Security update for MozillaFirefox

SUSE Security Update: Security update for MozillaFirefox
Announcement ID: SUSE-SU-2020:14290-1
Rating: important
References: #1161799 #1163368
Cross-References:CVE-2020-6796 CVE-2020-6797 CVE-2020-6798 CVE-2020-6799 CVE-2020-6800
Affected Products:
  • SUSE Linux Enterprise Server 11-SP4-LTSS

An update that fixes 5 vulnerabilities is now available.


This update for MozillaFirefox fixes the following issues:
Firefox was updated to version 68.5.0 ESR (bsc#1163368).

Security issues fixed:

  • CVE-2020-6796: Fixed a missing bounds check on shared memory in the parent process (bsc#1163368).
  • CVE-2020-6798: Fixed a JavaScript code injection issue caused by the incorrect parsing of template tags (bsc#1163368).
  • CVE-2020-6799: Fixed a local arbitrary code execution issue when handling PDF links from other applications (bsc#1163368).
  • CVE-2020-6800: Fixed several memory safety bugs (bsc#1163368).

Non-security issues fixed:
  • Fixed various issues opening files with spaces in their path (bmo#1601905, bmo#1602726).

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Server 11-SP4-LTSS:
    zypper in -t patch slessp4-MozillaFirefox-14290=1

Package List:

  • SUSE Linux Enterprise Server 11-SP4-LTSS (x86_64):
    • MozillaFirefox-68.5.0-78.61.2
    • MozillaFirefox-translations-common-68.5.0-78.61.2
    • MozillaFirefox-translations-other-68.5.0-78.61.2