SuSE: 2014:0248-2: important: Mozilla Firefox
Summary
Mozilla Firefox was updated to the 24.3.0ESR security release. The following security issues have been fixed: * MFSA 2014-01: Memory safety bugs fixed in Firefox ESR 24.3 and Firefox 27.0 (CVE-2014-1477)(bnc#862345) * MFSA 2014-02: Using XBL scopes its possible to steal(clone) native anonymous content (CVE-2014-1479)(bnc#862348) * MFSA 2014-03: Download "open file" dialog delay is too quick, doesn't prevent clickjacking (CVE-2014-1480) * MFSA 2014-04: Image decoding causing FireFox to crash with Goo Create (CVE-2014-1482)(bnc#862356) * MFSA 2014-05: caretPositionFromPoint and elementFromPoint leak information about iframe contents via timing information (CVE-2014-1483)(bnc#862360) * MFSA 2014-06: Fennec leaks profile path to logcat (CVE-2014-1484) * MFSA 2014-07: CSP should block XSLT as script, not as style (CVE-2014-1485) * MFSA 2014-08: imgRequestProxy Use-After-Free Remote ...
Read the Full AdvisoryReferences
#859055 #861847
Cross- CVE-2014-1477 CVE-2014-1479 CVE-2014-1480
CVE-2014-1481 CVE-2014-1482 CVE-2014-1483
CVE-2014-1484 CVE-2014-1485 CVE-2014-1486
CVE-2014-1487 CVE-2014-1488 CVE-2014-1489
CVE-2014-1490 CVE-2014-1491
Affected Products:
SUSE Linux Enterprise Server 11 SP2 LTSS
SUSE Linux Enterprise Server 11 SP1 LTSS
https://www.suse.com/security/cve/CVE-2014-1477.html
https://www.suse.com/security/cve/CVE-2014-1479.html
https://www.suse.com/security/cve/CVE-2014-1480.html
https://www.suse.com/security/cve/CVE-2014-1481.html
https://www.suse.com/security/cve/CVE-2014-1482.html
https://www.suse.com/security/cve/CVE-2014-1483.html
https://www.suse.com/security/cve/CVE-2014-1484.html
https://www.suse.com/security/cve/CVE-2014-1485.html
https://www.suse.com/security/cve/CVE-2014-1486.html
https://www.suse.com/security/cve/CVE-2014-1487.html
h...
Read the Full Advisory