr-32bit-4.9.3-0.5.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586): MozillaFirefox-10.0.10-0.5.2 MozillaFirefox-translations-10.0.10-0.5.2 - SLE SDK 10 SP4 (i586 ia64 ppc s390x): MozillaFirefox-branding-upstream-10.0.10-0.5.2

References

#786522

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 11 SP2

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://bugzilla.novell.com/786522

https://login.microfocus.com/nidp/app/login

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2012:1426-1
Rating: important

Related News