SUSE-SU-2016:3014-1 -- SLES MozillaFirefox, libfreebl3, libsoftokn3, mozilla-nssID: oval:org.secpod.oval:def:89045255 | Date: (C)2021-08-03 (M)2023-12-07 |
Class: PATCH | Family: unix |
This update for MozillaFirefox, mozilla-nss fixes security issues and bugs. The following vulnerabilities were fixed in Firefox ESR 45.5 : - CVE-2016-5297: Incorrect argument length checking in Javascript - CVE-2016-9066: Integer overflow leading to a buffer overflow in nsScriptLoadHandler - CVE-2016-5296: Heap-buffer-overflow WRITE in rasterize_edges_1 - CVE-2016-9064: Addons update must verify IDs match between current and new versions - CVE-2016-5290: Memory safety bugs fixed in Firefox 50 and Firefox ESR 45.5 - CVE-2016-5291: Same-origin policy violation using local HTML file and saved shortcut file The following vulnerabilities were fixed in mozilla-nss 3.21.3: - CVE-2016-9074: Insufficient timing side-channel resistance in divSpoiler - CVE-2016-5285: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash The following bugs were fixed: - Firefox would fail to go into fullscreen mode with some window managers The Mozilla Firefox changelog was amended to document patched dropped in a previous update.
Platform: |
SUSE Linux Enterprise Server 12 SP2 |
Product: |
MozillaFirefox |
libfreebl3 |
libsoftokn3 |
mozilla-nss |