Bug 977374 (CVE-2016-2805) - VUL-0: CVE-2016-2805: MozillaFirefox: Memory safety bug fixed in Firefox ESR 38.8 (MFSA 2016-39)
Summary: VUL-0: CVE-2016-2805: MozillaFirefox: Memory safety bug fixed in Firefox ESR...
Status: RESOLVED FIXED
Alias: CVE-2016-2805
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All All
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2016-04-29
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:SUSE:CVE-2016-2805:6.8:(AV:N/A...
Keywords:
Depends on: 977333
Blocks:
  Show dependency treegraph
 
Reported: 2016-04-27 08:34 UTC by Andreas Stieger
Modified: 2016-06-02 10:56 UTC (History)
7 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-04-27 08:34:21 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-39/

Mozilla developers fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. 

Christian Holler reported a memory safety problem that is fixed in Firefox ESR 38.8.

Memory safety bug fixed in Firefox ESR 38.8 (CVE-2016-2805)
https://bugzilla.mozilla.org/show_bug.cgi?id=1241731
Comment 1 Swamp Workflow Management 2016-04-27 11:48:17 UTC
An update workflow for this issue was started.
This issue was rated as critical.
Please submit fixed packages until 2016-04-29.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62674
Comment 2 Swamp Workflow Management 2016-04-27 22:00:31 UTC
bugbot adjusting priority
Comment 3 Andreas Stieger 2016-04-28 12:19:47 UTC
Adjust severity for memory safety bugs
Comment 4 Andreas Stieger 2016-04-30 11:38:37 UTC
All submission received, incidents running
Comment 5 Swamp Workflow Management 2016-05-06 18:08:09 UTC
SUSE-SU-2016:1258-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 977333,977374,977376,977381,977386
CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    MozillaFirefox-38.8.0esr-66.2
SUSE Linux Enterprise Software Development Kit 12 (src):    MozillaFirefox-38.8.0esr-66.2
SUSE Linux Enterprise Server 12-SP1 (src):    MozillaFirefox-38.8.0esr-66.2
SUSE Linux Enterprise Server 12 (src):    MozillaFirefox-38.8.0esr-66.2
SUSE Linux Enterprise Desktop 12-SP1 (src):    MozillaFirefox-38.8.0esr-66.2
SUSE Linux Enterprise Desktop 12 (src):    MozillaFirefox-38.8.0esr-66.2
Comment 6 Swamp Workflow Management 2016-05-18 16:09:49 UTC
SUSE-SU-2016:1342-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 977333,977374,977376,977381,977386
CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814
Sources used:
SUSE Linux Enterprise Server 11-SP2-LTSS (src):    MozillaFirefox-38.8.0esr-40.1
SUSE Linux Enterprise Debuginfo 11-SP2 (src):    MozillaFirefox-38.8.0esr-40.1
Comment 7 Swamp Workflow Management 2016-05-18 19:07:59 UTC
SUSE-SU-2016:1352-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 977333,977374,977376,977381,977386
CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814
Sources used:
SUSE Linux Enterprise Server 10 SP4 LTSS (src):    MozillaFirefox-38.8.0esr-0.5.1
Comment 8 Swamp Workflow Management 2016-05-20 17:08:32 UTC
SUSE-SU-2016:1374-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 977333,977374,977376,977381,977386
CVE References: CVE-2016-2805,CVE-2016-2807,CVE-2016-2808,CVE-2016-2814
Sources used:
SUSE OpenStack Cloud 5 (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
SUSE Manager Proxy 2.1 (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
SUSE Manager 2.1 (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
SUSE Linux Enterprise Server 11-SP4 (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    MozillaFirefox-38.8.0esr-40.5, mozilla-nspr-4.12-26.1, mozilla-nss-3.20.2-30.1
Comment 9 Sebastian Krahmer 2016-05-23 11:17:02 UTC
released