Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-12-SP4:GA
patchinfo.4348
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.4348
<patchinfo incident="4348"> <issue id="1028391" tracker="bnc">VUL-0: MozillaFirefox 52/45.8.0 security release</issue> <issue id="2017-5398" tracker="cve" /> <issue id="2017-5409" tracker="cve" /> <issue id="2017-5408" tracker="cve" /> <issue id="2017-5405" tracker="cve" /> <issue id="2017-5404" tracker="cve" /> <issue id="2017-5407" tracker="cve" /> <issue id="2017-5401" tracker="cve" /> <issue id="2017-5400" tracker="cve" /> <issue id="2017-5410" tracker="cve" /> <issue id="2017-5402" tracker="cve" /> <category>security</category> <rating>important</rating> <packager>pcerny</packager> <description> This update for MozillaFirefox to ESR 45.8 fixes the following issues: Security issues fixed (bsc#1028391): - CVE-2017-5402: Use-after-free working with events in FontFace objects - CVE-2017-5410: Memory corruption during JavaScript garbage collection incremental sweeping - CVE-2017-5400: asm.js JIT-spray bypass of ASLR and DEP - CVE-2017-5401: Memory Corruption when handling ErrorResult - CVE-2017-5407: Pixel and history stealing via floating-point timing side channel with SVG filters - CVE-2017-5404: Use-after-free working with ranges in selections - CVE-2017-5405: FTP response codes can cause use of uninitialized values for ports - CVE-2017-5408: Cross-origin reading of video captions in violation of CORS - CVE-2017-5409: File deletion via callback parameter in Mozilla Windows Updater and Maintenance Service - CVE-2017-5398: Memory safety bugs fixed in Firefox 52 and Firefox ESR 45.8 </description> <summary>Security update for MozillaFirefox</summary> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor