Lucene search

K
suseSuseSUSE-SU-2017:2872-1
HistoryOct 27, 2017 - 6:54 p.m.

Security update for MozillaFirefox, mozilla-nss (important)

2017-10-2718:54:21
lists.opensuse.org
37

EPSS

0.028

Percentile

90.9%

This update for MozillaFirefox and mozilla-nss fixes the following issues:

Mozilla Firefox was updated to ESR 52.4 (bsc#1060445)

  • MFSA 2017-22/CVE-2017-7825: OS X fonts render some Tibetan and Arabic
    unicode characters as spaces
  • MFSA 2017-22/CVE-2017-7805: Use-after-free in TLS 1.2 generating
    handshake hashes
  • MFSA 2017-22/CVE-2017-7819: Use-after-free while resizing images in
    design mode
  • MFSA 2017-22/CVE-2017-7818: Use-after-free during ARIA array manipulation
  • MFSA 2017-22/CVE-2017-7793: Use-after-free with Fetch API
  • MFSA 2017-22/CVE-2017-7824: Buffer overflow when drawing and validating
    elements with ANGLE
  • MFSA 2017-22/CVE-2017-7810: Memory safety bugs fixed in Firefox 56 and
    Firefox ESR 52.4
  • MFSA 2017-22/CVE-2017-7823: CSP sandbox directive did not create a
    unique origin
  • MFSA 2017-22/CVE-2017-7814: Blob and data URLs bypass phishing and
    malware protection warnings

Mozilla Network Security Services (Mozilla NSS) received a security fix:

  • MFSA 2017-22/CVE-2017-7805: Use-after-free in TLS 1.2 generating
    handshake hashes (bsc#1061005, bsc#1060445)