{"schema_version":"1.7.3","id":"openSUSE-SU-2019:1534-1","published":"2019-06-10T09:32:29Z","modified":"2026-02-04T04:07:19.932473Z","related":["CVE-2018-18511","CVE-2019-11691","CVE-2019-11692","CVE-2019-11693","CVE-2019-11694","CVE-2019-11698","CVE-2019-5798","CVE-2019-7317","CVE-2019-9797","CVE-2019-9800","CVE-2019-9815","CVE-2019-9816","CVE-2019-9817","CVE-2019-9818","CVE-2019-9819","CVE-2019-9820","CVE-2019-9821"],"upstream":["CVE-2018-18511","CVE-2019-11691","CVE-2019-11692","CVE-2019-11693","CVE-2019-11694","CVE-2019-11698","CVE-2019-5798","CVE-2019-7317","CVE-2019-9797","CVE-2019-9800","CVE-2019-9815","CVE-2019-9816","CVE-2019-9817","CVE-2019-9818","CVE-2019-9819","CVE-2019-9820","CVE-2019-9821"],"summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following issues:\n\nMozillaFirefox was updated to 60.7.0esr (boo#1135824 MFSA 2019-14):\n\n* CVE-2018-18511: Cross-origin theft of images with ImageBitmapRenderingContext\n* CVE-2019-11691: Use-after-free in XMLHttpRequest\n* CVE-2019-11692: Use-after-free removing listeners in the event listener manager\n* CVE-2019-11693: Buffer overflow in WebGL bufferdata on Linux\n* CVE-2019-11694: (Windows only) Uninitialized memory memory leakage in Windows sandbox\n* CVE-2019-11698: Theft of user history data through drag and drop of hyperlinks to and from bookmarks\n* CVE-2019-5798: Out-of-bounds read in Skia\n* CVE-2019-7317: Use-after-free in png_image_free of libpng library\n* CVE-2019-9797: Cross-origin theft of images with createImageBitmap\n* CVE-2019-9800: Memory safety bugs fixed in Firefox 67 and Firefox ESR 60.7\n* CVE-2019-9815: Disable hyperthreading on content JavaScript threads on macOS\n* CVE-2019-9816: Type confusion with object groups and UnboxedObjects\n* CVE-2019-9817: Stealing of cross-domain images using canvas\n* CVE-2019-9818: (Windows only) Use-after-free in crash generation server\n* CVE-2019-9819: Compartment mismatch with fetch API\n* CVE-2019-9820: Use-after-free of ChromeEventHandler by DocShell\n* CVE-2019-9821: Use-after-free in AssertWorkerThread\n","affected":[{"package":{"name":"MozillaFirefox","ecosystem":"openSUSE:Leap 15.0","purl":"pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"60.7.0-lp150.3.54.5"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"60.7.0-lp150.3.54.5","MozillaFirefox-branding-upstream":"60.7.0-lp150.3.54.5","MozillaFirefox-buildsymbols":"60.7.0-lp150.3.54.5","MozillaFirefox-devel":"60.7.0-lp150.3.54.5","MozillaFirefox-translations-common":"60.7.0-lp150.3.54.5","MozillaFirefox-translations-other":"60.7.0-lp150.3.54.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1534-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YRJRSOQJ2HUXLMXMB5IAGC7CGYVG6MJ7/#YRJRSOQJ2HUXLMXMB5IAGC7CGYVG6MJ7"},{"type":"REPORT","url":"https://bugzilla.suse.com/1135824"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18511"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11692"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-11698"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5798"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-7317"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9797"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9800"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9819"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9820"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9821"}]}