SUSE Security Update: Security update for Mozilla Firefox
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:1382-1
Rating:             important
References:         #833389 
Cross-References:   CVE-2013-1701 CVE-2013-1702 CVE-2013-1706
                    CVE-2013-1707 CVE-2013-1709 CVE-2013-1710
                    CVE-2013-1712 CVE-2013-1713 CVE-2013-1714
                    CVE-2013-1717
Affected Products:
                    SUSE Linux Enterprise Server 10 SP4 LTSS
______________________________________________________________________________

   An update that fixes 10 vulnerabilities is now available.
   It includes one version update.

Description:


   Update to Firefox 17.0.8esr (bnc#833389) to address:

   * MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 (bmo#855331,
   bmo#844088, bmo#858060, bmo#870200, bmo#874974, bmo#861530,
   bmo#854157, bmo#893684, bmo#878703, bmo#862185, bmo#879139,
   bmo#888107, bmo#880734) Miscellaneous memory safety hazards
   (rv:23.0 / rv:17.0.8)
   * MFSA 2013-66/CVE-2013-1706/CVE-2013-1707 (bmo#888314,
   bmo#888361) Buffer overflow in Mozilla Maintenance Service
   and Mozilla Updater
   * MFSA 2013-68/CVE-2013-1709 (bmo#848253) Document URI
   misrepresentation and masquerading
   * MFSA 2013-69/CVE-2013-1710 (bmo#871368) CRMF requests
   allow for code execution and XSS attacks
   * MFSA 2013-71/CVE-2013-1712 (bmo#859072) Further
   Privilege escalation through Mozilla Updater
   * MFSA 2013-72/CVE-2013-1713 (bmo#887098) Wrong
   principal used for validating URI for some Javascript
   components
   * MFSA 2013-73/CVE-2013-1714 (bmo#879787) Same-origin
   bypass with web workers and XMLHttpRequest
   * MFSA 2013-75/CVE-2013-1717 (bmo#406541) Local Java
   applets may read contents of local file system

   Security Issue references:

   * CVE-2013-1701
   
   * CVE-2013-1702
   
   * CVE-2013-1706
   
   * CVE-2013-1707
   
   * CVE-2013-1709
   
   * CVE-2013-1710
   
   * CVE-2013-1712
   
   * CVE-2013-1713
   
   * CVE-2013-1714
   
   * CVE-2013-1717
   



Package List:

   - SUSE Linux Enterprise Server 10 SP4 LTSS (i586 s390x) [New Version: 17.0.8esr]:

      MozillaFirefox-17.0.8esr-0.5.1
      MozillaFirefox-translations-17.0.8esr-0.5.1


References:

   https://www.suse.com/security/cve/CVE-2013-1701.html
   https://www.suse.com/security/cve/CVE-2013-1702.html
   https://www.suse.com/security/cve/CVE-2013-1706.html
   https://www.suse.com/security/cve/CVE-2013-1707.html
   https://www.suse.com/security/cve/CVE-2013-1709.html
   https://www.suse.com/security/cve/CVE-2013-1710.html
   https://www.suse.com/security/cve/CVE-2013-1712.html
   https://www.suse.com/security/cve/CVE-2013-1713.html
   https://www.suse.com/security/cve/CVE-2013-1714.html
   https://www.suse.com/security/cve/CVE-2013-1717.html
   https://bugzilla.novell.com/833389
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:1382-1: important: Mozilla Firefox

August 27, 2013
An update that fixes 10 vulnerabilities is now available

Summary

Update to Firefox 17.0.8esr (bnc#833389) to address: * MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 (bmo#855331, bmo#844088, bmo#858060, bmo#870200, bmo#874974, bmo#861530, bmo#854157, bmo#893684, bmo#878703, bmo#862185, bmo#879139, bmo#888107, bmo#880734) Miscellaneous memory safety hazards (rv:23.0 / rv:17.0.8) * MFSA 2013-66/CVE-2013-1706/CVE-2013-1707 (bmo#888314, bmo#888361) Buffer overflow in Mozilla Maintenance Service and Mozilla Updater * MFSA 2013-68/CVE-2013-1709 (bmo#848253) Document URI misrepresentation and masquerading * MFSA 2013-69/CVE-2013-1710 (bmo#871368) CRMF requests allow for code execution and XSS attacks * MFSA 2013-71/CVE-2013-1712 (bmo#859072) Further Privilege escalation through Mozilla Updater * MFSA 2013-72/CVE-2013-1713 (bmo#887098) Wrong principal used for validating URI for some Javascript components * MFSA 2013-73/CVE-2013-1714 (bmo#879787) Same-origin bypass with web workers and XMLHttpReq...

Read the Full Advisory

References

#833389

Cross- CVE-2013-1701 CVE-2013-1702 CVE-2013-1706

CVE-2013-1707 CVE-2013-1709 CVE-2013-1710

CVE-2013-1712 CVE-2013-1713 CVE-2013-1714

CVE-2013-1717

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2013-1701.html

https://www.suse.com/security/cve/CVE-2013-1702.html

https://www.suse.com/security/cve/CVE-2013-1706.html

https://www.suse.com/security/cve/CVE-2013-1707.html

https://www.suse.com/security/cve/CVE-2013-1709.html

https://www.suse.com/security/cve/CVE-2013-1710.html

https://www.suse.com/security/cve/CVE-2013-1712.html

https://www.suse.com/security/cve/CVE-2013-1713.html

https://www.suse.com/security/cve/CVE-2013-1714.html

https://www.suse.com/security/cve/CVE-2013-1717.html

https://bugzilla.novell.com/833389

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:1382-1
Rating: important

Related News