{"affected":[{"ecosystem_specific":{"binaries":[{"MozillaFirefox":"60.2.2-3.13.3","MozillaFirefox-branding-SLE":"60-4.5.3","MozillaFirefox-devel":"60.2.2-3.13.3","MozillaFirefox-translations-common":"60.2.2-3.13.3","MozillaFirefox-translations-other":"60.2.2-3.13.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"MozillaFirefox","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"60.2.2-3.13.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"MozillaFirefox":"60.2.2-3.13.3","MozillaFirefox-branding-SLE":"60-4.5.3","MozillaFirefox-devel":"60.2.2-3.13.3","MozillaFirefox-translations-common":"60.2.2-3.13.3","MozillaFirefox-translations-other":"60.2.2-3.13.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"MozillaFirefox-branding-SLE","purl":"pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"60-4.5.3"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\n  \nThis update for MozillaFirefox to 60.2.2ESR fixes the following issues:\n\nSecurity issues fixed:\n\nMFSA 2018-24:\n\n- CVE-2018-12386: A Type confusion in JavaScript allowed remote code execution (bsc#1110506)\n- CVE-2018-12387: Array.prototype.push stack pointer vulnerability may have enabled exploits in the sandboxed content process (bsc#1110507)\n\nMFSA 2018-23:\n\n- CVE-2018-12385: Fixed a crash in TransportSecurityInfo due to cached data (bsc#1109363)\n- CVE-2018-12383: Setting a master password did not delete unencrypted previously stored passwords (bsc#1107343)\n \nNon security issues fixed:\n\n- Avoid undefined behavior in IPC fd-passing code (bsc#1094767)\n- Fixed a startup crash affecting users migrating from older ESR releases\n- Clean up old NSS DB files after upgrading\n- Fixed an endianness problem in bindgen's handling of\n  bitfields, which was causing Firefox to crash on startup on big-endian\n  machines.  Also, updates the cc crate, which was buggy in the version\n  that was originally vendored in. (bsc#1109465)\n","id":"SUSE-SU-2018:3476-1","modified":"2018-10-25T18:09:44Z","published":"2018-10-25T18:09:44Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20183476-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094767"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107343"},{"type":"REPORT","url":"https://bugzilla.suse.com/1109363"},{"type":"REPORT","url":"https://bugzilla.suse.com/1109465"},{"type":"REPORT","url":"https://bugzilla.suse.com/1110506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1110507"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12386"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12387"}],"related":["CVE-2018-12383","CVE-2018-12385","CVE-2018-12386","CVE-2018-12387"],"summary":"Security update for MozillaFirefox","upstream":["CVE-2018-12383","CVE-2018-12385","CVE-2018-12386","CVE-2018-12387"]}