SuSE 11.3 Security Update : Mozilla Firefox (SAT Patch Number 8657)

critical Nessus Plugin ID 71560
New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it is different from CVSS.

VPR Score: 6.7

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

Mozilla Firefox has been updated to the 24.2.0 ESR security release.

This is a major upgrade from the 17 ESR release branch.

Security issues fixed :

- Application Installation doorhanger persists on navigation. (MFSA 2013-105). (CVE-2013-5611)

- Miscellaneous memory safety hazards (rv:24.2). (MFSA 2013-104). (CVE-2013-5609)

- Miscellaneous memory safety hazards (rv:26.0). (MFSA 2013-104). (CVE-2013-5610)

- Character encoding cross-origin XSS attack. (MFSA 2013-106). (CVE-2013-5612)

- Sandbox restrictions not applied to nested object elements. (MFSA 2013-107). (CVE-2013-5614)

- Use-after-free in event listeners. (MFSA 2013-108).
(CVE-2013-5616)

- Potential overflow in JavaScript binary search algorithms. (MFSA 2013-110). (CVE-2013-5619)

- Segmentation violation when replacing ordered list elements. (MFSA 2013-111). (CVE-2013-6671)

- Trust settings for built-in roots ignored during EV certificate validation. (MFSA 2013-113). (CVE-2013-6673)

- Use-after-free in synthetic mouse movement. (MFSA 2013-114). (CVE-2013-5613)

- GetElementIC typed array stubs can be generated outside observed typesets. (MFSA 2013-115). (CVE-2013-5615)

- Linux clipboard information disclosure though selection paste. (MFSA 2013-112). (CVE-2013-6672)

- Use-after-free during Table Editing (MFSA 2013-109).
(CVE-2013-5618)

Solution

Apply SAT patch number 8657.

See Also

http://www.mozilla.org/security/announce/2013/mfsa2013-105.html

http://www.mozilla.org/security/announce/2013/mfsa2013-107.html

http://www.mozilla.org/security/announce/2013/mfsa2013-108.html

http://www.mozilla.org/security/announce/2013/mfsa2013-109.html

http://www.mozilla.org/security/announce/2013/mfsa2013-110.html

http://www.mozilla.org/security/announce/2013/mfsa2013-111.html

http://www.mozilla.org/security/announce/2013/mfsa2013-112.html

http://www.mozilla.org/security/announce/2013/mfsa2013-113.html

http://www.mozilla.org/security/announce/2013/mfsa2013-115.html

https://bugzilla.novell.com/show_bug.cgi?id=854367

https://bugzilla.novell.com/show_bug.cgi?id=854370

http://support.novell.com/security/cve/CVE-2013-5609.html

http://support.novell.com/security/cve/CVE-2013-5610.html

http://support.novell.com/security/cve/CVE-2013-5611.html

http://support.novell.com/security/cve/CVE-2013-5612.html

http://support.novell.com/security/cve/CVE-2013-5613.html

http://support.novell.com/security/cve/CVE-2013-5614.html

http://support.novell.com/security/cve/CVE-2013-5615.html

http://support.novell.com/security/cve/CVE-2013-5616.html

http://support.novell.com/security/cve/CVE-2013-5618.html

http://support.novell.com/security/cve/CVE-2013-5619.html

http://support.novell.com/security/cve/CVE-2013-6671.html

http://support.novell.com/security/cve/CVE-2013-6672.html

http://support.novell.com/security/cve/CVE-2013-6673.html

Plugin Details

Severity: Critical

ID: 71560

File Name: suse_11_firefox24-201312-131216.nasl

Version: 1.3

Type: local

Agent: unix

Published: 12/20/2013

Updated: 1/19/2021

Dependencies: ssh_get_info.nasl

Risk Information

Risk Factor: Critical

VPR Score: 6.7

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:MozillaFirefox, p-cpe:/a:novell:suse_linux:11:MozillaFirefox-branding-SLED, p-cpe:/a:novell:suse_linux:11:MozillaFirefox-translations, p-cpe:/a:novell:suse_linux:11:libfreebl3, p-cpe:/a:novell:suse_linux:11:libfreebl3-32bit, p-cpe:/a:novell:suse_linux:11:libsoftokn3, p-cpe:/a:novell:suse_linux:11:libsoftokn3-32bit, p-cpe:/a:novell:suse_linux:11:mozilla-nss, p-cpe:/a:novell:suse_linux:11:mozilla-nss-32bit, p-cpe:/a:novell:suse_linux:11:mozilla-nss-tools, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 12/16/2013

Reference Information

CVE: CVE-2013-5609, CVE-2013-5610, CVE-2013-5611, CVE-2013-5612, CVE-2013-5613, CVE-2013-5614, CVE-2013-5615, CVE-2013-5616, CVE-2013-5618, CVE-2013-5619, CVE-2013-6671, CVE-2013-6672, CVE-2013-6673