File _patchinfo of Package patchinfo
<patchinfo incident="4692">
<packager>wrosenauer</packager>
<issue tracker="cve" id="2016-9080"></issue>
<issue tracker="cve" id="2016-9893"></issue>
<issue tracker="cve" id="2016-9894"></issue>
<issue tracker="cve" id="2016-9895"></issue>
<issue tracker="cve" id="2016-9896"></issue>
<issue tracker="cve" id="2016-9897"></issue>
<issue tracker="cve" id="2016-9898"></issue>
<issue tracker="cve" id="2016-9899"></issue>
<issue tracker="cve" id="2016-9900"></issue>
<issue tracker="cve" id="2016-9901"></issue>
<issue tracker="cve" id="2016-9902"></issue>
<issue tracker="cve" id="2016-9903"></issue>
<issue tracker="cve" id="2016-9904"></issue>
<issue tracker="bmo" id="1301381"></issue>
<issue tracker="bmo" id="1306628"></issue>
<issue tracker="bmo" id="1312272"></issue>
<issue tracker="bmo" id="1314442"></issue>
<issue tracker="bmo" id="1315435"></issue>
<issue tracker="bmo" id="1315543"></issue>
<issue tracker="bmo" id="1317409"></issue>
<issue tracker="bmo" id="1317936"></issue>
<issue tracker="bmo" id="1319122"></issue>
<issue tracker="bmo" id="1320039"></issue>
<issue tracker="bmo" id="1320057"></issue>
<issue tracker="bnc" id="1011922">AArch64: Firefox crashes after a few seconds of usage</issue>
<issue tracker="bnc" id="1015422">VUL-0: MozillaFirefox 50.1 / 45.6 ESR security release</issue>
<category>security</category>
<rating>important</rating>
<summary>Security update for MozillaFirefox</summary>
<description> This update to MozillaFirefox 50.1.0 fixes the following vulnerabilities:
- CVE-2016-9894: Buffer overflow in SkiaGL
- CVE-2016-9899: Use-after-free while manipulating DOM events and audio
elements
- CVE-2016-9895: CSP bypass using marquee tag
- CVE-2016-9896: Use-after-free with WebVR
- CVE-2016-9897: Memory corruption in libGLES
- CVE-2016-9898: Use-after-free in Editor while manipulating DOM subtrees
- CVE-2016-9900: Restricted external resources can be loaded by SVG images
through data URLs
- CVE-2016-9904: Cross-origin information leak in shared atoms
- CVE-2016-9901: Data from Pocket server improperly sanitized before
execution
- CVE-2016-9902: Pocket extension does not validate the origin of events
- CVE-2016-9903: XSS injection vulnerability in add-ons SDK
- CVE-2016-9080: Memory safety bugs fixed in Firefox 50.1
- CVE-2016-9893: Memory safety bugs fixed in Firefox 50.1 and Firefox ESR
45.6
The following bugs were fixed:
- boo#1011922: fix crash after a few seconds of usage on AArch64
</description>
</patchinfo>