Upstream information
CVE-2011-3655 at MITRE
Description
Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote attackers to gain privileges via a crafted web site.
NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
No Novell Bugzilla entries cross referenced.
SUSE Security Advisories:
- SUSE-SU-2011:1256-1, published Thu, 17 Nov 2011 23:08:23 +0100 (CET)
- SUSE-SU-2011:1256-2, published Fri, 18 Nov 2011 22:08:26 +0100 (CET)
- openSUSE-SU-2011:1243-1, published Tue, 15 Nov 2011 15:08:39 +0100 (CET)
- openSUSE-SU-2011:1290-1, published Thu, 1 Dec 2011 15:08:20 +0100 (CET)
- openSUSE-SU-2012:0567-1, published Fri, 27 Apr 2012 15:08:15 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
| openSUSE 11.4 DEBUGINFO | MozillaFirefox-debuginfo >= 8.0-0.2.2 MozillaFirefox-debugsource >= 8.0-0.2.2 MozillaThunderbird-debuginfo >= 3.1.16-0.19.2 MozillaThunderbird-debugsource >= 3.1.16-0.19.2 MozillaThunderbird-devel-debuginfo >= 3.1.16-0.19.2 enigmail-debuginfo >= 1.1.2+3.1.16-0.19.2 mozilla-js192-debuginfo >= 1.9.2.24-0.2.2 mozilla-js192-debuginfo-32bit >= 1.9.2.24-0.2.2 mozilla-xulrunner192-debuginfo >= 1.9.2.24-0.2.2 mozilla-xulrunner192-debuginfo-32bit >= 1.9.2.24-0.2.2 mozilla-xulrunner192-debugsource >= 1.9.2.24-0.2.2 mozilla-xulrunner192-devel-debuginfo >= 1.9.2.24-0.2.2 mozilla-xulrunner192-gnome-debuginfo >= 1.9.2.24-0.2.2 mozilla-xulrunner192-gnome-debuginfo-32bit >= 1.9.2.24-0.2.2
| |
| openSUSE 11.4 | MozillaFirefox >= 8.0-0.2.2 MozillaFirefox-branding-openSUSE >= 5.0-2.5.1 MozillaFirefox-branding-upstream >= 8.0-0.2.2 MozillaFirefox-buildsymbols >= 8.0-0.2.2 MozillaFirefox-devel >= 8.0-0.2.2 MozillaFirefox-translations-common >= 8.0-0.2.2 MozillaFirefox-translations-other >= 8.0-0.2.2 MozillaThunderbird >= 3.1.16-0.19.2 MozillaThunderbird-buildsymbols >= 3.1.16-0.19.2 MozillaThunderbird-devel >= 3.1.16-0.19.2 MozillaThunderbird-translations-common >= 3.1.16-0.19.2 MozillaThunderbird-translations-other >= 3.1.16-0.19.2 enigmail >= 1.1.2+3.1.16-0.19.2 mozilla-js192 >= 1.9.2.24-0.2.2 mozilla-js192-32bit >= 1.9.2.24-0.2.2 mozilla-xulrunner192 >= 1.9.2.24-0.2.2 mozilla-xulrunner192-32bit >= 1.9.2.24-0.2.2 mozilla-xulrunner192-buildsymbols >= 1.9.2.24-0.2.2 mozilla-xulrunner192-devel >= 1.9.2.24-0.2.2 mozilla-xulrunner192-gnome >= 1.9.2.24-0.2.2 mozilla-xulrunner192-gnome-32bit >= 1.9.2.24-0.2.2 mozilla-xulrunner192-translations-common >= 1.9.2.24-0.2.2 mozilla-xulrunner192-translations-common-32bit >= 1.9.2.24-0.2.2 mozilla-xulrunner192-translations-other >= 1.9.2.24-0.2.2 mozilla-xulrunner192-translations-other-32bit >= 1.9.2.24-0.2.2
| |
openSUSE 11.3 openSUSE 11.4 | seamonkey >= 2.5-0.2.1 seamonkey-dom-inspector >= 2.5-0.2.1 seamonkey-irc >= 2.5-0.2.1 seamonkey-translations-common >= 2.5-0.2.1 seamonkey-translations-other >= 2.5-0.2.1 seamonkey-venkman >= 2.5-0.2.1
| |
openSUSE 11.3 openSUSE 11.4 DEBUGINFO | seamonkey-debuginfo >= 2.5-0.2.1 seamonkey-debugsource >= 2.5-0.2.1
| |
SUSE Linux Enterprise Desktop 10 SP4 for x86 SUSE Linux Enterprise Server 10 SP4 for x86 | mozilla-nss >= 3.13.1-0.5.1 mozilla-nss-devel >= 3.13.1-0.5.1 mozilla-nss-tools >= 3.13.1-0.5.1
| Builds ZYPP Patch Nr: 7842 |
SLE SDK 10 SP4 for IBM iSeries and IBM pSeries SLE SDK 10 SP4 for IBM zSeries SLE SDK 10 SP4 for IPF SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 | mozilla-nss-tools >= 3.13.1-0.5.1
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IPF | mozilla-nss >= 3.13.1-0.5.1 mozilla-nss-devel >= 3.13.1-0.5.1 mozilla-nss-tools >= 3.13.1-0.5.1 mozilla-nss-x86 >= 3.13.1-0.5.1
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER | mozilla-nss >= 3.13.1-0.5.1 mozilla-nss-64bit >= 3.13.1-0.5.1 mozilla-nss-devel >= 3.13.1-0.5.1 mozilla-nss-tools >= 3.13.1-0.5.1
| Builds ZYPP Patch Nr: 7842 |
SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit | mozilla-nss >= 3.13.1-0.5.1 mozilla-nss-32bit >= 3.13.1-0.5.1 mozilla-nss-devel >= 3.13.1-0.5.1 mozilla-nss-tools >= 3.13.1-0.5.1
| Builds ZYPP Patch Nr: 7842 |