Bug 1160498 - (CVE-2019-17026) EMU: VUL-0: MozillaFirefox, Update Firefox to 72.0.1/68.4.1 esr (MFSA 2020-03)
(CVE-2019-17026)
EMU: VUL-0: MozillaFirefox, Update Firefox to 72.0.1/68.4.1 esr (MFSA 2020-03)
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Charles Robertson
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-01-08 22:55 UTC by Charles Robertson
Modified: 2022-09-06 16:42 UTC (History)
7 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Charles Robertson 2020-01-08 22:55:25 UTC
CVE-2019-17026 (bmo#1607443)
    IonMonkey type confusion with StoreElementHole and
    FallibleStoreElement
Comment 1 Alexandros Toptsoglou 2020-01-09 07:30:48 UTC
Link to the advisory:

https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/
Comment 2 Swamp Workflow Management 2020-01-09 08:11:04 UTC
This is an autogenerated message for OBS integration:
This bug (1160498) was mentioned in
https://build.opensuse.org/request/show/762071 Factory / MozillaFirefox
Comment 6 Swamp Workflow Management 2020-01-10 14:14:30 UTC
SUSE-SU-2020:0068-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE OpenStack Cloud 8 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE OpenStack Cloud 7 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP5 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP4 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    MozillaFirefox-68.4.1-109.101.1
SUSE Enterprise Storage 5 (src):    MozillaFirefox-68.4.1-109.101.1
HPE Helion Openstack 8 (src):    MozillaFirefox-68.4.1-109.101.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2020-01-10 17:14:14 UTC
SUSE-SU-2020:14268-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    MozillaFirefox-68.4.1-78.57.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2020-01-11 09:20:09 UTC
This is an autogenerated message for OBS integration:
This bug (1160498) was mentioned in
https://build.opensuse.org/request/show/763056 Factory / MozillaThunderbird
Comment 10 Swamp Workflow Management 2020-01-13 14:15:37 UTC
SUSE-SU-2020:0078-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    MozillaFirefox-68.4.1-3.66.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    MozillaFirefox-68.4.1-3.66.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (src):    MozillaFirefox-68.4.1-3.66.1
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    MozillaFirefox-68.4.1-3.66.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2020-01-15 14:11:30 UTC
openSUSE-SU-2020:0060-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
openSUSE Leap 15.1 (src):    MozillaFirefox-68.4.1-lp151.2.24.1
Comment 12 Swamp Workflow Management 2020-01-20 20:14:19 UTC
SUSE-SU-2020:0142-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
SUSE Linux Enterprise Workstation Extension 15-SP1 (src):    MozillaThunderbird-68.4.1-3.66.1
SUSE Linux Enterprise Workstation Extension 15 (src):    MozillaThunderbird-68.4.1-3.66.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2020-01-22 17:12:44 UTC
openSUSE-SU-2020:0094-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1160305,1160498
CVE References: CVE-2019-17015,CVE-2019-17016,CVE-2019-17017,CVE-2019-17021,CVE-2019-17022,CVE-2019-17024,CVE-2019-17026
Sources used:
openSUSE Leap 15.1 (src):    MozillaThunderbird-68.4.1-lp151.2.22.2
Comment 15 Marcus Meissner 2020-04-17 15:50:11 UTC
released