

Mozilla are in the process of tightening up the security of their Netscape plug-in API (NPAPI) based Add-ons and Extensions that are used to launch and embed applications in the Mozilla Firefox browser.If you have questions please reach out to maintenance coordination. At times this might be only a partial fix. NOTE: This line indicates an update has been released for the listed product(s).

SUSE Linux Enterprise Server 12-SP2-BCL (src): MozillaFirefox-78.2.0-112.19.2 SUSE Linux Enterprise Server 12-SP2-LTSS (src): MozillaFirefox-78.2.0-112.19.2

SUSE Linux Enterprise Server 12-SP3-BCL (src): MozillaFirefox-78.2.0-112.19.2 SUSE Linux Enterprise Server 12-SP3-LTSS (src): MozillaFirefox-78.2.0-112.19.2 SUSE Linux Enterprise Server 12-SP4-LTSS (src): MozillaFirefox-78.2.0-112.19.2 SUSE Linux Enterprise Server for SAP 12-SP2 (src): MozillaFirefox-78.2.0-112.19.2 SUSE Linux Enterprise Server for SAP 12-SP3 (src): MozillaFirefox-78.2.0-112.19.2

SUSE Linux Enterprise Server for SAP 12-SP4 (src): MozillaFirefox-78.2.0-112.19.2 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): MozillaFirefox-78.2.0-112.19.2 SUSE OpenStack Cloud Crowbar 8 (src): MozillaFirefox-78.2.0-112.19.2 SUSE OpenStack Cloud Crowbar 9 (src): MozillaFirefox-78.2.0-112.19.2 CVE-2020-15663: Downgrade attack on the Mozilla Maintenance Service could have resulted in escalation of privilegeĬVE-2020-15664: Attacker-induced prompt for extension installationĬVE-2020-15670: Memory safety bugs fixed in Firefox 80 and Firefox ESR 78.2ĬVE-2020-12401: Timing-attack on ECDSA signature generationĬVE-2020-6829: P-384 and P-521 vulnerable to an electro-magnetic side channel attack on signature generationĬVE-2020-12400: P-384 and P-521 vulnerable to a side channel attack on modular inversionĬVE-2020-15665: Address bar not reset when choosing to stay on a page after the beforeunload dialog is shownĬVE-2020-15666: MediaError message property leaks cross-origin response statusĬVE-2020-15667: Heap overflow when processing an update fileĬVE-2020-15668: Data Race when reading certificate information
