SUSE-SU-2015:0978-1

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20150978-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:0978-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:0978-1
Upstream
  • CVE-2015-0797
  • CVE-2015-2708
  • CVE-2015-2709
  • CVE-2015-2710
  • CVE-2015-2713
  • CVE-2015-2716
Related
  • CVE-2015-0797
  • CVE-2015-2708
  • CVE-2015-2709
  • CVE-2015-2710
  • CVE-2015-2713
  • CVE-2015-2716
Published
2015-05-19T09:15:45Z
Modified
2026-02-04T04:01:40Z
Summary
Security update for MozillaFirefox
Details

This update to Firefox 31.7.0 ESR fixes the following issues:

* 

  MFSA 2015-46 (CVE-2015-2708, CVE-2015-2709): Miscellaneous memory
  safety hazards (rv:38.0 / rv:31.7). Upstream references: bmo#1120655,
  bmo#1143299, bmo#1151139, bmo#1152177, bmo#1111251, bmo#1117977,
  bmo#1128064, bmo#1135066, bmo#1143194, bmo#1146101, bmo#1149526,
  bmo#1153688, bmo#1155474.

* 

  MFSA 2015-47 (CVE-2015-0797): Buffer overflow parsing H.264 video
  with Linux Gstreamer. Upstream references: bmo#1080995.

* 

  MFSA 2015-48 (CVE-2015-2710): Buffer overflow with SVG content and
  CSS. Upstream references: bmo#1149542.

* 

  MFSA 2015-51 (CVE-2015-2713): Use-after-free during text processing
  with vertical text enabled. Upstream references: bmo#1153478.

* 

  MFSA 2015-54 (CVE-2015-2716): Buffer overflow when parsing compressed
  XML. Upstream references: bmo#1140537.

Security Issues:

* CVE-2015-0797
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0797>
* CVE-2015-2708
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2708>
* CVE-2015-2709
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2709>
* CVE-2015-2710
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2710>
* CVE-2015-2713
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2713>
* CVE-2015-2716
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2716>
References

Affected packages