Bugzilla – Bug 977373
VUL-0: CVE-2016-2804: MozillaFirefox: Memory safety bugs fixed in Firefox 46 (MFSA 2016-39)
Last modified: 2020-04-05 18:20:50 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-39/ Mozilla developers fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Gary Kwong, Christian Holler, Andrew McCreight, Boris Zbarsky, and Steve Fink reported memory safety problems and crashes that are fixed in Firefox 46. Memory safety bugs fixed in Firefox 46 (CVE-2016-2804) https://bugzilla.mozilla.org/buglist.cgi?bug_id=1240880,1141382,1229855,1155328,1255298,1249183 This one affects openSUSE only.
bugbot adjusting priority
Adjust severity for memory safety bugs
This is an autogenerated message for OBS integration: This bug (977373) was mentioned in https://build.opensuse.org/request/show/392977 Factory / MozillaFirefox https://build.opensuse.org/request/show/392978 42.1 / MozillaFirefox https://build.opensuse.org/request/show/392979 13.2 / MozillaFirefox https://build.opensuse.org/request/show/392980 13.1 / MozillaFirefox
openSUSE submitted, updates running
This is an autogenerated message for OBS integration: This bug (977373) was mentioned in https://build.opensuse.org/request/show/393514 Factory / MozillaFirefox
openSUSE-SU-2016:1211-1: An update that fixes 10 vulnerabilities is now available. Category: security (important) Bug References: 977333,977373,977375,977376,977379,977381,977382,977384,977386,977388 CVE References: CVE-2016-2804,CVE-2016-2806,CVE-2016-2807,CVE-2016-2808,CVE-2016-2811,CVE-2016-2812,CVE-2016-2814,CVE-2016-2816,CVE-2016-2817,CVE-2016-2820 Sources used: openSUSE Leap 42.1 (src): MozillaFirefox-46.0-21.1, mozilla-nss-3.22.3-15.2 openSUSE 13.2 (src): MozillaFirefox-46.0-68.1, mozilla-nss-3.22.3-31.1
Closing bugs exclusive to openSUSE as fixed.
openSUSE-SU-2016:1251-1: An update that fixes 13 vulnerabilities is now available. Category: security (moderate) Bug References: 977333,977373,977375,977376,977377,977378,977379,977380,977381,977382,977384,977386,977388 CVE References: CVE-2016-2804,CVE-2016-2806,CVE-2016-2807,CVE-2016-2808,CVE-2016-2809,CVE-2016-2810,CVE-2016-2811,CVE-2016-2812,CVE-2016-2813,CVE-2016-2814,CVE-2016-2816,CVE-2016-2817,CVE-2016-2820 Sources used: openSUSE 13.1 (src): MozillaFirefox-46.0-113.2, mozilla-nss-3.22.3-77.1