FlawAtlas
Search the atlas
SUSE-SU-2019:14246-1 Not scored

Security update for Mozilla Firefox

This update contains the Mozilla Firefox ESR 68.2 release. Mozilla Firefox was updated to ESR 68.2 release: * Enterprise: New administrative policies were added. More information and templates are available at the Policy Templates page. * Various security fixes: MFSA 2019-33 (bsc#1154738) * CVE-2019-15903: Heap overflow in expat library in XML_GetCurrentLineNumber * CVE-2019-11757: Use-after-free when creating index updates in IndexedDB * CVE-2019-11758: Potentially exploitable crash due to 360 Total Security * CVE-2019-11759: Stack buffer overflow in HKDF output * CVE-2019-11760: Stack buffer overflow in WebRTC networking * CVE-2019-11761: Unintended access to a privileged JSONView object * CVE-2019-11762: document.domain-based origin isolation has same-origin- property violation * CVE-2019-11763: Incorrect HTML parsing results in XSS bypass technique * CVE-2019-11764: Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2 Other Issues resolved: * [bsc#1104841] Newer versions of firefox have a dependency on GLIBCXX_3.4.20 * [bsc#1074235] MozillaFirefox: background tab crash reports sent inadvertently without user opt-in * [bsc#1043008] Firefox hangs randomly when browsing and scrolling * [bsc#1025108] Firefox stops loading page until mouse is moved * [bsc#905528] Firefox malfunctions due to broken omni.ja archives

Exploit probability Not scored
Published January 17, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 11 SP4-LTSS MozillaFirefox
SUSE:Linux Enterprise Server 11 SP4-LTSS MozillaFirefox-branding-SLED
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-atk
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-cairo
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-gdk-pixbuf
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-glib2
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-gtk3
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-harfbuzz
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-libffi
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-libffi-gcc5
SUSE:Linux Enterprise Server 11 SP4-LTSS firefox-pango
SUSE:Linux Enterprise Server 11 SP4-LTSS mozilla-nspr
SUSE:Linux Enterprise Server 11 SP4-LTSS mozilla-nss

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2019:14246-1

This update contains the Mozilla Firefox ESR 68.2 release. Mozilla Firefox was updated to ESR 68.2 release: * Enterprise: New administrative policies were added. More information and templates are available at the Policy Templates page. * Various security fixes: MFSA 2019-33 (bsc#1154738) * CVE-2019-15903: Heap overflow in expat library in XML_GetCurrentLineNumber * CVE-2019-11757: Use-after-free when creating index updates in IndexedDB * CVE-2019-11758: Potentially exploitable crash due to 360 Total Security * CVE-2019-11759: Stack buffer overflow in HKDF output * CVE-2019-11760: Stack buffer overflow in WebRTC networking * CVE-2019-11761: Unintended access to a privileged JSONView object * CVE-2019-11762: document.domain-based origin isolation has same-origin- property violation * CVE-2019-11763: Incorrect HTML parsing results in XSS bypass technique * CVE-2019-11764: Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2 Other Issues resolved: * [bsc#1104841] Newer versions of firefox have a dependency on GLIBCXX_3.4.20 * [bsc#1074235] MozillaFirefox: background tab crash reports sent inadvertently without user opt-in * [bsc#1043008] Firefox hangs randomly when browsing and scrolling * [bsc#1025108] Firefox stops loading page until mouse is moved * [bsc#905528] Firefox malfunctions due to broken omni.ja archives

View original source

05 / REFERENCES

Further evidence