Security update for MozillaFirefox

SUSE Security Update: Security update for MozillaFirefox
Announcement ID: SUSE-SU-2021:0431-1
Rating: low
References: #1181848
Affected Products:
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Server 12-SP5

An update that contains security fixes can now be installed.

Description:

This update for MozillaFirefox fixes the following issues:
Firefox Extended Support Release 78.7.1 ESR (bsc#1181848)

  • Fixed: Prevent access to NTFS special paths that could lead to filesystem corruption.
  • Buffer overflow in depth pitch calculations for compressed textures

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Software Development Kit 12-SP5:
    zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-431=1
  • SUSE Linux Enterprise Server 12-SP5:
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-431=1

Package List:

  • SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64):
    • MozillaFirefox-debuginfo-78.7.1-112.48.1
    • MozillaFirefox-debugsource-78.7.1-112.48.1
    • MozillaFirefox-devel-78.7.1-112.48.1
  • SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64):
    • MozillaFirefox-78.7.1-112.48.1
    • MozillaFirefox-debuginfo-78.7.1-112.48.1
    • MozillaFirefox-debugsource-78.7.1-112.48.1
    • MozillaFirefox-devel-78.7.1-112.48.1
    • MozillaFirefox-translations-common-78.7.1-112.48.1

References: