SuSE 11.3 Security Update : Mozilla Firefox (SAT Patch Number 8657)

critical Nessus Plugin ID 71560

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

Mozilla Firefox has been updated to the 24.2.0 ESR security release.

This is a major upgrade from the 17 ESR release branch.

Security issues fixed :

- Application Installation doorhanger persists on navigation. (MFSA 2013-105). (CVE-2013-5611)

- Miscellaneous memory safety hazards (rv:24.2). (MFSA 2013-104). (CVE-2013-5609)

- Miscellaneous memory safety hazards (rv:26.0). (MFSA 2013-104). (CVE-2013-5610)

- Character encoding cross-origin XSS attack. (MFSA 2013-106). (CVE-2013-5612)

- Sandbox restrictions not applied to nested object elements. (MFSA 2013-107). (CVE-2013-5614)

- Use-after-free in event listeners. (MFSA 2013-108).
(CVE-2013-5616)

- Potential overflow in JavaScript binary search algorithms. (MFSA 2013-110). (CVE-2013-5619)

- Segmentation violation when replacing ordered list elements. (MFSA 2013-111). (CVE-2013-6671)

- Trust settings for built-in roots ignored during EV certificate validation. (MFSA 2013-113). (CVE-2013-6673)

- Use-after-free in synthetic mouse movement. (MFSA 2013-114). (CVE-2013-5613)

- GetElementIC typed array stubs can be generated outside observed typesets. (MFSA 2013-115). (CVE-2013-5615)

- Linux clipboard information disclosure though selection paste. (MFSA 2013-112). (CVE-2013-6672)

- Use-after-free during Table Editing (MFSA 2013-109).
(CVE-2013-5618)

Solution

Apply SAT patch number 8657.

See Also

http://www.mozilla.org/security/announce/2013/mfsa2013-105.html

http://www.mozilla.org/security/announce/2013/mfsa2013-107.html

http://www.mozilla.org/security/announce/2013/mfsa2013-108.html

http://www.mozilla.org/security/announce/2013/mfsa2013-109.html

http://www.mozilla.org/security/announce/2013/mfsa2013-110.html

http://www.mozilla.org/security/announce/2013/mfsa2013-111.html

http://www.mozilla.org/security/announce/2013/mfsa2013-112.html

http://www.mozilla.org/security/announce/2013/mfsa2013-113.html

http://www.mozilla.org/security/announce/2013/mfsa2013-115.html

https://bugzilla.novell.com/show_bug.cgi?id=854367

https://bugzilla.novell.com/show_bug.cgi?id=854370

http://support.novell.com/security/cve/CVE-2013-5609.html

http://support.novell.com/security/cve/CVE-2013-5610.html

http://support.novell.com/security/cve/CVE-2013-5611.html

http://support.novell.com/security/cve/CVE-2013-5612.html

http://support.novell.com/security/cve/CVE-2013-5613.html

http://support.novell.com/security/cve/CVE-2013-5614.html

http://support.novell.com/security/cve/CVE-2013-5615.html

http://support.novell.com/security/cve/CVE-2013-5616.html

http://support.novell.com/security/cve/CVE-2013-5618.html

http://support.novell.com/security/cve/CVE-2013-5619.html

http://support.novell.com/security/cve/CVE-2013-6671.html

http://support.novell.com/security/cve/CVE-2013-6672.html

http://support.novell.com/security/cve/CVE-2013-6673.html

Plugin Details

Severity: Critical

ID: 71560

File Name: suse_11_firefox24-201312-131216.nasl

Version: 1.3

Type: local

Agent: unix

Published: 12/20/2013

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:mozillafirefox, p-cpe:/a:novell:suse_linux:11:mozillafirefox-branding-sled, p-cpe:/a:novell:suse_linux:11:mozillafirefox-translations, p-cpe:/a:novell:suse_linux:11:libfreebl3, p-cpe:/a:novell:suse_linux:11:libfreebl3-32bit, p-cpe:/a:novell:suse_linux:11:libsoftokn3, p-cpe:/a:novell:suse_linux:11:libsoftokn3-32bit, p-cpe:/a:novell:suse_linux:11:mozilla-nss, p-cpe:/a:novell:suse_linux:11:mozilla-nss-32bit, p-cpe:/a:novell:suse_linux:11:mozilla-nss-tools, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 12/16/2013

Reference Information

CVE: CVE-2013-5609, CVE-2013-5610, CVE-2013-5611, CVE-2013-5612, CVE-2013-5613, CVE-2013-5614, CVE-2013-5615, CVE-2013-5616, CVE-2013-5618, CVE-2013-5619, CVE-2013-6671, CVE-2013-6672, CVE-2013-6673