Bug 1010404 (CVE-2016-9066)

Summary: VUL-0: CVE-2016-9066: MozillaFirefox: Integer overflow leading to a buffer overflow in nsScriptLoadHandler
Product: [Novell Products] SUSE Security Incidents Reporter: Johannes Segitz <jsegitz>
Component: IncidentsAssignee: Petr Cerny <pcerny>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Major    
Priority: P3 - Medium    
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard: CVSSv2:SUSE:CVE-2016-9066:6.8:(AV:N/AC:M/Au:N/C:P/I:P/A:P) CVSSv2:RedHat:CVE-2016-9066:5.1:(AV:N/AC:H/Au:N/C:P/I:P/A:P) maint:released:oes2015:63202 CVSSv3:RedHat:CVE-2016-9066:5.6:(AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Bug Depends on:    
Bug Blocks: 1009026    

Description Johannes Segitz 2016-11-16 09:32:42 UTC
Security vulnerabilities fixed in Firefox 50
https://www.mozilla.org/security/announce/2016/mfsa2016-89.html

Discovered by: Samuel GroƟ
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data.

https://bugzilla.mozilla.org/show_bug.cgi?id=1299686
Comment 1 Swamp Workflow Management 2016-11-16 23:00:53 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2016-11-18 16:07:53 UTC
openSUSE-SU-2016:2861-1: An update that fixes 19 vulnerabilities is now available.

Category: security (important)
Bug References: 1009026,1010395,1010399,1010401,1010402,1010404,1010405,1010406,1010408,1010409,1010410,1010420,1010421,1010422,1010423,1010424,1010425,1010426,1010427
CVE References: CVE-2016-5289,CVE-2016-5290,CVE-2016-5291,CVE-2016-5292,CVE-2016-5296,CVE-2016-5297,CVE-2016-9063,CVE-2016-9064,CVE-2016-9066,CVE-2016-9067,CVE-2016-9068,CVE-2016-9069,CVE-2016-9070,CVE-2016-9071,CVE-2016-9073,CVE-2016-9074,CVE-2016-9075,CVE-2016-9076,CVE-2016-9077
Sources used:
openSUSE Leap 42.2 (src):    MozillaFirefox-50.0-39.2, mozilla-nss-3.26.2-32.1
openSUSE Leap 42.1 (src):    MozillaFirefox-50.0-39.1, mozilla-nss-3.26.2-32.1
openSUSE 13.2 (src):    MozillaFirefox-50.0-88.1, mozilla-nss-3.26.2-49.1
Comment 3 Bernhard Wiedemann 2016-12-04 11:00:51 UTC
This is an autogenerated message for OBS integration:
This bug (1010404) was mentioned in
https://build.opensuse.org/request/show/443688 13.1 / MozillaThunderbird
Comment 4 Swamp Workflow Management 2016-12-05 18:07:52 UTC
openSUSE-SU-2016:3011-1: An update that fixes 30 vulnerabilities is now available.

Category: security (important)
Bug References: 1009026,1010401,1010404,1010410,1010411,1010427,1012807,1012964
CVE References: CVE-2016-5289,CVE-2016-5290,CVE-2016-5291,CVE-2016-5292,CVE-2016-5293,CVE-2016-5294,CVE-2016-5295,CVE-2016-5296,CVE-2016-5297,CVE-2016-5298,CVE-2016-5299,CVE-2016-9061,CVE-2016-9062,CVE-2016-9063,CVE-2016-9064,CVE-2016-9065,CVE-2016-9066,CVE-2016-9067,CVE-2016-9068,CVE-2016-9069,CVE-2016-9070,CVE-2016-9071,CVE-2016-9072,CVE-2016-9073,CVE-2016-9074,CVE-2016-9075,CVE-2016-9076,CVE-2016-9077,CVE-2016-9078,CVE-2016-9079
Sources used:
openSUSE 13.1 (src):    MozillaFirefox-50.0.2-131.1, MozillaThunderbird-45.5.1-70.92.1, mozilla-nss-3.26.2-94.1
Comment 5 Swamp Workflow Management 2016-12-05 20:08:01 UTC
SUSE-SU-2016:3014-1: An update that solves 8 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1009026,1010395,1010401,1010402,1010404,1010410,1010422,1010427,1010517,992549
CVE References: CVE-2016-5285,CVE-2016-5290,CVE-2016-5291,CVE-2016-5296,CVE-2016-5297,CVE-2016-9064,CVE-2016-9066,CVE-2016-9074
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Server for SAP 12 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Server 12-SP2 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Server 12-SP1 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Server 12-LTSS (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    MozillaFirefox-45.5.0esr-88.1, mozilla-nss-3.21.3-50.1
Comment 6 Swamp Workflow Management 2016-12-06 12:07:50 UTC
openSUSE-SU-2016:3019-1: An update that solves 6 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1009026,1010401,1010404,1010410,1010411,1010427,1012964
CVE References: CVE-2016-5290,CVE-2016-5291,CVE-2016-5296,CVE-2016-5297,CVE-2016-9066,CVE-2016-9079
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    MozillaThunderbird-45.5.1-17.1
Comment 7 Swamp Workflow Management 2016-12-10 22:10:50 UTC
SUSE-SU-2016:3080-1: An update that solves 9 vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1000751,1009026,1010395,1010401,1010402,1010404,1010410,1010422,1010427,1010517,1012964,992549
CVE References: CVE-2016-5285,CVE-2016-5290,CVE-2016-5291,CVE-2016-5296,CVE-2016-5297,CVE-2016-9064,CVE-2016-9066,CVE-2016-9074,CVE-2016-9079
Sources used:
SUSE OpenStack Cloud 5 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Manager Proxy 2.1 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Manager 2.1 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Linux Enterprise Server 11-SP4 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    MozillaFirefox-45.5.1esr-59.1, mozilla-nss-3.21.3-39.1
Comment 8 Swamp Workflow Management 2016-12-13 12:08:51 UTC
SUSE-SU-2016:3105-1: An update that solves 9 vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1000751,1009026,1010395,1010401,1010402,1010404,1010410,1010422,1010427,1010517,1012964,992549
CVE References: CVE-2016-5285,CVE-2016-5290,CVE-2016-5291,CVE-2016-5296,CVE-2016-5297,CVE-2016-9064,CVE-2016-9066,CVE-2016-9074,CVE-2016-9079
Sources used:
SUSE Linux Enterprise Server 11-SP2-LTSS (src):    MozillaFirefox-45.5.1esr-63.1, mozilla-nss-3.21.3-30.1
SUSE Linux Enterprise Debuginfo 11-SP2 (src):    MozillaFirefox-45.5.1esr-63.1, mozilla-nss-3.21.3-30.1
Comment 9 Marcus Meissner 2017-04-13 11:14:35 UTC
released