[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2024:1319-1 -- SLES MozillaFirefox

ID: oval:org.secpod.oval:def:89051761Date: (C)2024-04-26   (M)2024-04-29
Class: PATCHFamily: unix




This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.10.0 ESR : * CVE-2024-3852: GetBoundName in the JIT returned the wrong object * CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement * CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection * CVE-2024-2609: Permission prompt input delay could expire when not in focus * CVE-2024-3859: Integer-overflow led to out-of-bounds-read in the OpenType sanitizer * CVE-2024-3861: Potential use-after-free due to AlignedBuffer self-move * CVE-2024-3863: Download Protections were bypassed by .xrm-ms files on Windows * CVE-2024-3302: Denial of Service using HTTP/2 CONTINUATION frames * CVE-2024-3864: Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10

Platform:
SUSE Linux Enterprise Server 12 SP5
Product:
MozillaFirefox
Reference:
SUSE-SU-2024:1319-1
CVE-2024-2609
CVE-2024-3302
CVE-2024-3852
CVE-2024-3854
CVE-2024-3857
CVE-2024-3859
CVE-2024-3861
CVE-2024-3863
CVE-2024-3864
CVE    9
CVE-2024-2609
CVE-2024-3861
CVE-2024-3864
CVE-2024-3852
...
CPE    2
cpe:/o:suse:suse_linux_enterprise_server:12:sp5
cpe:/a:mozilla:MozillaFirefox

© SecPod Technologies