FlawAtlas
Search the atlas
SUSE-SU-2018:0374-1 Not scored

Security update for MozillaFirefox

This update for MozillaFirefox to version 52.6 several issues. These security issues were fixed: - CVE-2018-5091: Use-after-free with DTMF timers (bsc#1077291). - CVE-2018-5095: Integer overflow in Skia library during edge builder allocation (bsc#1077291). - CVE-2018-5096: Use-after-free while editing form elements (bsc#1077291). - CVE-2018-5097: Use-after-free when source document is manipulated during XSLT (bsc#1077291). - CVE-2018-5098: Use-after-free while manipulating form input elements (bsc#1077291). - CVE-2018-5099: Use-after-free with widget listener (bsc#1077291). - CVE-2018-5104: Use-after-free during font face manipulation (bsc#1077291). - CVE-2018-5089: Fixed several memory safety bugs (bsc#1077291). - CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right (bsc#1077291). - CVE-2018-5102: Use-after-free in HTML media elements (bsc#1077291). - CVE-2018-5103: Use-after-free during mouse event handling (bsc#1077291).

Exploit probability Not scored
Published February 6, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Desktop 12 SP3 MozillaFirefox
SUSE:Linux Enterprise Server 12 SP1-LTSS MozillaFirefox
SUSE:Linux Enterprise Server 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Server 12 SP3 MozillaFirefox
SUSE:Linux Enterprise Server 12-LTSS MozillaFirefox
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 MozillaFirefox
SUSE:Linux Enterprise Software Development Kit 12 SP2 MozillaFirefox
SUSE:Linux Enterprise Software Development Kit 12 SP3 MozillaFirefox
SUSE:OpenStack Cloud 6 MozillaFirefox

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:0374-1

This update for MozillaFirefox to version 52.6 several issues. These security issues were fixed: - CVE-2018-5091: Use-after-free with DTMF timers (bsc#1077291). - CVE-2018-5095: Integer overflow in Skia library during edge builder allocation (bsc#1077291). - CVE-2018-5096: Use-after-free while editing form elements (bsc#1077291). - CVE-2018-5097: Use-after-free when source document is manipulated during XSLT (bsc#1077291). - CVE-2018-5098: Use-after-free while manipulating form input elements (bsc#1077291). - CVE-2018-5099: Use-after-free with widget listener (bsc#1077291). - CVE-2018-5104: Use-after-free during font face manipulation (bsc#1077291). - CVE-2018-5089: Fixed several memory safety bugs (bsc#1077291). - CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right (bsc#1077291). - CVE-2018-5102: Use-after-free in HTML media elements (bsc#1077291). - CVE-2018-5103: Use-after-free during mouse event handling (bsc#1077291).

View original source

05 / REFERENCES

Further evidence