Beschreibung: | Summary: The remote host is missing an update for the 'MozillaFirefox' package(s) announced via the openSUSE-SU-2019:1534-1 advisory.
Vulnerability Insight: This update for MozillaFirefox fixes the following issues:
MozillaFirefox was updated to 60.7.0esr (boo#1135824 MFSA 2019-14):
* CVE-2018-18511: Cross-origin theft of images with ImageBitmapRenderingContext
* CVE-2019-11691: Use-after-free in XMLHttpRequest
* CVE-2019-11692: Use-after-free removing listeners in the event listener manager
* CVE-2019-11693: Buffer overflow in WebGL bufferdata on Linux
* CVE-2019-11694: (Windows only) Uninitialized memory memory leakage in Windows sandbox
* CVE-2019-11698: Theft of user history data through drag and drop of hyperlinks to and from bookmarks
* CVE-2019-5798: Out-of-bounds read in Skia
* CVE-2019-7317: Use-after-free in png_image_free of libpng library
* CVE-2019-9797: Cross-origin theft of images with createImageBitmap
* CVE-2019-9800: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7
* CVE-2019-9815: Disable hyperthreading on content JavaScript threads on macOS
* CVE-2019-9816: Type confusion with object groups and UnboxedObjects
* CVE-2019-9817: Stealing of cross-domain images using canvas
* CVE-2019-9818: (Windows only) Use-after-free in crash generation server
* CVE-2019-9819: Compartment mismatch with fetch API
* CVE-2019-9820: Use-after-free of ChromeEventHandler by DocShell
* CVE-2019-9821: Use-after-free in AssertWorkerThread
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or 'zypper patch'.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1534=1
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1534=1
Affected Software/OS: 'MozillaFirefox' package(s) on openSUSE Leap 42.3, openSUSE Leap 15.0.
Solution: Please install the updated package(s).
CVSS Score: 7.5
CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
|