New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 5.9
Synopsis
The remote openSUSE host is missing a security update.
Description
MozillaFirefox was updated to version 39.0 to fix 21 security issues.
These security issues were fixed :
- CVE-2015-2724/CVE-2015-2725/CVE-2015-2726: Miscellaneous memory safety hazards (bsc#935979).
- CVE-2015-2727: Local files or privileged URLs in pages can be opened into new tabs (bsc#935979).
- CVE-2015-2728: Type confusion in Indexed Database Manager (bsc#935979).
- CVE-2015-2729: Out-of-bound read while computing an oscillator rendering range in Web Audio (bsc#935979).
- CVE-2015-2731: Use-after-free in Content Policy due to microtask execution error (bsc#935979).
- CVE-2015-2730: ECDSA signature validation fails to handle some signatures correctly (bsc#935979).
- CVE-2015-2722/CVE-2015-2733: Use-after-free in workers while using XMLHttpRequest (bsc#935979).
- CVE-2015-2734/CVE-2015-2735/CVE-2015-2736/CVE-2015-2737/ CVE-2015-2738/CVE-2015-2739/CVE-2015-2740:
Vulnerabilities found through code inspection (bsc#935979).
- CVE-2015-2741: Key pinning is ignored when overridable errors are encountered (bsc#935979).
- CVE-2015-2743: Privilege escalation in PDF.js (bsc#935979).
- CVE-2015-4000: NSS accepts export-length DHE keys with regular DHE cipher suites (bsc#935979).
- CVE-2015-2721: NSS incorrectly permits skipping of ServerKeyExchange (bsc#935979).
New features :
- Share Hello URLs with social networks
- Support for 'switch' role in ARIA 1.1 (web accessibility)
- SafeBrowsing malware detection lookups enabled for downloads (Mac OS X and Linux)
- Support for new Unicode 8.0 skin tone emoji
- Removed support for insecure SSLv3 for network communications
- Disable use of RC4 except for temporarily whitelisted hosts
- NPAPI Plug-in performance improved via asynchronous initialization
mozilla-nss was updated to version 3.19.2 to fix some of the security issues listed above.
Solution
Update the affected MozillaFirefox / mozilla-nss packages.