Security update for Mozilla Firefox

SUSE Security Update: Security update for Mozilla Firefox
Announcement ID: SUSE-SU-2013:1382-1
Rating: important
References: #833389
Affected Products:
  • SUSE Linux Enterprise Server 10 SP4 LTSS

  • An update that fixes 10 vulnerabilities is now available. It includes one version update.

    Description:


    Update to Firefox 17.0.8esr (bnc#833389) to address:

    * MFSA 2013-63/CVE-2013-1701/CVE-2013-1702 (bmo#855331,
    bmo#844088, bmo#858060, bmo#870200, bmo#874974, bmo#861530,
    bmo#854157, bmo#893684, bmo#878703, bmo#862185, bmo#879139,
    bmo#888107, bmo#880734) Miscellaneous memory safety hazards
    (rv:23.0 / rv:17.0.8)
    * MFSA 2013-66/CVE-2013-1706/CVE-2013-1707 (bmo#888314,
    bmo#888361) Buffer overflow in Mozilla Maintenance Service
    and Mozilla Updater
    * MFSA 2013-68/CVE-2013-1709 (bmo#848253) Document URI
    misrepresentation and masquerading
    * MFSA 2013-69/CVE-2013-1710 (bmo#871368) CRMF requests
    allow for code execution and XSS attacks
    * MFSA 2013-71/CVE-2013-1712 (bmo#859072) Further
    Privilege escalation through Mozilla Updater
    * MFSA 2013-72/CVE-2013-1713 (bmo#887098) Wrong
    principal used for validating URI for some Javascript
    components
    * MFSA 2013-73/CVE-2013-1714 (bmo#879787) Same-origin
    bypass with web workers and XMLHttpRequest
    * MFSA 2013-75/CVE-2013-1717 (bmo#406541) Local Java
    applets may read contents of local file system

    Security Issue references:

    * CVE-2013-1701
    >
    * CVE-2013-1702
    >
    * CVE-2013-1706
    >
    * CVE-2013-1707
    >
    * CVE-2013-1709
    >
    * CVE-2013-1710
    >
    * CVE-2013-1712
    >
    * CVE-2013-1713
    >
    * CVE-2013-1714
    >
    * CVE-2013-1717
    >

    Package List:

    • SUSE Linux Enterprise Server 10 SP4 LTSS (i586 s390x) [New Version: 17.0.8esr]:
    • MozillaFirefox-17.0.8esr-0.5.1
    • MozillaFirefox-translations-17.0.8esr-0.5.1

    References:

    • http://support.novell.com/security/cve/CVE-2013-1701.html
    • http://support.novell.com/security/cve/CVE-2013-1702.html
    • http://support.novell.com/security/cve/CVE-2013-1706.html
    • http://support.novell.com/security/cve/CVE-2013-1707.html
    • http://support.novell.com/security/cve/CVE-2013-1709.html
    • http://support.novell.com/security/cve/CVE-2013-1710.html
    • http://support.novell.com/security/cve/CVE-2013-1712.html
    • http://support.novell.com/security/cve/CVE-2013-1713.html
    • http://support.novell.com/security/cve/CVE-2013-1714.html
    • http://support.novell.com/security/cve/CVE-2013-1717.html
    • https://bugzilla.novell.com/833389
    • http://download.suse.com/patch/finder/?keywords=4ec72487a7980101b353c16bf1aff155