SUSE-SU-2020:14290-1: important: Security update for MozillaFirefox
sle-updates at lists.suse.com
sle-updates at lists.suse.com
Mon Feb 24 10:11:31 MST 2020
SUSE Security Update: Security update for MozillaFirefox
______________________________________________________________________________
Announcement ID: SUSE-SU-2020:14290-1
Rating: important
References: #1161799 #1163368
Cross-References: CVE-2020-6796 CVE-2020-6797 CVE-2020-6798
CVE-2020-6799 CVE-2020-6800
Affected Products:
SUSE Linux Enterprise Server 11-SP4-LTSS
______________________________________________________________________________
An update that fixes 5 vulnerabilities is now available.
Description:
This update for MozillaFirefox fixes the following issues:
Firefox was updated to version 68.5.0 ESR (bsc#1163368).
Security issues fixed:
- CVE-2020-6796: Fixed a missing bounds check on shared memory in the
parent process (bsc#1163368).
- CVE-2020-6798: Fixed a JavaScript code injection issue caused by the
incorrect parsing of template tags (bsc#1163368).
- CVE-2020-6799: Fixed a local arbitrary code execution issue when
handling PDF links from other applications (bsc#1163368).
- CVE-2020-6800: Fixed several memory safety bugs (bsc#1163368).
Non-security issues fixed:
- Fixed various issues opening files with spaces in their path
(bmo#1601905, bmo#1602726).
Patch Instructions:
To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- SUSE Linux Enterprise Server 11-SP4-LTSS:
zypper in -t patch slessp4-MozillaFirefox-14290=1
Package List:
- SUSE Linux Enterprise Server 11-SP4-LTSS (x86_64):
MozillaFirefox-68.5.0-78.61.2
MozillaFirefox-translations-common-68.5.0-78.61.2
MozillaFirefox-translations-other-68.5.0-78.61.2
References:
https://www.suse.com/security/cve/CVE-2020-6796.html
https://www.suse.com/security/cve/CVE-2020-6797.html
https://www.suse.com/security/cve/CVE-2020-6798.html
https://www.suse.com/security/cve/CVE-2020-6799.html
https://www.suse.com/security/cve/CVE-2020-6800.html
https://bugzilla.suse.com/1161799
https://bugzilla.suse.com/1163368
More information about the sle-updates
mailing list