SUSE-SU-2015:0593-2

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20150593-2/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:0593-2.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:0593-2
Upstream
  • CVE-2015-0817
  • CVE-2015-0818
Related
  • CVE-2015-0817
  • CVE-2015-0818
Published
2015-03-23T23:58:05Z
Modified
2026-02-04T03:56:46.401437Z
Summary
Security update for MozillaFirefox
Details

MozillaFirefox was updated to the 31.5.3ESR release to fix two security vulnerabilities:

* 

  MFSA 2015-29 / CVE-2015-0817: Security researcher ilxu1a reported,
  through HP Zero Day Initiative's Pwn2Own contest, a flaw in Mozilla's
  implementation of typed array bounds checking in JavaScript
  just-in-time compilation (JIT) and its management of bounds checking
  for heap access. This flaw can be leveraged into the reading and
  writing of memory allowing for arbitrary code execution on the local
  system.

* 

  MFSA 2015-28 / CVE-2015-0818: Security researcher Mariusz Mlynski
  reported, through HP Zero Day Initiative's Pwn2Own contest, a method
  to run arbitrary scripts in a privileged context. This bypassed the
  same-origin policy protections by using a flaw in the processing of
  SVG format content navigation.

Security Issues:

* CVE-2015-0817
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0817>
* CVE-2015-0818
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0818>
References

Affected packages