SUSE-SU-2015:2336-1

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20152336-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:2336-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:2336-1
Upstream
  • CVE-2015-7201
  • CVE-2015-7202
  • CVE-2015-7205
  • CVE-2015-7210
  • CVE-2015-7212
  • CVE-2015-7213
  • CVE-2015-7214
  • CVE-2015-7222
Related
  • CVE-2015-7201
  • CVE-2015-7202
  • CVE-2015-7205
  • CVE-2015-7210
  • CVE-2015-7212
  • CVE-2015-7213
  • CVE-2015-7214
  • CVE-2015-7222
Published
2015-12-21T16:19:48Z
Modified
2026-02-04T03:49:23Z
Summary
Security update for MozillaFirefox
Details

MozillaFirefox was updated to version 38.5.0 ESR.

It fixes the following security issues:

  • MFSA 2015-134/CVE-2015-7201/CVE-2015-7202 Miscellaneous memory safety hazards (rv:43.0 / rv:38.5)
  • MFSA 2015-138/CVE-2015-7210 Use-after-free in WebRTC when datachannel is used after being destroyed
  • MFSA 2015-139/CVE-2015-7212 Integer overflow allocating extremely large textures
  • MFSA 2015-145/CVE-2015-7205 Underflow through code inspection
  • MFSA 2015-146/CVE-2015-7213 Integer overflow in MP4 playback in 64-bit versions
  • MFSA 2015-147/CVE-2015-7222 Integer underflow and buffer overflow processing MP4 metadata in libstagefright
  • MFSA 2015-149/CVE-2015-7214 Cross-site reading attack through data and view-source URIs
References

Affected packages

SUSE:Linux Enterprise Server 11 SP2-LTSS / MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
38.5.0esr-28.2

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "38.5.0esr-28.2",
            "MozillaFirefox-translations": "38.5.0esr-28.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:2336-1.json"