SuSE: 2013:0843-1: important: Mozilla Firefox
Summary
Mozilla Firefox has been updated to the 17.0.6ESR security release. * MFSA 2013-30: Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan Sreckovic, and Joe Drew reported memory safety problems and crashes that affect Firefox ESR 17, and Firefox 19. (CVE-2013-0788) * MFSA 2013-31 / CVE-2013-0800: Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover an out-of-bounds write in Cairo graphics library. When certain values are passed to it during rendering, Cairo attempts to use negative boundaries or sizes for box...
Read the Full AdvisoryReferences
#755821 #792432 #819204
Cross- CVE-2013-0788 CVE-2013-0791 CVE-2013-0792
CVE-2013-0793 CVE-2013-0794 CVE-2013-0795
CVE-2013-0796 CVE-2013-0797 CVE-2013-0799
CVE-2013-0800
Affected Products:
SUSE Linux Enterprise Server 10 SP4
SUSE Linux Enterprise Desktop 10 SP4
SLE SDK 10 SP4
https://www.suse.com/security/cve/CVE-2013-0788.html
https://www.suse.com/security/cve/CVE-2013-0791.html
https://www.suse.com/security/cve/CVE-2013-0792.html
https://www.suse.com/security/cve/CVE-2013-0793.html
https://www.suse.com/security/cve/CVE-2013-0794.html
https://www.suse.com/security/cve/CVE-2013-0795.html
https://www.suse.com/security/cve/CVE-2013-0796.html
https://www.suse.com/security/cve/CVE-2013-0797.html
https://www.suse.com/security/cve/CVE-2013-0799.html
https://www.suse.com/security/cve/CVE-2013-0800.html
https://bugzilla.novell.com/755821
https:...
Read the Full Advisory