SUSE-SU-2013:1678-1: important: Security update for Mozilla Firefox

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Thu Nov 14 19:04:10 MST 2013


   SUSE Security Update: Security update for Mozilla Firefox
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:1678-1
Rating:             important
References:         #847708 
Cross-References:   CVE-2013-1739
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP3
                    SUSE Linux Enterprise Software Development Kit 11 SP2
                    SUSE Linux Enterprise Server 11 SP3 for VMware
                    SUSE Linux Enterprise Server 11 SP3
                    SUSE Linux Enterprise Server 11 SP2 for VMware
                    SUSE Linux Enterprise Server 11 SP2
                    SUSE Linux Enterprise Server 11 SP1 LTSS
                    SUSE Linux Enterprise Server 10 SP4 LTSS
                    SUSE Linux Enterprise Server 10 SP3 LTSS
                    SUSE Linux Enterprise Desktop 11 SP3
                    SUSE Linux Enterprise Desktop 11 SP2
______________________________________________________________________________

   An update that fixes one vulnerability is now available. It
   includes four new package versions.

Description:


   Mozilla Firefox has been updated to the 17.0.10ESR release,
   which fixes  various bugs and security issues:

   *

   MFSA 2013-93: Mozilla developers identified and fixed
   several memory safety bugs in the browser engine used in
   Firefox and other Mozilla-based products. Some of these
   bugs showed evidence of memory corruption under certain
   circumstances, and we presume that with enough effort at
   least some of these could be exploited to run arbitrary
   code.

   Jesse Ruderman and Christoph Diehl reported memory
   safety problems and crashes that affect Firefox ESR 17,
   Firefox ESR 24, and Firefox 24. (CVE-2013-5590)

   Carsten Book reported a crash fixed in the NSS
   library used by Mozilla-based products fixed in Firefox 25,
   Firefox ESR 24.1, and Firefox ESR 17.0.10.(CVE-2013-1739)

   *

   MFSA 2013-95 / CVE-2013-5604: Security researcher
   Abhishek Arya (Inferno) of the Google Chrome Security Team
   used the Address Sanitizer tool to discover an access
   violation due to uninitialized data during Extensible
   Stylesheet Language Transformation (XSLT) processing. This
   leads to a potentially exploitable crash.

   *

   MFSA 2013-96 / CVE-2013-5595: Compiler Engineer Dan
   Gohman of Google discovered a flaw in the JavaScript engine
   where memory was being incorrectly allocated for some
   functions and the calls for allocations were not always
   properly checked for overflow, leading to potential buffer
   overflows. When combined with other vulnerabilities, these
   flaws could be potentially exploitable.

   *

   MFSA 2013-98 / CVE-2013-5597: Security researcher
   Byoungyoung Lee of Georgia Tech Information Security Center
   (GTISC) used the Address Sanitizer tool to discover a
   use-after-free during state change events while updating
   the offline cache. This leads to a potentially exploitable
   crash.

   *

   MFSA 2013-100: Security researcher Nils used the
   Address Sanitizer tool while fuzzing to discover missing
   strong references in browsing engine leading to
   use-after-frees. This can lead to a potentially exploitable
   crash.

   o ASAN heap-use-after-free in
   nsIPresShell::GetPresContext() with canvas, onresize and
   mozTextStyle (CVE-2013-5599) o ASAN use-after-free in
   nsIOService::NewChannelFromURIWithProxyFlags with Blob URL
   (CVE-2013-5600) o ASAN use-after free in GC allocation in
   nsEventListenerManager::SetEventHandler (CVE-2013-5601)
   *

   MFSA 2013-101 / CVE-2013-5602: Security researcher
   Nils used the Address Sanitizer tool while fuzzing to
   discover a memory corruption issue with the JavaScript
   engine when using workers with direct proxies. This results
   in a potentially exploitable crash.

   Security Issue reference:

   * CVE-2013-1739
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1739
   >


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP3:

      zypper in -t patch sdksp3-firefox-201310-8491 sdksp3-mozilla-nss-201310-8485

   - SUSE Linux Enterprise Software Development Kit 11 SP2:

      zypper in -t patch sdksp2-mozilla-nss-201310-8484

   - SUSE Linux Enterprise Server 11 SP3 for VMware:

      zypper in -t patch slessp3-firefox-201310-8491 slessp3-mozilla-nss-201310-8485

   - SUSE Linux Enterprise Server 11 SP3:

      zypper in -t patch slessp3-firefox-201310-8491 slessp3-mozilla-nss-201310-8485

   - SUSE Linux Enterprise Server 11 SP2 for VMware:

      zypper in -t patch slessp2-firefox-201310-8545 slessp2-mozilla-nss-201310-8484

   - SUSE Linux Enterprise Server 11 SP2:

      zypper in -t patch slessp2-firefox-201310-8545 slessp2-mozilla-nss-201310-8484

   - SUSE Linux Enterprise Server 11 SP1 LTSS:

      zypper in -t patch slessp1-firefox-201310-8492 slessp1-mozilla-nss-201310-8486

   - SUSE Linux Enterprise Desktop 11 SP3:

      zypper in -t patch sledsp3-firefox-201310-8491 sledsp3-mozilla-nss-201310-8485

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-firefox-201310-8545 sledsp2-mozilla-nss-201310-8484

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      MozillaFirefox-devel-17.0.10esr-0.7.4
      mozilla-nspr-devel-4.10.1-0.3.1
      mozilla-nss-devel-3.15.2-0.8.1

   - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      mozilla-nspr-devel-4.10.1-0.3.1
      mozilla-nss-devel-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]:

      MozillaFirefox-17.0.10esr-0.7.4
      MozillaFirefox-translations-17.0.10esr-0.7.4
      libfreebl3-3.15.2-0.8.1
      libsoftokn3-3.15.2-0.8.1
      mozilla-nspr-4.10.1-0.3.1
      mozilla-nss-3.15.2-0.8.1
      mozilla-nss-tools-3.15.2-0.8.1

   - SUSE Linux Enterprise Server 11 SP3 for VMware (x86_64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-32bit-3.15.2-0.8.1
      libsoftokn3-32bit-3.15.2-0.8.1
      mozilla-nspr-32bit-4.10.1-0.3.1
      mozilla-nss-32bit-3.15.2-0.8.1

   - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]:

      MozillaFirefox-17.0.10esr-0.7.4
      MozillaFirefox-branding-SLED-7-0.12.41
      MozillaFirefox-translations-17.0.10esr-0.7.4
      libfreebl3-3.15.2-0.8.1
      libsoftokn3-3.15.2-0.8.1
      mozilla-nspr-4.10.1-0.3.1
      mozilla-nss-3.15.2-0.8.1
      mozilla-nss-tools-3.15.2-0.8.1

   - SUSE Linux Enterprise Server 11 SP3 (ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-32bit-3.15.2-0.8.1
      libsoftokn3-32bit-3.15.2-0.8.1
      mozilla-nspr-32bit-4.10.1-0.3.1
      mozilla-nss-32bit-3.15.2-0.8.1

   - SUSE Linux Enterprise Server 11 SP3 (ia64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-x86-3.15.2-0.8.1
      libsoftokn3-x86-3.15.2-0.8.1
      mozilla-nspr-x86-4.10.1-0.3.1
      mozilla-nss-x86-3.15.2-0.8.1

   - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]:

      MozillaFirefox-17.0.10esr-0.4.2.4
      MozillaFirefox-translations-17.0.10esr-0.4.2.4
      libfreebl3-3.15.2-0.3.1
      mozilla-nspr-4.10.1-0.3.1
      mozilla-nss-3.15.2-0.3.1
      mozilla-nss-tools-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 11 SP2 for VMware (x86_64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-32bit-3.15.2-0.3.1
      mozilla-nspr-32bit-4.10.1-0.3.1
      mozilla-nss-32bit-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]:

      MozillaFirefox-17.0.10esr-0.4.2.4
      MozillaFirefox-branding-SLED-7-0.6.9.62
      MozillaFirefox-translations-17.0.10esr-0.4.2.4
      libfreebl3-3.15.2-0.3.1
      mozilla-nspr-4.10.1-0.3.1
      mozilla-nss-3.15.2-0.3.1
      mozilla-nss-tools-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-32bit-3.15.2-0.3.1
      mozilla-nspr-32bit-4.10.1-0.3.1
      mozilla-nss-32bit-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 11 SP2 (ia64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-x86-3.15.2-0.3.1
      mozilla-nspr-x86-4.10.1-0.3.1
      mozilla-nss-x86-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 11 SP1 LTSS (i586 s390x x86_64) [New Version: 17.0.10esr,3.15.2,4.10.1 and 7]:

      MozillaFirefox-17.0.10esr-0.4.2.1
      MozillaFirefox-branding-SLED-7-0.6.9.60
      MozillaFirefox-translations-17.0.10esr-0.4.2.1
      libfreebl3-3.15.2-0.3.1
      mozilla-nspr-4.10.1-0.3.1
      mozilla-nss-3.15.2-0.3.1
      mozilla-nss-tools-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 11 SP1 LTSS (s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-32bit-3.15.2-0.3.1
      mozilla-nspr-32bit-4.10.1-0.3.1
      mozilla-nss-32bit-3.15.2-0.3.1

   - SUSE Linux Enterprise Server 10 SP4 LTSS (i586 s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      mozilla-nspr-4.10.1-0.5.1
      mozilla-nspr-devel-4.10.1-0.5.1
      mozilla-nss-3.15.2-0.5.1
      mozilla-nss-devel-3.15.2-0.5.1
      mozilla-nss-tools-3.15.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 LTSS (s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      mozilla-nspr-32bit-4.10.1-0.5.1
      mozilla-nss-32bit-3.15.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      mozilla-nspr-4.10.1-0.5.1
      mozilla-nspr-devel-4.10.1-0.5.1
      mozilla-nss-3.15.2-0.5.1
      mozilla-nss-devel-3.15.2-0.5.1
      mozilla-nss-tools-3.15.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP3 LTSS (s390x x86_64) [New Version: 3.15.2 and 4.10.1]:

      mozilla-nspr-32bit-4.10.1-0.5.1
      mozilla-nss-32bit-3.15.2-0.5.1

   - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]:

      MozillaFirefox-17.0.10esr-0.7.4
      MozillaFirefox-branding-SLED-7-0.12.41
      MozillaFirefox-translations-17.0.10esr-0.7.4
      libfreebl3-3.15.2-0.8.1
      libsoftokn3-3.15.2-0.8.1
      mozilla-nspr-4.10.1-0.3.1
      mozilla-nss-3.15.2-0.8.1
      mozilla-nss-tools-3.15.2-0.8.1

   - SUSE Linux Enterprise Desktop 11 SP3 (x86_64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-32bit-3.15.2-0.8.1
      libsoftokn3-32bit-3.15.2-0.8.1
      mozilla-nspr-32bit-4.10.1-0.3.1
      mozilla-nss-32bit-3.15.2-0.8.1

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 17.0.10esr,3.15.2 and 4.10.1]:

      MozillaFirefox-17.0.10esr-0.4.2.4
      MozillaFirefox-branding-SLED-7-0.6.9.62
      MozillaFirefox-translations-17.0.10esr-0.4.2.4
      libfreebl3-3.15.2-0.3.1
      mozilla-nspr-4.10.1-0.3.1
      mozilla-nss-3.15.2-0.3.1
      mozilla-nss-tools-3.15.2-0.3.1

   - SUSE Linux Enterprise Desktop 11 SP2 (x86_64) [New Version: 3.15.2 and 4.10.1]:

      libfreebl3-32bit-3.15.2-0.3.1
      mozilla-nspr-32bit-4.10.1-0.3.1
      mozilla-nss-32bit-3.15.2-0.3.1


References:

   http://support.novell.com/security/cve/CVE-2013-1739.html
   https://bugzilla.novell.com/847708
   http://download.novell.com/patch/finder/?keywords=07c7008fa5d3132fbafd48744ab7c997
   http://download.novell.com/patch/finder/?keywords=1edf663f8550de4b96445d1cbca59315
   http://download.novell.com/patch/finder/?keywords=30958073bccf2d3c9d16900439fc7ec3
   http://download.novell.com/patch/finder/?keywords=574e354cc19e6404e0964c3b1348f211
   http://download.novell.com/patch/finder/?keywords=92ad00fe40f67f855b720f6d4ae5751a
   http://download.novell.com/patch/finder/?keywords=96c6d994dc18c3fd7399e875d9d14ac1
   http://download.novell.com/patch/finder/?keywords=d36d3817c15a3112e57723f3b4a2059a
   http://download.novell.com/patch/finder/?keywords=f4dc527883357fa1c73dfcbfaa52ddfe



More information about the sle-security-updates mailing list