{"affected":[{"ecosystem_specific":{"binaries":[{"MozillaFirefox":"60.2.0-3.10.1","MozillaFirefox-branding-SLE":"60-4.3.1","MozillaFirefox-devel":"60.2.0-3.10.1","MozillaFirefox-translations-common":"60.2.0-3.10.1","MozillaFirefox-translations-other":"60.2.0-3.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"MozillaFirefox","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"60.2.0-3.10.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"MozillaFirefox":"60.2.0-3.10.1","MozillaFirefox-branding-SLE":"60-4.3.1","MozillaFirefox-devel":"60.2.0-3.10.1","MozillaFirefox-translations-common":"60.2.0-3.10.1","MozillaFirefox-translations-other":"60.2.0-3.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"MozillaFirefox-branding-SLE","purl":"pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"60-4.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for MozillaFirefox to ESR 60.2 fixes several issues.\n\nThese general changes are part of the version 60 release.\n\n- New browser engine with speed improvements\n- Redesigned graphical user interface elements\n- Unified address and search bar for new installations\n- New tab page listing top visited, recently visited and recommended pages\n- Support for configuration policies in enterprise deployments via JSON files\n- Support for Web Authentication, allowing the use of USB tokens for\n  authentication to web sites\n\nThe following changes affect compatibility:\n\n- Now exclusively supports extensions built using the WebExtension API.\n- Unsupported legacy extensions will no longer work in Firefox 60 ESR\n- TLS certificates issued by Symantec before June 1st, 2016 are no longer trusted\n  The 'security.pki.distrust_ca_policy' preference can be set to 0 to reinstate\n  trust in those certificates\n\nThe following issues affect performance:\n\n- new format for storing private keys, certificates and certificate trust\n  If the user home or data directory is on a network file system, it is\n  recommended that users set the following environment variable to avoid\n  slowdowns: NSS_SDB_USE_CACHE=yes\n  This setting is not recommended for local, fast file systems.\n\nThese security issues were fixed:\n\n- CVE-2018-12381: Dragging and dropping Outlook email message results in page navigation (bsc#1107343).\n- CVE-2017-16541: Proxy bypass using automount and autofs (bsc#1107343).\n- CVE-2018-12376: Various memory safety bugs (bsc#1107343).\n- CVE-2018-12377: Use-after-free in refresh driver timers (bsc#1107343).\n- CVE-2018-12378: Use-after-free in IndexedDB (bsc#1107343).\n- CVE-2018-12379: Out-of-bounds write with malicious MAR file (bsc#1107343).\n","id":"SUSE-SU-2018:2890-1","modified":"2018-09-27T10:04:13Z","published":"2018-09-27T10:04:13Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20182890-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107343"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-12381"}],"related":["CVE-2017-16541","CVE-2018-12376","CVE-2018-12377","CVE-2018-12378","CVE-2018-12379","CVE-2018-12381"],"summary":"Security update for MozillaFirefox","upstream":["CVE-2017-16541","CVE-2018-12376","CVE-2018-12377","CVE-2018-12378","CVE-2018-12379","CVE-2018-12381"]}