SUSE Security Update: Security update for Mozilla Firefox
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:1325-2
Rating:             important
References:         #833389 
Affected Products:
                    SUSE Linux Enterprise Server 11 SP1 for VMware LTSS
                    SUSE Linux Enterprise Server 11 SP1 LTSS
                    SUSE Linux Enterprise Server 10 SP3 LTSS
______________________________________________________________________________

   An update that contains security fixes can now be
   installed. It includes four new package versions.

Description:


   This update to Firefox 17.0.8esr (bnc#833389) addresses the
   following  issues:

   * MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 (bmo#855331,
   bmo#844088, bmo#858060, bmo#870200, bmo#874974, bmo#861530,
   bmo#854157, bmo#893684, bmo#878703, bmo#862185, bmo#879139,
   bmo#888107, bmo#880734) Miscellaneous memory safety hazards
   (rv:23.0 / rv:17.0.8)
   * MFSA 2013-66/CVE-2013-1706/CVE-2013-1707 (bmo#888314,
   bmo#888361) Buffer overflow in Mozilla Maintenance Service
   and Mozilla Updater
   * MFSA 2013-68/CVE-2013-1709 (bmo#848253) Document URI
   misrepresentation and masquerading
   * MFSA 2013-69/CVE-2013-1710 (bmo#871368) CRMF requests
   allow for code execution and XSS attacks
   * MFSA 2013-71/CVE-2013-1712 (bmo#859072) Further
   Privilege escalation through Mozilla Updater
   * MFSA 2013-72/CVE-2013-1713 (bmo#887098) Wrong
   principal used for validating URI for some Javascript
   components
   * MFSA 2013-73/CVE-2013-1714 (bmo#879787) Same-origin
   bypass with web workers and XMLHttpRequest
   * MFSA 2013-75/CVE-2013-1717 (bmo#406541) Local Java
   applets may read contents of local file system


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server 11 SP1 for VMware LTSS:

      zypper in -t patch slessp1-MozillaFirefox-8188

   - SUSE Linux Enterprise Server 11 SP1 LTSS:

      zypper in -t patch slessp1-MozillaFirefox-8188

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server 11 SP1 for VMware LTSS (i586 x86_64) [New Version: 17.0.8esr]:

      MozillaFirefox-17.0.8esr-0.4.2.1
      MozillaFirefox-translations-17.0.8esr-0.4.2.1

   - SUSE Linux Enterprise Server 11 SP1 LTSS (i586 s390x x86_64) [New Version: 17.0.8esr]:

      MozillaFirefox-17.0.8esr-0.4.2.1
      MozillaFirefox-translations-17.0.8esr-0.4.2.1

   - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x x86_64) [New Version: 3.14.3 and 4.9.6]:

      mozilla-nspr-4.9.6-0.5.7
      mozilla-nspr-devel-4.9.6-0.5.7
      mozilla-nss-3.14.3-0.5.7
      mozilla-nss-devel-3.14.3-0.5.7
      mozilla-nss-tools-3.14.3-0.5.7

   - SUSE Linux Enterprise Server 10 SP3 LTSS (s390x x86_64) [New Version: 3.14.3 and 4.9.6]:

      mozilla-nspr-32bit-4.9.6-0.5.7
      mozilla-nss-32bit-3.14.3-0.5.7

   - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x) [New Version: 17.0.8esr and 7]:

      MozillaFirefox-17.0.8esr-0.5.3
      MozillaFirefox-branding-SLED-7-0.10.34
      MozillaFirefox-translations-17.0.8esr-0.5.3


References:

   https://bugzilla.novell.com/833389
   https://login.microfocus.com/nidp/app/login
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:1325-2: important: Mozilla Firefox

August 23, 2013
An update that contains security fixes can now be An update that contains security fixes can now be An update that contains security fixes can now be installed

Summary

This update to Firefox 17.0.8esr (bnc#833389) addresses the following issues: * MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 (bmo#855331, bmo#844088, bmo#858060, bmo#870200, bmo#874974, bmo#861530, bmo#854157, bmo#893684, bmo#878703, bmo#862185, bmo#879139, bmo#888107, bmo#880734) Miscellaneous memory safety hazards (rv:23.0 / rv:17.0.8) * MFSA 2013-66/CVE-2013-1706/CVE-2013-1707 (bmo#888314, bmo#888361) Buffer overflow in Mozilla Maintenance Service and Mozilla Updater * MFSA 2013-68/CVE-2013-1709 (bmo#848253) Document URI misrepresentation and masquerading * MFSA 2013-69/CVE-2013-1710 (bmo#871368) CRMF requests allow for code execution and XSS attacks * MFSA 2013-71/CVE-2013-1712 (bmo#859072) Further Privilege escalation through Mozilla Updater * MFSA 2013-72/CVE-2013-1713 (bmo#887098) Wrong principal used for validating URI for some Javascript components * MFSA 2013-73/CVE-2013-1714 (bmo#879787) Same-origin bypass wi...

Read the Full Advisory

References

#833389

Affected Products:

SUSE Linux Enterprise Server 11 SP1 for VMware LTSS

SUSE Linux Enterprise Server 11 SP1 LTSS

SUSE Linux Enterprise Server 10 SP3 LTSS

https://bugzilla.novell.com/833389

https://login.microfocus.com/nidp/app/login

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:1325-2
Rating: important

Related News