SuSE 11.3 Security Update : Mozilla Firefox (SAT Patch Number 8657)

critical Nessus Plugin ID 71559
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

Mozilla Firefox has been updated to the 24.2.0 ESR security release.

This is a major upgrade from the 17 ESR release branch.

Security issues fixed :

- Application Installation doorhanger persists on navigation. (MFSA 2013-105). (CVE-2013-5611)

- Miscellaneous memory safety hazards (rv:24.2). (MFSA 2013-104). (CVE-2013-5609)

- Miscellaneous memory safety hazards (rv:26.0). (MFSA 2013-104). (CVE-2013-5610)

- Character encoding cross-origin XSS attack. (MFSA 2013-106). (CVE-2013-5612)

- Sandbox restrictions not applied to nested object elements. (MFSA 2013-107). (CVE-2013-5614)

- Use-after-free in event listeners. (MFSA 2013-108).
(CVE-2013-5616)

- Potential overflow in JavaScript binary search algorithms. (MFSA 2013-110). (CVE-2013-5619)

- Segmentation violation when replacing ordered list elements. (MFSA 2013-111). (CVE-2013-6671)

- Trust settings for built-in roots ignored during EV certificate validation. (MFSA 2013-113). (CVE-2013-6673)

- Use-after-free in synthetic mouse movement. (MFSA 2013-114). (CVE-2013-5613)

- GetElementIC typed array stubs can be generated outside observed typesets. (MFSA 2013-115). (CVE-2013-5615)

- Linux clipboard information disclosure though selection paste. (MFSA 2013-112). (CVE-2013-6672)

- Use-after-free during Table Editing (MFSA 2013-109).
(CVE-2013-5618)

Solution

Apply SAT patch number 8657.

See Also

http://www.mozilla.org/security/announce/2013/mfsa2013-105.html

http://www.mozilla.org/security/announce/2013/mfsa2013-107.html

http://www.mozilla.org/security/announce/2013/mfsa2013-108.html

http://www.mozilla.org/security/announce/2013/mfsa2013-109.html

http://www.mozilla.org/security/announce/2013/mfsa2013-110.html

http://www.mozilla.org/security/announce/2013/mfsa2013-111.html

http://www.mozilla.org/security/announce/2013/mfsa2013-112.html

http://www.mozilla.org/security/announce/2013/mfsa2013-113.html

http://www.mozilla.org/security/announce/2013/mfsa2013-115.html

https://bugzilla.novell.com/show_bug.cgi?id=854367

https://bugzilla.novell.com/show_bug.cgi?id=854370

http://support.novell.com/security/cve/CVE-2013-5609.html

http://support.novell.com/security/cve/CVE-2013-5610.html

http://support.novell.com/security/cve/CVE-2013-5611.html

http://support.novell.com/security/cve/CVE-2013-5612.html

http://support.novell.com/security/cve/CVE-2013-5613.html

http://support.novell.com/security/cve/CVE-2013-5614.html

http://support.novell.com/security/cve/CVE-2013-5615.html

http://support.novell.com/security/cve/CVE-2013-5616.html

http://support.novell.com/security/cve/CVE-2013-5618.html

http://support.novell.com/security/cve/CVE-2013-5619.html

http://support.novell.com/security/cve/CVE-2013-6671.html

http://support.novell.com/security/cve/CVE-2013-6672.html

http://support.novell.com/security/cve/CVE-2013-6673.html

Plugin Details

Severity: Critical

ID: 71559

File Name: suse_11_firefox24-201312-131215.nasl

Version: 1.3

Type: local

Agent: unix

Published: 12/20/2013

Updated: 1/19/2021

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:MozillaFirefox, p-cpe:/a:novell:suse_linux:11:MozillaFirefox-branding-SLED, p-cpe:/a:novell:suse_linux:11:MozillaFirefox-translations, p-cpe:/a:novell:suse_linux:11:libfreebl3, p-cpe:/a:novell:suse_linux:11:libsoftokn3, p-cpe:/a:novell:suse_linux:11:mozilla-nss, p-cpe:/a:novell:suse_linux:11:mozilla-nss-tools, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 12/15/2013

Reference Information

CVE: CVE-2013-5609, CVE-2013-5610, CVE-2013-5611, CVE-2013-5612, CVE-2013-5613, CVE-2013-5614, CVE-2013-5615, CVE-2013-5616, CVE-2013-5618, CVE-2013-5619, CVE-2013-6671, CVE-2013-6672, CVE-2013-6673