SUSE Security Update: Security update for Mozilla Firefox
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0470-1
Rating:             important
References:         #808243 
Cross-References:   CVE-2013-0787
Affected Products:
                    SUSE Linux Enterprise Server 11 SP2 for VMware
                    SUSE Linux Enterprise Server 11 SP2
                    SUSE Linux Enterprise Desktop 11 SP2
______________________________________________________________________________

   An update that fixes one vulnerability is now available. It
   includes one version update.

Description:


   MozillaFirefox has been updated to the 17.0.4ESR release
   which fixes one  important security issue:

   * MFSA 2013-29 / CVE-2013-0787: VUPEN Security, via
   TippingPoint's Zero Day Initiative, reported a
   use-after-free within the HTML editor when content script
   is run by the document.execCommand() function while
   internal editor operations are occurring. This could allow
   for arbitrary code execution.

   Security Issue reference:

   * CVE-2013-0787
   


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server 11 SP2 for VMware:

      zypper in -t patch slessp2-firefox-201303-7464

   - SUSE Linux Enterprise Server 11 SP2:

      zypper in -t patch slessp2-firefox-201303-7464

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-firefox-201303-7464

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 17.0.4esr]:

      MozillaFirefox-17.0.4esr-0.5.1
      MozillaFirefox-translations-17.0.4esr-0.5.1

   - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 17.0.4esr]:

      MozillaFirefox-17.0.4esr-0.5.1
      MozillaFirefox-translations-17.0.4esr-0.5.1

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 17.0.4esr]:

      MozillaFirefox-17.0.4esr-0.5.1
      MozillaFirefox-translations-17.0.4esr-0.5.1


References:

   https://www.suse.com/security/cve/CVE-2013-0787.html
   https://bugzilla.novell.com/808243
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:0470-1: important: Mozilla Firefox

March 15, 2013
An update that fixes one vulnerability is now available

Summary

MozillaFirefox has been updated to the 17.0.4ESR release which fixes one important security issue: * MFSA 2013-29 / CVE-2013-0787: VUPEN Security, via TippingPoint's Zero Day Initiative, reported a use-after-free within the HTML editor when content script is run by the document.execCommand() function while internal editor operations are occurring. This could allow for arbitrary code execution. Security Issue reference: * CVE-2013-0787 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 for VMware: zypper in -t patch slessp2-firefox-201303-7464 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-firefox-201303-7464 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-firefox-201303-7464 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 17.0.4esr]: MozillaFirefox-17.0.4esr-0.5.1 MozillaFirefox-translations-17.0.4esr-0.5.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 17.0.4esr]: MozillaFirefox-17.0.4esr-0.5.1 MozillaFirefox-translations-17.0.4esr-0.5.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 17.0.4esr]: MozillaFirefox-17.0.4esr-0.5.1 MozillaFirefox-translations-17.0.4esr-0.5.1

References

#808243

Cross- CVE-2013-0787

Affected Products:

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2013-0787.html

https://bugzilla.novell.com/808243

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:0470-1
Rating: important

Related News