Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1731-1

Опубликовано: 18 мая 2022
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 91.9.0 ESR (MFSA 2022-17)(bsc#1198970):

  • CVE-2022-29914: Fullscreen notification bypass using popups
  • CVE-2022-29909: Bypassing permission prompt in nested browsing contexts
  • CVE-2022-29916: Leaking browser history with CSS variables
  • CVE-2022-29911: iframe Sandbox bypass
  • CVE-2022-29912: Reader mode bypassed SameSite cookies
  • CVE-2022-29917: Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9

Список пакетов

Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
MozillaFirefox-91.9.0-150000.150.38.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise High Performance Computing 15-ESPOS
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise High Performance Computing 15-LTSS
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise Server 15 SP1-BCL
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise Server 15 SP1-LTSS
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise Server 15-LTSS
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise Server for SAP Applications 15
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3
SUSE Linux Enterprise Server for SAP Applications 15 SP1
MozillaFirefox-91.9.0-150000.150.38.3
MozillaFirefox-devel-91.9.0-150000.150.38.3
MozillaFirefox-translations-common-91.9.0-150000.150.38.3
MozillaFirefox-translations-other-91.9.0-150000.150.38.3

Описание

Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-devel-91.9.0-150000.150.38.3

Ссылки

Описание

An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-devel-91.9.0-150000.150.38.3

Ссылки

Описание

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-devel-91.9.0-150000.150.38.3

Ссылки

Описание

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-devel-91.9.0-150000.150.38.3

Ссылки

Описание

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-devel-91.9.0-150000.150.38.3

Ссылки

Описание

Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-91.9.0-150000.150.38.3
SUSE Enterprise Storage 6:MozillaFirefox-devel-91.9.0-150000.150.38.3

Ссылки
Уязвимость SUSE-SU-2022:1731-1