Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.852727
Kategorie:SuSE Local Security Checks
Titel:openSUSE: Security Advisory for MozillaFirefox (openSUSE-SU-2019:2260-1)
Zusammenfassung:The remote host is missing an update for the 'MozillaFirefox'; package(s) announced via the openSUSE-SU-2019:2260-1 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'MozillaFirefox'
package(s) announced via the openSUSE-SU-2019:2260-1 advisory.

Vulnerability Insight:
This update for MozillaFirefox to 68.1 fixes the following issues:

Security issues fixed:

- CVE-2019-9811: Fixed a sandbox escape via installation of malicious
language pack. (bsc#1140868)

- CVE-2019-9812: Fixed a sandbox escape through Firefox Sync. (bsc#1149294)

- CVE-2019-11710: Fixed several memory safety bugs. (bsc#1140868)

- CVE-2019-11714: Fixed a potentially exploitable crash in Necko.
(bsc#1140868)

- CVE-2019-11716: Fixed a sandbox bypass. (bsc#1140868)

- CVE-2019-11718: Fixed inadequate sanitation in the Activity Stream
component. (bsc#1140868)

- CVE-2019-11720: Fixed a character encoding XSS vulnerability.
(bsc#1140868)

- CVE-2019-11721: Fixed a homograph domain spoofing issue through unicode
latin 'kra' character. (bsc#1140868)

- CVE-2019-11723: Fixed a cookie leakage during add-on fetching across
private browsing boundaries. (bsc#1140868)

- CVE-2019-11724: Fixed an outdated permission, granting access to retired
site input.mozilla.org. (bsc#1140868)

- CVE-2019-11725: Fixed a Safebrowsing bypass involving WebSockets.
(bsc#1140868)

- CVE-2019-11727: Fixed a vulnerability where it possible to force NSS to
sign CertificateVerify with PKCS#1 v1.5 signatures when those are the
only ones advertised by server in CertificateRequest in TLS 1.3.
(bsc#1141322)

- CVE-2019-11728: Fixed an improper handling of the Alt-Svc header that
allowed remote port scans. (bsc#1140868)

- CVE-2019-11733: Fixed an insufficient protection of stored passwords in
'Saved Logins'. (bnc#1145665)

- CVE-2019-11735: Fixed several memory safety bugs. (bnc#1149293)

- CVE-2019-11736: Fixed a file manipulation and privilege escalation in
Mozilla Maintenance Service. (bnc#1149292)

- CVE-2019-11738: Fixed a content security policy bypass through
hash-based sources in directives. (bnc#1149302)

- CVE-2019-11740: Fixed several memory safety bugs. (bsc#1149299)

- CVE-2019-11742: Fixed a same-origin policy violation involving SVG
filters and canvas to steal cross-origin images. (bsc#1149303)

- CVE-2019-11743: Fixed a timing side-channel attack on cross-origin
information, utilizing unload event attributes. (bsc#1149298)

- CVE-2019-11744: Fixed an XSS caused by breaking out of title and
textarea elements using innerHTML. (bsc#1149304)

- CVE-2019-11746: Fixed a use-after-free while manipulating video.
(bsc#1149297)

- CVE-2019-11752: Fixed a use-after-free while extracting a key value in
IndexedDB. (bsc#1149296)

- CVE-2019-11753: Fixed a privilege escalation with Mozilla Maintenance
Service in custom Firefox installation loca ...

Description truncated. Please see the references for more information.

Affected Software/OS:
'MozillaFirefox' package(s) on openSUSE Leap 15.0.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-9811
https://security.gentoo.org/glsa/201908-12
https://security.gentoo.org/glsa/201908-20
https://bugzilla.mozilla.org/show_bug.cgi?id=1538007
https://bugzilla.mozilla.org/show_bug.cgi?id=1539598
https://bugzilla.mozilla.org/show_bug.cgi?id=1563327
https://www.mozilla.org/security/advisories/mfsa2019-21/
https://www.mozilla.org/security/advisories/mfsa2019-22/
https://www.mozilla.org/security/advisories/mfsa2019-23/
https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html
SuSE Security Announcement: openSUSE-SU-2019:1811 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html
SuSE Security Announcement: openSUSE-SU-2019:1813 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
SuSE Security Announcement: openSUSE-SU-2019:1990 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html
SuSE Security Announcement: openSUSE-SU-2019:2251 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html
SuSE Security Announcement: openSUSE-SU-2019:2260 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-9812
https://bugzilla.mozilla.org/show_bug.cgi?id=1538015
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.