SUSE-SU-2019:14246-1
Vulnerability Summary
Timeline
Description
Security update for Mozilla Firefox This update contains the Mozilla Firefox ESR 68.2 release. Mozilla Firefox was updated to ESR 68.2 release: * Enterprise: New administrative policies were added. More information and templates are available at the Policy Templates page. * Various security fixes: MFSA 2019-33 (bsc#1154738) * CVE-2019-15903: Heap overflow in expat library in XML_GetCurrentLineNumber * CVE-2019-11757: Use-after-free when creating index updates in IndexedDB * CVE-2019-11758: Potentially exploitable crash due to 360 Total Security * CVE-2019-11759: Stack buffer overflow in HKDF output * CVE-2019-11760: Stack buffer overflow in WebRTC networking * CVE-2019-11761: Unintended access to a privileged JSONView object * CVE-2019-11762: document.domain-based origin isolation has same-origin- property violation * CVE-2019-11763: Incorrect HTML parsing results in XSS bypass technique * CVE-2019-11764: Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2 Other Issues resolved: * [bsc#1104841] Newer versions of firefox have a dependency on GLIBCXX_3.4.20 * [bsc#1074235] MozillaFirefox: background tab crash reports sent inadvertently without user opt-in * [bsc#1043008] Firefox hangs randomly when browsing and scrolling * [bsc#1025108] Firefox stops loading page until mouse is moved * [bsc#905528] Firefox malfunctions due to broken omni.ja archives
Affected Systems
- suse•firefox-atk&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 2.26.1-2.8.4
- suse•firefox-cairo&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 1.15.10-2.13.4
- suse•firefox-gdk-pixbuf&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 2.36.11-2.8.4
- suse•firefox-glib2&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 2.54.3-2.14.7
- suse•firefox-gtk3&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 3.10.9-2.15.3
- suse•firefox-harfbuzz&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 1.7.5-2.7.4
- suse•firefox-libffi-gcc5&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 5.3.1+r233831-14.1
- suse•firefox-libffi&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 3.2.1.git259-2.3.3
- suse•firefox-pango&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 1.40.14-2.7.4
- suse•mozilla-nspr&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 4.21-29.6.1
- suse•mozilla-nss&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 3.45-38.9.3
- suse•MozillaFirefox-branding-SLED&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 68-21.9.8
- suse•MozillaFirefox&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
< 68.2.0-78.51.4
References (230)
- https://www.suse.com/support/update/announcement/2019/suse-su-201914246-1/
- https://bugzilla.suse.com/1000036
- https://bugzilla.suse.com/1001652
- https://bugzilla.suse.com/1025108
- https://bugzilla.suse.com/1029377
- https://bugzilla.suse.com/1029902
- https://bugzilla.suse.com/1040164
- https://bugzilla.suse.com/104105
- https://bugzilla.suse.com/1042670
- https://bugzilla.suse.com/1043008
- https://bugzilla.suse.com/1044946
- https://bugzilla.suse.com/1047925
- https://bugzilla.suse.com/1047936
- https://bugzilla.suse.com/1048299
- https://bugzilla.suse.com/1049186
- https://bugzilla.suse.com/1050653
- https://bugzilla.suse.com/1056058
- https://bugzilla.suse.com/1058013
- https://bugzilla.suse.com/1066242
- https://bugzilla.suse.com/1066953
- https://bugzilla.suse.com/1070738
- https://bugzilla.suse.com/1070853
- https://bugzilla.suse.com/1072320
- https://bugzilla.suse.com/1072322
- https://bugzilla.suse.com/1073796
- https://bugzilla.suse.com/1073798
- https://bugzilla.suse.com/1073799
- https://bugzilla.suse.com/1073803
- https://bugzilla.suse.com/1073808
- https://bugzilla.suse.com/1073818
- https://bugzilla.suse.com/1073823
- https://bugzilla.suse.com/1073829
- https://bugzilla.suse.com/1073830
- https://bugzilla.suse.com/1073832
- https://bugzilla.suse.com/1073846
- https://bugzilla.suse.com/1074235
- https://bugzilla.suse.com/1077230
- https://bugzilla.suse.com/1079761
- https://bugzilla.suse.com/1081750
- https://bugzilla.suse.com/1082318
- https://bugzilla.suse.com/1087453
- https://bugzilla.suse.com/1087459
- https://bugzilla.suse.com/1087463
- https://bugzilla.suse.com/1088573
- https://bugzilla.suse.com/1091764
- https://bugzilla.suse.com/1094814
- https://bugzilla.suse.com/1097158
- https://bugzilla.suse.com/1097375
- https://bugzilla.suse.com/1097401
- https://bugzilla.suse.com/1097404
- https://bugzilla.suse.com/1097748
- https://bugzilla.suse.com/1104841
- https://bugzilla.suse.com/1105019
- https://bugzilla.suse.com/1107030
- https://bugzilla.suse.com/1109465
- https://bugzilla.suse.com/1117473
- https://bugzilla.suse.com/1117626
- https://bugzilla.suse.com/1117627
- https://bugzilla.suse.com/1117629
- https://bugzilla.suse.com/1117630
- https://bugzilla.suse.com/1120644
- https://bugzilla.suse.com/1122191
- https://bugzilla.suse.com/1123482
- https://bugzilla.suse.com/1124525
- https://bugzilla.suse.com/1127532
- https://bugzilla.suse.com/1129346
- https://bugzilla.suse.com/1130694
- https://bugzilla.suse.com/1130840
- https://bugzilla.suse.com/1133452
- https://bugzilla.suse.com/1133810
- https://bugzilla.suse.com/1134209
- https://bugzilla.suse.com/1138459
- https://bugzilla.suse.com/1140290
- https://bugzilla.suse.com/1140868
- https://bugzilla.suse.com/1141853
- https://bugzilla.suse.com/1144919
- https://bugzilla.suse.com/1145665
- https://bugzilla.suse.com/1146090
- https://bugzilla.suse.com/1146091
- https://bugzilla.suse.com/1146093
- https://bugzilla.suse.com/1146094
- https://bugzilla.suse.com/1146095
- https://bugzilla.suse.com/1146097
- https://bugzilla.suse.com/1146099
- https://bugzilla.suse.com/1146100
- https://bugzilla.suse.com/1149323
- https://bugzilla.suse.com/1153423
- https://bugzilla.suse.com/1154738
- https://bugzilla.suse.com/1447070
- https://bugzilla.suse.com/1447409
- https://bugzilla.suse.com/744625
- https://bugzilla.suse.com/744629
- https://bugzilla.suse.com/845955
- https://bugzilla.suse.com/865853
- https://bugzilla.suse.com/905528
- https://bugzilla.suse.com/917607
- https://bugzilla.suse.com/935856
- https://bugzilla.suse.com/937414
- https://bugzilla.suse.com/947747
- https://bugzilla.suse.com/948045
- https://bugzilla.suse.com/948602
- https://bugzilla.suse.com/955142
- https://bugzilla.suse.com/957814
- https://bugzilla.suse.com/957815
- https://bugzilla.suse.com/961254
- https://bugzilla.suse.com/962297
- https://bugzilla.suse.com/966076
- https://bugzilla.suse.com/966077
- https://bugzilla.suse.com/985201
- https://bugzilla.suse.com/986541
- https://bugzilla.suse.com/991344
- https://bugzilla.suse.com/998743
- https://www.suse.com/security/cve/CVE-2013-2882
- https://www.suse.com/security/cve/CVE-2013-6639
- https://www.suse.com/security/cve/CVE-2013-6640
- https://www.suse.com/security/cve/CVE-2013-6668
- https://www.suse.com/security/cve/CVE-2014-0224
- https://www.suse.com/security/cve/CVE-2015-3193
- https://www.suse.com/security/cve/CVE-2015-3194
- https://www.suse.com/security/cve/CVE-2015-5380
- https://www.suse.com/security/cve/CVE-2015-7384
- https://www.suse.com/security/cve/CVE-2016-2086
- https://www.suse.com/security/cve/CVE-2016-2178
- https://www.suse.com/security/cve/CVE-2016-2183
- https://www.suse.com/security/cve/CVE-2016-2216
- https://www.suse.com/security/cve/CVE-2016-5172
- https://www.suse.com/security/cve/CVE-2016-5325
- https://www.suse.com/security/cve/CVE-2016-6304
- https://www.suse.com/security/cve/CVE-2016-6306
- https://www.suse.com/security/cve/CVE-2016-7052
- https://www.suse.com/security/cve/CVE-2016-7099
- https://www.suse.com/security/cve/CVE-2017-1000381
- https://www.suse.com/security/cve/CVE-2017-10686
- https://www.suse.com/security/cve/CVE-2017-11111
- https://www.suse.com/security/cve/CVE-2017-11499
- https://www.suse.com/security/cve/CVE-2017-14228
- https://www.suse.com/security/cve/CVE-2017-14849
- https://www.suse.com/security/cve/CVE-2017-14919
- https://www.suse.com/security/cve/CVE-2017-15896
- https://www.suse.com/security/cve/CVE-2017-15897
- https://www.suse.com/security/cve/CVE-2017-17810
- https://www.suse.com/security/cve/CVE-2017-17811
- https://www.suse.com/security/cve/CVE-2017-17812
- https://www.suse.com/security/cve/CVE-2017-17813
- https://www.suse.com/security/cve/CVE-2017-17814
- https://www.suse.com/security/cve/CVE-2017-17815
- https://www.suse.com/security/cve/CVE-2017-17816
- https://www.suse.com/security/cve/CVE-2017-17817
- https://www.suse.com/security/cve/CVE-2017-17818
- https://www.suse.com/security/cve/CVE-2017-17819
- https://www.suse.com/security/cve/CVE-2017-17820
- https://www.suse.com/security/cve/CVE-2017-18207
- https://www.suse.com/security/cve/CVE-2017-3735
- https://www.suse.com/security/cve/CVE-2017-3736
- https://www.suse.com/security/cve/CVE-2017-3738
- https://www.suse.com/security/cve/CVE-2018-0732
- https://www.suse.com/security/cve/CVE-2018-1000168
- https://www.suse.com/security/cve/CVE-2018-12115
- https://www.suse.com/security/cve/CVE-2018-12116
- https://www.suse.com/security/cve/CVE-2018-12121
- https://www.suse.com/security/cve/CVE-2018-12122
- https://www.suse.com/security/cve/CVE-2018-12123
- https://www.suse.com/security/cve/CVE-2018-20406
- https://www.suse.com/security/cve/CVE-2018-20852
- https://www.suse.com/security/cve/CVE-2018-7158
- https://www.suse.com/security/cve/CVE-2018-7159
- https://www.suse.com/security/cve/CVE-2018-7160
- https://www.suse.com/security/cve/CVE-2018-7161
- https://www.suse.com/security/cve/CVE-2018-7167
- https://www.suse.com/security/cve/CVE-2019-10160
- https://www.suse.com/security/cve/CVE-2019-11709
- https://www.suse.com/security/cve/CVE-2019-11710
- https://www.suse.com/security/cve/CVE-2019-11711
- https://www.suse.com/security/cve/CVE-2019-11712
- https://www.suse.com/security/cve/CVE-2019-11713
- https://www.suse.com/security/cve/CVE-2019-11714
- https://www.suse.com/security/cve/CVE-2019-11715
- https://www.suse.com/security/cve/CVE-2019-11716
- https://www.suse.com/security/cve/CVE-2019-11717
- https://www.suse.com/security/cve/CVE-2019-11718
- https://www.suse.com/security/cve/CVE-2019-11719
- https://www.suse.com/security/cve/CVE-2019-11720
- https://www.suse.com/security/cve/CVE-2019-11721
- https://www.suse.com/security/cve/CVE-2019-11723
- https://www.suse.com/security/cve/CVE-2019-11724
- https://www.suse.com/security/cve/CVE-2019-11725
- https://www.suse.com/security/cve/CVE-2019-11727
- https://www.suse.com/security/cve/CVE-2019-11728
- https://www.suse.com/security/cve/CVE-2019-11729
- https://www.suse.com/security/cve/CVE-2019-11730
- https://www.suse.com/security/cve/CVE-2019-11733
- https://www.suse.com/security/cve/CVE-2019-11735
- https://www.suse.com/security/cve/CVE-2019-11736
- https://www.suse.com/security/cve/CVE-2019-11738
- https://www.suse.com/security/cve/CVE-2019-11740
- https://www.suse.com/security/cve/CVE-2019-11742
- https://www.suse.com/security/cve/CVE-2019-11743
- https://www.suse.com/security/cve/CVE-2019-11744
- https://www.suse.com/security/cve/CVE-2019-11746
- https://www.suse.com/security/cve/CVE-2019-11747
- https://www.suse.com/security/cve/CVE-2019-11748
- https://www.suse.com/security/cve/CVE-2019-11749
- https://www.suse.com/security/cve/CVE-2019-11750
- https://www.suse.com/security/cve/CVE-2019-11751
- https://www.suse.com/security/cve/CVE-2019-11752
- https://www.suse.com/security/cve/CVE-2019-11753
- https://www.suse.com/security/cve/CVE-2019-11757
- https://www.suse.com/security/cve/CVE-2019-11758
- https://www.suse.com/security/cve/CVE-2019-11759
- https://www.suse.com/security/cve/CVE-2019-11760
- https://www.suse.com/security/cve/CVE-2019-11761
- https://www.suse.com/security/cve/CVE-2019-11762
- https://www.suse.com/security/cve/CVE-2019-11763
- https://www.suse.com/security/cve/CVE-2019-11764
- https://www.suse.com/security/cve/CVE-2019-13173
- https://www.suse.com/security/cve/CVE-2019-15903
- https://www.suse.com/security/cve/CVE-2019-5010
- https://www.suse.com/security/cve/CVE-2019-5737
- https://www.suse.com/security/cve/CVE-2019-9511
- https://www.suse.com/security/cve/CVE-2019-9512
- https://www.suse.com/security/cve/CVE-2019-9513
- https://www.suse.com/security/cve/CVE-2019-9514
- https://www.suse.com/security/cve/CVE-2019-9515
- https://www.suse.com/security/cve/CVE-2019-9516
- https://www.suse.com/security/cve/CVE-2019-9517
- https://www.suse.com/security/cve/CVE-2019-9518
- https://www.suse.com/security/cve/CVE-2019-9636
- https://www.suse.com/security/cve/CVE-2019-9811
- https://www.suse.com/security/cve/CVE-2019-9812
- https://www.suse.com/security/cve/CVE-2019-9947