{"id":"SUSE-SU-2015:0704-2","summary":"Security update for MozillaFirefox","details":"Mozilla Firefox was updated to 31.6.0 ESR to fix five security issues.\n\nThe following vulnerabilities were fixed:\n\n* Miscellaneous memory safety hazards (MFSA 2015-30/CVE-2015-0814/CVE-2015-0815)\n* Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA 2015-31/CVE-2015-0813)\n* resource:// documents can load privileged pages (MFSA 2015-33/CVE-2015-0816)\n* CORS requests should not follow 30x redirections after preflight (MFSA 2015-37/CVE-2015-0807)\n* Same-origin bypass through anchor navigation (MFSA 2015-40/CVE-2015-0801)\n","modified":"2026-02-04T03:04:02.465813Z","published":"2015-04-02T14:42:07Z","related":["CVE-2015-0801","CVE-2015-0807","CVE-2015-0813","CVE-2015-0814","CVE-2015-0815","CVE-2015-0816"],"upstream":["CVE-2015-0801","CVE-2015-0807","CVE-2015-0813","CVE-2015-0814","CVE-2015-0815","CVE-2015-0816"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150704-2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/925368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0801"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0807"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0813"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0816"}],"affected":[{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Desktop 12","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"31.6.0esr-30.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations":"31.6.0esr-30.1","MozillaFirefox":"31.6.0esr-30.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:0704-2.json"}}],"schema_version":"1.7.3"}