Security update for MozillaFirefox
This update for MozillaFirefox to ESR 60.9 fixes the following issues: Security issues fixed: - CVE-2019-11742: Fixed a same-origin policy violation involving SVG filters and canvas to steal cross-origin images. (bsc#1149303) - CVE-2019-11746: Fixed a use-after-free while manipulating video. (bsc#1149297) - CVE-2019-11744: Fixed an XSS caused by breaking out of title and textarea elements using innerHTML. (bsc#1149304) - CVE-2019-11753: Fixed a privilege escalation with Mozilla Maintenance Service in custom Firefox installation location. (bsc#1149295) - CVE-2019-11752: Fixed a use-after-free while extracting a key value in IndexedDB. (bsc#1149296) - CVE-2019-11743: Fixed a timing side-channel attack on cross-origin information, utilizing unload event attributes. (bsc#1149298) - CVE-2019-11740: Fixed several memory safety bugs. (bsc#1149299)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for MozillaFirefox to ESR 60.9 fixes the following issues: Security issues fixed: - CVE-2019-11742: Fixed a same-origin policy violation involving SVG filters and canvas to steal cross-origin images. (bsc#1149303) - CVE-2019-11746: Fixed a use-after-free while manipulating video. (bsc#1149297) - CVE-2019-11744: Fixed an XSS caused by breaking out of title and textarea elements using innerHTML. (bsc#1149304) - CVE-2019-11753: Fixed a privilege escalation with Mozilla Maintenance Service in custom Firefox installation location. (bsc#1149295) - CVE-2019-11752: Fixed a use-after-free while extracting a key value in IndexedDB. (bsc#1149296) - CVE-2019-11743: Fixed a timing side-channel attack on cross-origin information, utilizing unload event attributes. (bsc#1149298) - CVE-2019-11740: Fixed several memory safety bugs. (bsc#1149299)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1149294
- https://bugzilla.suse.com/1149295
- https://bugzilla.suse.com/1149296
- https://bugzilla.suse.com/1149297
- https://bugzilla.suse.com/1149298
- https://bugzilla.suse.com/1149299
- https://bugzilla.suse.com/1149303
- https://bugzilla.suse.com/1149304
- https://bugzilla.suse.com/1149324
- https://www.suse.com/security/cve/CVE-2019-11740
- https://www.suse.com/security/cve/CVE-2019-11742
- https://www.suse.com/security/cve/CVE-2019-11743
- https://www.suse.com/security/cve/CVE-2019-11744
- https://www.suse.com/security/cve/CVE-2019-11746
- https://www.suse.com/security/cve/CVE-2019-11752
- https://www.suse.com/security/cve/CVE-2019-11753
- https://www.suse.com/security/cve/CVE-2019-9812
- https://www.suse.com/support/update/announcement/2019/suse-su-20192436-1/