Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.850681
Categoría:SuSE Local Security Checks
Título:openSUSE: Security Advisory for MozillaFirefox (openSUSE-SU-2015:0077-2)
Resumen:The remote host is missing an update for the 'MozillaFirefox'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'MozillaFirefox'
package(s) announced via the referenced advisory.

Vulnerability Insight:
MozillaFirefox was updated to version 35.0 (bnc#910669)

Notable features:

* Firefox Hello with new rooms-based conversations model

* Implemented HTTP Public Key Pinning Extension (for enhanced
authentication of encrypted connections)

Security fixes:

* MFSA 2015-01/CVE-2014-8634/CVE-2014-8635 Miscellaneous memory safety
hazards

* MFSA 2015-02/CVE-2014-8637 (bmo#1094536) Uninitialized memory use during
bitmap rendering

* MFSA 2015-03/CVE-2014-8638 (bmo#1080987) sendBeacon requests lack an
Origin header

* MFSA 2015-04/CVE-2014-8639 (bmo#1095859) Cookie injection through Proxy
Authenticate responses

* MFSA 2015-05/CVE-2014-8640 (bmo#1100409) Read of uninitialized memory in
Web Audio

* MFSA 2015-06/CVE-2014-8641 (bmo#1108455) Read-after-free in WebRTC

* MFSA 2015-07/CVE-2014-8643 (bmo#1114170) (Windows-only) Gecko Media
Plugin sandbox escape

* MFSA 2015-08/CVE-2014-8642 (bmo#1079658) Delegated OCSP responder
certificates failure with id-pkix-ocsp-nocheck extension

* MFSA 2015-09/CVE-2014-8636 (bmo#987794) XrayWrapper bypass through DOM
objects

- obsolete tracker-miner-firefox 0.15 because it leads to startup
crashes (bnc#908892)

Affected Software/OS:
MozillaFirefox on openSUSE 13.2

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-8634
BugTraq ID: 72049
http://www.securityfocus.com/bid/72049
Debian Security Information: DSA-3127 (Google Search)
http://www.debian.org/security/2015/dsa-3127
Debian Security Information: DSA-3132 (Google Search)
http://www.debian.org/security/2015/dsa-3132
https://security.gentoo.org/glsa/201504-01
RedHat Security Advisories: RHSA-2015:0046
http://rhn.redhat.com/errata/RHSA-2015-0046.html
RedHat Security Advisories: RHSA-2015:0047
http://rhn.redhat.com/errata/RHSA-2015-0047.html
http://www.securitytracker.com/id/1031533
http://www.securitytracker.com/id/1031534
http://secunia.com/advisories/62237
http://secunia.com/advisories/62242
http://secunia.com/advisories/62250
http://secunia.com/advisories/62253
http://secunia.com/advisories/62259
http://secunia.com/advisories/62273
http://secunia.com/advisories/62274
http://secunia.com/advisories/62283
http://secunia.com/advisories/62293
http://secunia.com/advisories/62304
http://secunia.com/advisories/62313
http://secunia.com/advisories/62315
http://secunia.com/advisories/62316
http://secunia.com/advisories/62418
http://secunia.com/advisories/62446
http://secunia.com/advisories/62657
http://secunia.com/advisories/62790
SuSE Security Announcement: SUSE-SU-2015:0171 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html
SuSE Security Announcement: SUSE-SU-2015:0173 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html
SuSE Security Announcement: SUSE-SU-2015:0180 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html
SuSE Security Announcement: openSUSE-SU-2015:0077 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
SuSE Security Announcement: openSUSE-SU-2015:0133 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-01/msg00071.html
SuSE Security Announcement: openSUSE-SU-2015:0192 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
SuSE Security Announcement: openSUSE-SU-2015:1266 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://www.ubuntu.com/usn/USN-2460-1
XForce ISS Database: firefox-cve20148634-code-exec(99955)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99955
Common Vulnerability Exposure (CVE) ID: CVE-2014-8635
BugTraq ID: 72050
http://www.securityfocus.com/bid/72050
Common Vulnerability Exposure (CVE) ID: CVE-2014-8636
BugTraq ID: 72041
http://www.securityfocus.com/bid/72041
http://packetstormsecurity.com/files/130972/Firefox-Proxy-Prototype-Privileged-Javascript-Injection.html
https://community.rapid7.com/community/metasploit/blog/2015/03/23/r7-2015-04-disclosure-mozilla-firefox-proxy-prototype-rce-cve-2014-8636
XForce ISS Database: firefox-cve20148636-sec-bypass(99964)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99964
Common Vulnerability Exposure (CVE) ID: CVE-2014-8637
BugTraq ID: 72048
http://www.securityfocus.com/bid/72048
XForce ISS Database: firefox-cve20148637-info-disc(99957)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99957
Common Vulnerability Exposure (CVE) ID: CVE-2014-8638
BugTraq ID: 72047
http://www.securityfocus.com/bid/72047
XForce ISS Database: firefox-cve20148638-csrf(99958)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99958
Common Vulnerability Exposure (CVE) ID: CVE-2014-8639
BugTraq ID: 72046
http://www.securityfocus.com/bid/72046
XForce ISS Database: firefox-cve20148639-session-hijacking(99959)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99959
Common Vulnerability Exposure (CVE) ID: CVE-2014-8640
BugTraq ID: 72045
http://www.securityfocus.com/bid/72045
XForce ISS Database: firefox-cve20148640-info-disc(99960)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99960
Common Vulnerability Exposure (CVE) ID: CVE-2014-8641
BugTraq ID: 72044
http://www.securityfocus.com/bid/72044
XForce ISS Database: firefox-cve20148641-dos(99961)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99961
Common Vulnerability Exposure (CVE) ID: CVE-2014-8642
BugTraq ID: 72042
http://www.securityfocus.com/bid/72042
XForce ISS Database: firefox-cve20148642-sec-bypass(99963)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99963
Common Vulnerability Exposure (CVE) ID: CVE-2014-8643
BugTraq ID: 72043
http://www.securityfocus.com/bid/72043
XForce ISS Database: firefox-cve20148643-sec-bypass(99962)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99962
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.