FlawAtlas
Search the atlas
SUSE-SU-2017:0714-1 Not scored

Security update for MozillaFirefox

This update for MozillaFirefox to ESR 45.8 fixes the following issues: Security issues fixed (bsc#1028391): - CVE-2017-5402: Use-after-free working with events in FontFace objects - CVE-2017-5410: Memory corruption during JavaScript garbage collection incremental sweeping - CVE-2017-5400: asm.js JIT-spray bypass of ASLR and DEP - CVE-2017-5401: Memory Corruption when handling ErrorResult - CVE-2017-5407: Pixel and history stealing via floating-point timing side channel with SVG filters - CVE-2017-5404: Use-after-free working with ranges in selections - CVE-2017-5405: FTP response codes can cause use of uninitialized values for ports - CVE-2017-5408: Cross-origin reading of video captions in violation of CORS - CVE-2017-5409: File deletion via callback parameter in Mozilla Windows Updater and Maintenance Service - CVE-2017-5398: Memory safety bugs fixed in Firefox 52 and Firefox ESR 45.8

Exploit probability Not scored
Published March 17, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP1 MozillaFirefox
SUSE:Linux Enterprise Desktop 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Server 12 SP1 MozillaFirefox
SUSE:Linux Enterprise Server 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Server 12-LTSS MozillaFirefox
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Software Development Kit 12 SP1 MozillaFirefox
SUSE:Linux Enterprise Software Development Kit 12 SP2 MozillaFirefox

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2017:0714-1

This update for MozillaFirefox to ESR 45.8 fixes the following issues: Security issues fixed (bsc#1028391): - CVE-2017-5402: Use-after-free working with events in FontFace objects - CVE-2017-5410: Memory corruption during JavaScript garbage collection incremental sweeping - CVE-2017-5400: asm.js JIT-spray bypass of ASLR and DEP - CVE-2017-5401: Memory Corruption when handling ErrorResult - CVE-2017-5407: Pixel and history stealing via floating-point timing side channel with SVG filters - CVE-2017-5404: Use-after-free working with ranges in selections - CVE-2017-5405: FTP response codes can cause use of uninitialized values for ports - CVE-2017-5408: Cross-origin reading of video captions in violation of CORS - CVE-2017-5409: File deletion via callback parameter in Mozilla Windows Updater and Maintenance Service - CVE-2017-5398: Memory safety bugs fixed in Firefox 52 and Firefox ESR 45.8

View original source

05 / REFERENCES

Further evidence