Upstream information

CVE-2015-4482 at MITRE

Description

mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (aka MAR) file.

SUSE information

SUSE Bugzilla entry: 940806 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Module for Desktop Applications 15
  • MozillaFirefox >= 52.7.3-1.35
  • MozillaFirefox-devel >= 52.7.3-1.35
  • MozillaFirefox-translations-common >= 52.7.3-1.35
  • MozillaFirefox-translations-other >= 52.7.3-1.35
Patchnames:
SUSE Linux Enterprise Module for Desktop Applications 15 GA MozillaFirefox
SUSE Linux Enterprise Workstation Extension 15
  • MozillaThunderbird >= 52.8-1.2
  • MozillaThunderbird-devel >= 52.8-1.2
  • MozillaThunderbird-translations-common >= 52.8-1.2
  • MozillaThunderbird-translations-other >= 52.8-1.2
Patchnames:
SUSE Linux Enterprise Workstation Extension 15 GA MozillaThunderbird
openSUSE 13.1
  • MozillaFirefox >= 40.0-82.1
  • MozillaFirefox-branding-openSUSE >= 40-2.3.1
  • MozillaFirefox-branding-upstream >= 40.0-82.1
  • MozillaFirefox-buildsymbols >= 40.0-82.1
  • MozillaFirefox-debuginfo >= 40.0-82.1
  • MozillaFirefox-debugsource >= 40.0-82.1
  • MozillaFirefox-devel >= 40.0-82.1
  • MozillaFirefox-translations-common >= 40.0-82.1
  • MozillaFirefox-translations-other >= 40.0-82.1
  • MozillaThunderbird >= 38.2.0-70.60.2
  • MozillaThunderbird-buildsymbols >= 38.2.0-70.60.2
  • MozillaThunderbird-debuginfo >= 38.2.0-70.60.2
  • MozillaThunderbird-debugsource >= 38.2.0-70.60.2
  • MozillaThunderbird-devel >= 38.2.0-70.60.2
  • MozillaThunderbird-translations-common >= 38.2.0-70.60.2
  • MozillaThunderbird-translations-other >= 38.2.0-70.60.2
Patchnames:
openSUSE-2015-547
openSUSE-2015-558
openSUSE Leap 15.0
  • MozillaFirefox >= 60.0-lp150.2.2
  • MozillaFirefox-translations-common >= 60.0-lp150.2.2
  • MozillaFirefox-translations-other >= 60.0-lp150.2.2
  • MozillaThunderbird >= 52.7-lp150.2.16
  • MozillaThunderbird-translations-common >= 52.7-lp150.2.16
  • MozillaThunderbird-translations-other >= 52.7-lp150.2.16
Patchnames:
openSUSE Leap 15.0 GA MozillaFirefox
openSUSE Leap 15.0 GA MozillaThunderbird
openSUSE Leap 42.1
  • MozillaFirefox >= 41.0.2-1.2
  • MozillaFirefox-translations-common >= 41.0.2-1.2
  • MozillaThunderbird >= 38.3.0-2.2
  • MozillaThunderbird-translations-common >= 38.3.0-2.2
Patchnames:
openSUSE Leap 42.1 GA MozillaFirefox
openSUSE Leap 42.1 GA MozillaThunderbird
openSUSE Leap 42.2
  • MozillaFirefox >= 49.0.2-37.1
  • MozillaFirefox-translations-common >= 49.0.2-37.1
  • MozillaThunderbird >= 45.4.0-23.1
  • MozillaThunderbird-translations-common >= 45.4.0-23.1
Patchnames:
openSUSE Leap 42.2 GA MozillaFirefox
openSUSE Leap 42.2 GA MozillaThunderbird
openSUSE Leap 42.3
  • MozillaFirefox >= 52.2-58.2
  • MozillaFirefox-translations-common >= 52.2-58.2
  • MozillaThunderbird >= 52.2.1-42.1
  • MozillaThunderbird-translations-common >= 52.2.1-42.1
Patchnames:
openSUSE Leap 42.3 GA MozillaFirefox
openSUSE Leap 42.3 GA MozillaThunderbird
openSUSE Tumbleweed
  • MozillaFirefox >= 50.1.0-1.1
  • MozillaFirefox-branding-upstream >= 50.1.0-1.1
  • MozillaFirefox-buildsymbols >= 50.1.0-1.1
  • MozillaFirefox-devel >= 50.1.0-1.1
  • MozillaFirefox-translations-common >= 50.1.0-1.1
  • MozillaFirefox-translations-other >= 50.1.0-1.1
  • MozillaThunderbird >= 45.5.1-1.1
  • MozillaThunderbird-buildsymbols >= 45.5.1-1.1
  • MozillaThunderbird-devel >= 45.5.1-1.1
  • MozillaThunderbird-translations-common >= 45.5.1-1.1
  • MozillaThunderbird-translations-other >= 45.5.1-1.1
Patchnames:
openSUSE Tumbleweed GA MozillaFirefox
openSUSE Tumbleweed GA MozillaThunderbird