ALT-BU-2015-2405-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-2928
The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.
- [oss-security] 20150406 CVE Request: tor: new upstream releases (0.2.6.7, 0.2.5.12 and 0.2.4.27) fixing security issues
- [oss-security] 20150406 CVE Request: tor: new upstream releases (0.2.6.7, 0.2.5.12 and 0.2.4.27) fixing security issues
- https://trac.torproject.org/projects/tor/ticket/15600
- https://trac.torproject.org/projects/tor/ticket/15600
Modified: 2024-11-21
CVE-2015-2929
The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
Closed vulnerabilities
BDU:2015-09883
Уязвимости браузера Firefox, позволяющие удалённому злоумышленнику вызвать отказ в обслуживании
BDU:2015-09884
Уязвимости браузера Firefox, позволяющие удалённому злоумышленнику вызвать отказ в обслуживании
BDU:2015-09885
Уязвимости браузера Firefox ESR, позволяющие удалённому злоумышленнику вызвать отказ в обслуживании
BDU:2015-09886
Уязвимости почтового клиента Thunderbird, позволяющие удалённому злоумышленнику вызвать отказ в обслуживании
BDU:2015-09887
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти ограничения безопасности
BDU:2015-09888
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный JavaScript-код
BDU:2015-09889
Уязвимость браузера Firefox ESR, позволяющая удалённому злоумышленнику выполнить произвольный JavaScript-код
BDU:2015-09890
Уязвимость почтового клиента Thunderbird, позволяющая удалённому злоумышленнику выполнить произвольный JavaScript-код
BDU:2015-09891
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику получить доступ к динамической памяти процесса или вызвать отказ в обслуживании
BDU:2015-09892
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику вызвать отказ в обслуживании
BDU:2015-09893
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику подделать межсайтовые запросы
BDU:2015-09894
Уязвимость браузера Firefox ESR, позволяющая удалённому злоумышленнику подделать межсайтовые запросы
BDU:2015-09895
Уязвимость почтового клиента Thunderbird, позволяющая удалённому злоумышленнику подделать межсайтовые запросы
BDU:2015-09896
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2015-09897
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2015-09898
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2015-09899
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2015-09900
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный JavaScript-код
BDU:2015-09901
Уязвимость браузера Firefox ESR, позволяющая удалённому злоумышленнику выполнить произвольный JavaScript-код
BDU:2015-09902
Уязвимость почтового клиента Thunderbird, позволяющая удалённому злоумышленнику выполнить произвольный JavaScript-код
BDU:2015-09903
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный JavaScript-код
BDU:2015-09904
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти проверку сертификата
Modified: 2024-11-21
CVE-2015-0799
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-44.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-44.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1032030
- 1032030
- USN-2557-1
- USN-2557-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1148328
- https://bugzilla.mozilla.org/show_bug.cgi?id=1148328
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0801
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- SUSE-SU-2015:0704
- SUSE-SU-2015:0704
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:1266
- openSUSE-SU-2015:1266
- RHSA-2015:0766
- RHSA-2015:0766
- RHSA-2015:0771
- RHSA-2015:0771
- DSA-3211
- DSA-3211
- DSA-3212
- DSA-3212
- http://www.mozilla.org/security/announce/2015/mfsa2015-40.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-40.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- 73455
- 73455
- 1031996
- 1031996
- 1032000
- 1032000
- USN-2550-1
- USN-2550-1
- USN-2552-1
- USN-2552-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1146339
- https://bugzilla.mozilla.org/show_bug.cgi?id=1146339
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0802
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-42.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-42.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1124898
- https://bugzilla.mozilla.org/show_bug.cgi?id=1124898
- GLSA-201512-10
- GLSA-201512-10
- 37958
- 37958
Modified: 2024-11-21
CVE-2015-0803
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-39.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-39.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1134561
- https://bugzilla.mozilla.org/show_bug.cgi?id=1134561
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0804
The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-39.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-39.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1134560
- https://bugzilla.mozilla.org/show_bug.cgi?id=1134560
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0805
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors that trigger rendering of 2D graphics content.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-38.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-38.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1135511
- https://bugzilla.mozilla.org/show_bug.cgi?id=1135511
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0806
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-38.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-38.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1099437
- https://bugzilla.mozilla.org/show_bug.cgi?id=1099437
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0807
The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- SUSE-SU-2015:0704
- SUSE-SU-2015:0704
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:1266
- openSUSE-SU-2015:1266
- RHSA-2015:0766
- RHSA-2015:0766
- RHSA-2015:0771
- RHSA-2015:0771
- DSA-3211
- DSA-3211
- DSA-3212
- DSA-3212
- http://www.mozilla.org/security/announce/2015/mfsa2015-37.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-37.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- 73457
- 73457
- 1031996
- 1031996
- 1032000
- 1032000
- USN-2550-1
- USN-2550-1
- USN-2552-1
- USN-2552-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1111834
- https://bugzilla.mozilla.org/show_bug.cgi?id=1111834
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0808
The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-36.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-36.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1109552
- https://bugzilla.mozilla.org/show_bug.cgi?id=1109552
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0811
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-34.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-34.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1132468
- https://bugzilla.mozilla.org/show_bug.cgi?id=1132468
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0812
Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- http://www.mozilla.org/security/announce/2015/mfsa2015-32.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-32.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1128126
- https://bugzilla.mozilla.org/show_bug.cgi?id=1128126
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0814
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- SUSE-SU-2015:0704
- SUSE-SU-2015:0704
- http://www.mozilla.org/security/announce/2015/mfsa2015-30.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-30.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 1031996
- 1031996
- 1032000
- 1032000
- USN-2550-1
- USN-2550-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1005991
- https://bugzilla.mozilla.org/show_bug.cgi?id=1005991
- https://bugzilla.mozilla.org/show_bug.cgi?id=1111327
- https://bugzilla.mozilla.org/show_bug.cgi?id=1111327
- https://bugzilla.mozilla.org/show_bug.cgi?id=1116306
- https://bugzilla.mozilla.org/show_bug.cgi?id=1116306
- https://bugzilla.mozilla.org/show_bug.cgi?id=1127012
- https://bugzilla.mozilla.org/show_bug.cgi?id=1127012
- https://bugzilla.mozilla.org/show_bug.cgi?id=1130150
- https://bugzilla.mozilla.org/show_bug.cgi?id=1130150
- https://bugzilla.mozilla.org/show_bug.cgi?id=1132342
- https://bugzilla.mozilla.org/show_bug.cgi?id=1132342
- https://bugzilla.mozilla.org/show_bug.cgi?id=1133909
- https://bugzilla.mozilla.org/show_bug.cgi?id=1133909
- https://bugzilla.mozilla.org/show_bug.cgi?id=1136397
- https://bugzilla.mozilla.org/show_bug.cgi?id=1136397
- https://bugzilla.mozilla.org/show_bug.cgi?id=1137624
- https://bugzilla.mozilla.org/show_bug.cgi?id=1137624
- https://bugzilla.mozilla.org/show_bug.cgi?id=1138391
- https://bugzilla.mozilla.org/show_bug.cgi?id=1138391
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0815
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- SUSE-SU-2015:0704
- SUSE-SU-2015:0704
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:1266
- openSUSE-SU-2015:1266
- RHSA-2015:0766
- RHSA-2015:0766
- RHSA-2015:0771
- RHSA-2015:0771
- DSA-3211
- DSA-3211
- DSA-3212
- DSA-3212
- http://www.mozilla.org/security/announce/2015/mfsa2015-30.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-30.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- 73466
- 73466
- 1031996
- 1031996
- 1032000
- 1032000
- USN-2550-1
- USN-2550-1
- USN-2552-1
- USN-2552-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1036515
- https://bugzilla.mozilla.org/show_bug.cgi?id=1036515
- https://bugzilla.mozilla.org/show_bug.cgi?id=1137326
- https://bugzilla.mozilla.org/show_bug.cgi?id=1137326
- https://bugzilla.mozilla.org/show_bug.cgi?id=1138199
- https://bugzilla.mozilla.org/show_bug.cgi?id=1138199
- GLSA-201512-10
- GLSA-201512-10
Modified: 2024-11-21
CVE-2015-0816
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
- openSUSE-SU-2015:0677
- openSUSE-SU-2015:0677
- SUSE-SU-2015:0704
- SUSE-SU-2015:0704
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:0892
- openSUSE-SU-2015:1266
- openSUSE-SU-2015:1266
- RHSA-2015:0766
- RHSA-2015:0766
- RHSA-2015:0771
- RHSA-2015:0771
- DSA-3211
- DSA-3211
- DSA-3212
- DSA-3212
- http://www.mozilla.org/security/announce/2015/mfsa2015-33.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-33.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- 73461
- 73461
- 1031996
- 1031996
- 1032000
- 1032000
- USN-2550-1
- USN-2550-1
- USN-2552-1
- USN-2552-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1144991
- https://bugzilla.mozilla.org/show_bug.cgi?id=1144991
- GLSA-201512-10
- GLSA-201512-10
- 37958
- 37958