Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2022:40696-1

Опубликовано: 03 мар. 2022
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 91.6.0 ESR / MFSA 2022-05 (bsc#1195682)

  • CVE-2022-22753: Privilege Escalation to SYSTEM on Windows via Maintenance Service
  • CVE-2022-22754: Extensions could have bypassed permission confirmation during update
  • CVE-2022-22756: Drag and dropping an image could have resulted in the dropped object being an executable
  • CVE-2022-22759: Sandboxed iframes could have executed script if the parent appended elements
  • CVE-2022-22760: Cross-Origin responses could be distinguished between script and non-script content-types
  • CVE-2022-22761: frame-ancestors Content Security Policy directive was not enforced for framed extension pages
  • CVE-2022-22763: Script Execution during invalid object state
  • CVE-2022-22764: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6

Firefox Extended Support Release 91.5.1 ESR (bsc#1195230)

  • Fixed an issue that allowed unexpected data to be submitted in some of our search telemetry

Список пакетов

openSUSE Leap 15.4
MozillaFirefox-91.6.0-152.15.1
MozillaFirefox-branding-upstream-91.6.0-152.15.1
MozillaFirefox-devel-91.6.0-152.15.1
MozillaFirefox-translations-common-91.6.0-152.15.1
MozillaFirefox-translations-other-91.6.0-152.15.1

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
openSUSE Leap 15.4:MozillaFirefox-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-branding-upstream-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-devel-91.6.0-152.15.1
openSUSE Leap 15.4:MozillaFirefox-translations-common-91.6.0-152.15.1

Ссылки
Уязвимость openSUSE-SU-2022:40696-1