Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.851359
Category:SuSE Local Security Checks
Title:SUSE: Security Advisory for MozillaFirefox (SUSE-SU-2016:1691-1)
Summary:The remote host is missing an update for the 'MozillaFirefox'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'MozillaFirefox'
package(s) announced via the referenced advisory.

Vulnerability Insight:
MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss and mozilla-nspr
were updated to fix nine security issues.

MozillaFirefox was updated to version 45.2.0 ESR. mozilla-nss was updated
to version 3.21.1.

These security issues were fixed:

- CVE-2016-2834: Memory safety bugs in NSS (MFSA 2016-61) (bsc#983639).

- CVE-2016-2824: Out-of-bounds write with WebGL shader (MFSA 2016-53)
(bsc#983651).

- CVE-2016-2822: Addressbar spoofing though the SELECT element (MFSA
2016-52) (bsc#983652).

- CVE-2016-2821: Use-after-free deleting tables from a contenteditable
document (MFSA 2016-51) (bsc#983653).

- CVE-2016-2819: Buffer overflow parsing HTML5 fragments (MFSA 2016-50)
(bsc#983655).

- CVE-2016-2828: Use-after-free when textures are used in WebGL operations
after recycle pool destruction (MFSA 2016-56) (bsc#983646).

- CVE-2016-2831: Entering fullscreen and persistent pointerlock without
user permission (MFSA 2016-58) (bsc#983643).

- CVE-2016-2815, CVE-2016-2818: Miscellaneous memory safety hazards (MFSA
2016-49) (bsc#983638)

These non-security issues were fixed:

- bsc#982366: Unknown SSL protocol error in connections

- Fix crashes on aarch64

* Determine page size at runtime (bsc#984006)

* Allow aarch64 to work in safe mode (bsc#985659)

- Fix crashes on mainframes

All extensions must now be signed by addons.mozilla.org. Please read
README.SUSE for more details.

Affected Software/OS:
MozillaFirefox, on SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Desktop 12

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-2815
BugTraq ID: 91075
http://www.securityfocus.com/bid/91075
http://www.securitytracker.com/id/1036057
SuSE Security Announcement: SUSE-SU-2016:1691 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00055.html
SuSE Security Announcement: openSUSE-SU-2016:1552 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html
SuSE Security Announcement: openSUSE-SU-2016:1557 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html
SuSE Security Announcement: openSUSE-SU-2016:1767 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00006.html
SuSE Security Announcement: openSUSE-SU-2016:1769 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00007.html
SuSE Security Announcement: openSUSE-SU-2016:1778 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00008.html
http://www.ubuntu.com/usn/USN-2993-1
Common Vulnerability Exposure (CVE) ID: CVE-2016-2818
Debian Security Information: DSA-3600 (Google Search)
http://www.debian.org/security/2016/dsa-3600
Debian Security Information: DSA-3647 (Google Search)
http://www.debian.org/security/2016/dsa-3647
RedHat Security Advisories: RHSA-2016:1217
https://access.redhat.com/errata/RHSA-2016:1217
RedHat Security Advisories: RHSA-2016:1392
https://access.redhat.com/errata/RHSA-2016:1392
http://www.ubuntu.com/usn/USN-3023-1
Common Vulnerability Exposure (CVE) ID: CVE-2016-2819
https://www.exploit-db.com/exploits/44293/
Common Vulnerability Exposure (CVE) ID: CVE-2016-2821
Common Vulnerability Exposure (CVE) ID: CVE-2016-2822
Common Vulnerability Exposure (CVE) ID: CVE-2016-2824
Common Vulnerability Exposure (CVE) ID: CVE-2016-2828
Common Vulnerability Exposure (CVE) ID: CVE-2016-2831
Common Vulnerability Exposure (CVE) ID: CVE-2016-2834
BugTraq ID: 91072
http://www.securityfocus.com/bid/91072
Debian Security Information: DSA-3688 (Google Search)
http://www.debian.org/security/2016/dsa-3688
RedHat Security Advisories: RHSA-2016:2779
http://rhn.redhat.com/errata/RHSA-2016-2779.html
http://www.ubuntu.com/usn/USN-3029-1
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.