Oval Definition:oval:com.redhat.rhsa:def:20220824
Revision Date:2022-03-10Version:637
Title:RHSA-2022:0824: firefox security and bug fix update (Critical)
Description:Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 91.7.0 ESR.

Security Fix(es):

  • Mozilla: Use-after-free in XSLT parameter processing (CVE-2022-26485)

  • Mozilla: Use-after-free in WebGPU IPC Framework (CVE-2022-26486)

  • expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)

  • expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236)

  • expat: Integer overflow in storeRawNames() (CVE-2022-25315)

  • Mozilla: Use-after-free in text reflows (CVE-2022-26381)

  • Mozilla: Browser window spoof using fullscreen mode (CVE-2022-26383)

  • Mozilla: iframe allow-scripts sandbox bypass (CVE-2022-26384)

  • Mozilla: Time-of-check time-of-use bug when verifying add-on signatures (CVE-2022-26387)

  • Mozilla: Temporary files downloaded to /tmp and accessible by other local users (CVE-2022-26386)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Bug Fix(es):

  • Firefox 91.3.0-1 Language packs installed at /usr/lib64/firefox/langpacks cannot be used any more (BZ#2030190)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2022-25235
    CVE-2022-25236
    CVE-2022-25315
    CVE-2022-26381
    CVE-2022-26383
    CVE-2022-26384
    CVE-2022-26386
    CVE-2022-26387
    CVE-2022-26485
    CVE-2022-26486
    RHSA-2022:0824
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND firefox is earlier than 0:91.7.0-3.el7_9
  • AND firefox is signed with Red Hat redhatrelease2 key
  • BACK