{"id":"SUSE-SU-2015:0706-1","summary":"Security update for Mozilla Firefox","details":"\nMozilla Firefox was updated to 31.6.0 ESR to fix five security issues.\n\nThe following vulnerabilities have been fixed:\n\n    * Miscellaneous memory safety hazards (MFSA\n      2015-30/CVE-2015-0814/CVE-2015-0815)\n    * Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA\n      2015-31/CVE-2015-0813)\n    * resource:// documents can load privileged pages (MFSA\n      2015-33/CVE-2015-0816)\n    * CORS requests should not follow 30x redirections after preflight\n      (MFSA 2015-37/CVE-2015-0807)\n    * Same-origin bypass through anchor navigation (MFSA\n      2015-40/CVE-2015-0801)\n\nSecurity Issues:\n\n    * CVE-2015-0801\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0801\u003e\n    * CVE-2015-0807\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0807\u003e\n    * CVE-2015-0813\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0813\u003e\n    * CVE-2015-0814\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0814\u003e\n    * CVE-2015-0816\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0816\u003e\n\n","modified":"2026-02-04T02:46:32.341417Z","published":"2015-04-02T12:17:21Z","related":["CVE-2015-0801","CVE-2015-0807","CVE-2015-0813","CVE-2015-0814","CVE-2015-0816"],"upstream":["CVE-2015-0801","CVE-2015-0807","CVE-2015-0813","CVE-2015-0814","CVE-2015-0816"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150706-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/925368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0801"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0807"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0813"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0816"}],"schema_version":"1.7.3"}