Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1757-1

Опубликовано: 19 мая 2022
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 91.9.0 ESR (MFSA 2022-17)(bsc#1198970):

  • CVE-2022-29914: Fullscreen notification bypass using popups
  • CVE-2022-29909: Bypassing permission prompt in nested browsing contexts
  • CVE-2022-29916: Leaking browser history with CSS variables
  • CVE-2022-29911: iframe Sandbox bypass
  • CVE-2022-29912: Reader mode bypassed SameSite cookies
  • CVE-2022-29917: Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9

Список пакетов

HPE Helion OpenStack 8
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
MozillaFirefox-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
MozillaFirefox-91.9.0-112.108.4
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
MozillaFirefox-91.9.0-112.108.4
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
MozillaFirefox-91.9.0-112.108.4
SUSE Linux Enterprise Server 12 SP2-BCL
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Server 12 SP3-BCL
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Server 12 SP3-LTSS
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Server 12 SP4-LTSS
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Server 12 SP5
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Server for SAP Applications 12 SP3
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Server for SAP Applications 12 SP4
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE Linux Enterprise Software Development Kit 12 SP5
MozillaFirefox-devel-91.9.0-112.108.4
SUSE OpenStack Cloud 8
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE OpenStack Cloud 9
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE OpenStack Cloud Crowbar 8
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4
SUSE OpenStack Cloud Crowbar 9
MozillaFirefox-91.9.0-112.108.4
MozillaFirefox-devel-91.9.0-112.108.4
MozillaFirefox-translations-common-91.9.0-112.108.4

Описание

Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-devel-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-translations-common-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-112.108.4

Ссылки

Описание

An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-devel-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-translations-common-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-112.108.4

Ссылки

Описание

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-devel-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-translations-common-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-112.108.4

Ссылки

Описание

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-devel-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-translations-common-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-112.108.4

Ссылки

Описание

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-devel-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-translations-common-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-112.108.4

Ссылки

Описание

Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.


Затронутые продукты
HPE Helion OpenStack 8:MozillaFirefox-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-devel-91.9.0-112.108.4
HPE Helion OpenStack 8:MozillaFirefox-translations-common-91.9.0-112.108.4
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:MozillaFirefox-91.9.0-112.108.4

Ссылки