Upstream information

CVE-2012-1938 at MITRE

Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 13.0, Thunderbird before 13.0, and SeaMonkey before 2.10 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) methodjit/ImmutableSync.cpp, (2) the JSObject::makeDenseArraySlow function in js/src/jsarray.cpp, and unknown other components.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 9.3
Vector AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entry: 765204 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Server 12 SP1
  • MozillaFirefox >= 38.4.0esr-51.1
  • MozillaFirefox-translations >= 38.4.0esr-51.1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • MozillaFirefox >= 45.4.0esr-81.1
  • MozillaFirefox-translations >= 45.4.0esr-81.1
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP3
  • MozillaFirefox >= 52.2.0esr-108.3
  • MozillaFirefox-translations >= 52.2.0esr-108.3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP4
  • MozillaFirefox >= 52.9.0esr-109.38.2
  • MozillaFirefox-translations >= 52.9.0esr-109.38.2
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server 12
  • MozillaFirefox >= 31.1.0esr-1.20
  • MozillaFirefox-translations >= 31.1.0esr-1.20
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise Server 12 SP5
  • MozillaFirefox >= 68.1.0-109.92.1
  • MozillaFirefox-translations-common >= 68.1.0-109.92.1
SUSE Linux Enterprise Module for Desktop Applications 15
  • MozillaFirefox >= 52.7.3-1.35
  • MozillaFirefox-devel >= 52.7.3-1.35
  • MozillaFirefox-translations-common >= 52.7.3-1.35
  • MozillaFirefox-translations-other >= 52.7.3-1.35
SUSE Linux Enterprise Server 11 SP1
SUSE Linux Enterprise Server 11 SP2
  • MozillaFirefox >= 10.0.5-0.3.6
  • MozillaFirefox-translations >= 10.0.5-0.3.6
  • libfreebl3 >= 3.13.5-0.4.2
  • libfreebl3-32bit >= 3.13.5-0.4.2
  • libfreebl3-x86 >= 3.13.5-0.4.2
  • mozilla-nspr >= 4.9.1-0.5.1
  • mozilla-nspr-32bit >= 4.9.1-0.5.1
  • mozilla-nspr-x86 >= 4.9.1-0.5.1
  • mozilla-nss >= 3.13.5-0.4.2
  • mozilla-nss-32bit >= 3.13.5-0.4.2
  • mozilla-nss-tools >= 3.13.5-0.4.2
  • mozilla-nss-x86 >= 3.13.5-0.4.2
  • mozilla-xulrunner191 >= 1.9.1.11-0.1.1
  • mozilla-xulrunner191-32bit >= 1.9.1.11-0.1.1
  • mozilla-xulrunner191-gnomevfs >= 1.9.1.11-0.1.1
  • mozilla-xulrunner191-translations >= 1.9.1.11-0.1.1
  • mozilla-xulrunner191-x86 >= 1.9.1.11-0.1.1
  • mozilla-xulrunner192 >= 1.9.2.24-0.3.1
  • mozilla-xulrunner192-32bit >= 1.9.2.24-0.3.2
  • mozilla-xulrunner192-gnome >= 1.9.2.24-0.3.1
  • mozilla-xulrunner192-translations >= 1.9.2.24-0.3.1
  • mozilla-xulrunner192-x86 >= 1.9.2.24-0.3.1
Patchnames:
slessp1-MozillaFirefox
SUSE Linux Enterprise Software Development Kit 12 SP1
  • MozillaFirefox-devel >= 38.4.0esr-51.1
SUSE Linux Enterprise Software Development Kit 12 SP2
  • MozillaFirefox-devel >= 45.4.0esr-81.1
SUSE Linux Enterprise Software Development Kit 12 SP3
  • MozillaFirefox-devel >= 52.2.0esr-108.3
SUSE Linux Enterprise Software Development Kit 12 SP4
  • MozillaFirefox-devel >= 52.9.0esr-109.38.2
SUSE Linux Enterprise Software Development Kit 12 SP5
  • MozillaFirefox-devel >= 68.1.0-109.92.1
SUSE Linux Enterprise Software Development Kit 12
  • MozillaFirefox-devel >= 31.1.0esr-1.20
SUSE Linux Enterprise Workstation Extension 15 SP1
  • MozillaThunderbird >= 60.6.1-3.28.1
  • MozillaThunderbird-translations-common >= 60.6.1-3.28.1
  • MozillaThunderbird-translations-other >= 60.6.1-3.28.1
SUSE Linux Enterprise Workstation Extension 15
  • MozillaThunderbird >= 52.8-1.2
  • MozillaThunderbird-devel >= 52.8-1.2
  • MozillaThunderbird-translations-common >= 52.8-1.2
  • MozillaThunderbird-translations-other >= 52.8-1.2
openSUSE Leap 15.0
  • MozillaFirefox >= 60.0-lp150.2.2
  • MozillaFirefox-translations-common >= 60.0-lp150.2.2
  • MozillaFirefox-translations-other >= 60.0-lp150.2.2
  • MozillaThunderbird >= 52.7-lp150.2.16
  • MozillaThunderbird-translations-common >= 52.7-lp150.2.16
  • MozillaThunderbird-translations-other >= 52.7-lp150.2.16
Patchnames:
openSUSE Leap 15.0 GA MozillaFirefox
openSUSE Leap 15.0 GA MozillaThunderbird
openSUSE Tumbleweed
  • MozillaFirefox >= 50.1.0-1.1
  • MozillaFirefox-branding-upstream >= 50.1.0-1.1
  • MozillaFirefox-buildsymbols >= 50.1.0-1.1
  • MozillaFirefox-devel >= 50.1.0-1.1
  • MozillaFirefox-translations-common >= 50.1.0-1.1
  • MozillaFirefox-translations-other >= 50.1.0-1.1
  • MozillaThunderbird >= 45.5.1-1.1
  • MozillaThunderbird-buildsymbols >= 45.5.1-1.1
  • MozillaThunderbird-devel >= 45.5.1-1.1
  • MozillaThunderbird-translations-common >= 45.5.1-1.1
  • MozillaThunderbird-translations-other >= 45.5.1-1.1
  • seamonkey >= 2.40-6.1
  • seamonkey-dom-inspector >= 2.40-6.1
  • seamonkey-irc >= 2.40-6.1
  • seamonkey-translations-common >= 2.40-6.1
  • seamonkey-translations-other >= 2.40-6.1
Patchnames:
openSUSE Tumbleweed GA MozillaFirefox
openSUSE Tumbleweed GA MozillaThunderbird
openSUSE Tumbleweed GA seamonkey