Oval Definition:oval:org.opensuse.security:def:58009
Revision Date:2021-09-22Version:1
Title:Security update for MozillaFirefox (Important)
Description:
This update for MozillaFirefox fixes the following issues:

This update contains the Firefox Extended Support Release 91.1.0 ESR.

* Fixed: Various stability, functionality, and security fixes

MFSA 2021-40 (bsc#1190269, bsc#1190274):

* CVE-2021-38492: Navigating to `mk:` URL scheme could load Internet Explorer
* CVE-2021-38495: Memory safety bugs fixed in Firefox 92 and Firefox ESR 91.1

Firefox 91.0.1esr ESR

* Fixed: Fixed an issue causing buttons on the tab bar to be
resized when loading certain websites (bug 1704404)
* Fixed: Fixed an issue which caused tabs from private windows
to be visible in non-private windows when viewing switch-to-
tab results in the address bar panel (bug 1720369)
* Fixed: Various stability fixes
* Fixed: Security fix MFSA 2021-37 (bsc#1189547)
* CVE-2021-29991 (bmo#1724896)
Header Splitting possible with HTTP/3 Responses

Firefox Extended Support Release 91.0 ESR

* New: Some of the highlights of the new Extended Support Release are:

- A number of user interface changes. For more information,
see the Firefox 89 release notes.
- Firefox now supports logging into Microsoft, work, and
school accounts using Windows single sign-on. Learn more
- On Windows, updates can now be applied in the background
while Firefox is not running.
- Firefox for Windows now offers a new page about:third-party
to help identify compatibility issues caused by third-party
applications
- Version 2 of Firefox's SmartBlock feature further improves
private browsing. Third party Facebook scripts are blocked to
prevent you from being tracked, but are now automatically
loaded 'just in time' if you decide to 'Log in with Facebook'
on any website.
- Enhanced the privacy of the Firefox Browser's Private
Browsing mode with Total Cookie Protection, which confines
cookies to the site where they were created, preventing
companis from using cookies to track your browsing across
sites. This feature was originally launched in Firefox's ETP
Strict mode.
- PDF forms now support JavaScript embedded in PDF files.
Some PDF forms use JavaScript for validation and other
interactive features.
- You'll encounter less website breakage in Private Browsing
and Strict Enhanced Tracking Protection with SmartBlock,
which provides stand-in scripts so that websites load
properly.
- Improved Print functionality with a cleaner design and
better integration with your computer's printer settings.
- Firefox now protects you from supercookies, a type of
tracker that can stay hidden in your browser and track you
online, even after you clear cookies. By isolating
supercookies, Firefox prevents them from tracking your web
browsing from one site to the next.
- Firefox now remembers your preferred location for saved
bookmarks, displays the bookmarks toolbar by default on new
tabs, and gives you easy access to all of your bookmarks via
a toolbar folder.
- Native support for macOS devices built with Apple Silicon
CPUs brings dramatic performance improvements over the non-
native build that was shipped in Firefox 83: Firefox launches
over 2.5 times faster and web apps are now twice as
responsive (per the SpeedoMeter 2.0 test). If you are on a
new Apple device, follow these steps to upgrade to the latest
Firefox.
- Pinch zooming will now be supported for our users with
Windows touchscreen devices and touchpads on Mac devices.
Firefox users may now use pinch to zoom on touch-capable
devices to zoom in and out of webpages.
- We’ve improved functionality and design for a number of
Firefox search features:
* Selecting a search engine at the bottom of the search
panel now enters search mode for that engine, allowing you to
see suggestions (if available) for your search terms. The old
behavior (immediately performing a search) is available with
a shift-click.
* When Firefox autocompletes the URL of one of your search
engines, you can now search with that engine directly in the
address bar by selecting the shortcut in the address bar
results.
* We’ve added buttons at the bottom of the search panel to
allow you to search your bookmarks, open tabs, and history.
- Firefox supports AcroForm, which will allow you to fill in,
print, and save supported PDF forms and the PDF viewer also
has a new fresh look.
- For our users in the US and Canada, Firefox can now save,
manage, and auto-fill credit card information for you, making
shopping on Firefox ever more convenient.
- In addition to our default, dark and light themes, with
this release, Firefox introduces the Alpenglow theme: a
colorful appearance for buttons, menus, and windows. You can
update your Firefox themes under settings or preferences.
* Changed: Firefox no longer supports Adobe Flash. There is no
setting available to re-enable Flash support.
* Enterprise: Various bug fixes and new policies have been
implemented in the latest version of Firefox. See more
details in the Firefox for Enterprise 91 Release Notes.

MFSA 2021-33 (bsc#1188891):

* CVE-2021-29986: Race condition when resolving DNS names could have led to
memory corruption
* CVE-2021-29981: Live range splitting could have led to conflicting
assignments in the JIT
* CVE-2021-29988: Memory corruption as a result of incorrect style treatment
* CVE-2021-29983: Firefox for Android could get stuck in fullscreen mode
* CVE-2021-29984: Incorrect instruction reordering during JIT optimization
* CVE-2021-29980: Uninitialized memory in a canvas object could have led to
memory corruption
* CVE-2021-29987: Users could have been tricked into accepting unwanted
permissions on Linux
* CVE-2021-29985: Use-after-free media channels
* CVE-2021-29982: Single bit data leak due to incorrect JIT optimization and
type confusion
* CVE-2021-29989: Memory safety bugs fixed in Firefox 91 and Firefox ESR 78.13
* CVE-2021-29990: Memory safety bugs fixed in Firefox 91
Family:unixClass:patch
Status:Reference(s):1063535
1074662
1083125
1085447
1087082
1087083
1089343
1090368
1090646
1090869
1091236
1092548
1104134
1106171
1106172
1106173
1106195
1106989
1106996
1107410
1107411
1107412
1107413
1107420
1107421
1107422
1107423
1107426
1107581
1107609
1108027
1109105
1109961
1110279
1112767
1113107
1116574
1116998
1118004
1120381
1120767
1120932
1122033
1122053
1122875
1123709
1124365
1124366
1124368
1127558
1127752
1128471
1128472
1128474
1128476
1128480
1128481
1128490
1128492
1128493
1128649
1128954
1128987
1130330
1130414
1131053
1131317
1132053
1132054
1132060
1133719
1138301
1138303
1152856
1154212
1170643
1170771
1174421
1188891
1189547
1190269
1190274
906574
924960
933288
933878
936227
942865
957566
957567
957598
957600
960837
971741
972127
CVE-2014-8964
CVE-2015-2325
CVE-2015-2327
CVE-2015-2328
CVE-2015-3210
CVE-2015-3217
CVE-2015-5073
CVE-2015-8380
CVE-2015-8381
CVE-2015-8382
CVE-2015-8383
CVE-2015-8384
CVE-2015-8385
CVE-2015-8386
CVE-2015-8387
CVE-2015-8388
CVE-2015-8389
CVE-2015-8390
CVE-2015-8391
CVE-2015-8392
CVE-2015-8393
CVE-2015-8394
CVE-2015-8395
CVE-2016-1283
CVE-2016-3191
CVE-2017-1000433
CVE-2017-13166
CVE-2018-1000872
CVE-2018-1087
CVE-2018-11763
CVE-2018-13785
CVE-2018-15908
CVE-2018-15909
CVE-2018-15910
CVE-2018-15911
CVE-2018-16412
CVE-2018-16413
CVE-2018-16509
CVE-2018-16510
CVE-2018-16511
CVE-2018-16513
CVE-2018-16539
CVE-2018-16540
CVE-2018-16541
CVE-2018-16542
CVE-2018-16543
CVE-2018-16585
CVE-2018-16644
CVE-2018-16802
CVE-2018-17183
CVE-2018-20467
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3183
CVE-2018-3214
CVE-2018-3639
CVE-2018-3640
CVE-2018-3646
CVE-2018-4191
CVE-2018-4197
CVE-2018-4207
CVE-2018-4208
CVE-2018-4209
CVE-2018-4210
CVE-2018-4212
CVE-2018-4213
CVE-2018-4261
CVE-2018-4262
CVE-2018-4263
CVE-2018-4264
CVE-2018-4265
CVE-2018-4266
CVE-2018-4267
CVE-2018-4270
CVE-2018-4272
CVE-2018-4273
CVE-2018-4278
CVE-2018-4284
CVE-2018-4299
CVE-2018-4306
CVE-2018-4309
CVE-2018-4312
CVE-2018-4314
CVE-2018-4315
CVE-2018-4316
CVE-2018-4317
CVE-2018-4318
CVE-2018-4319
CVE-2018-4323
CVE-2018-4328
CVE-2018-4345
CVE-2018-4358
CVE-2018-4359
CVE-2018-4361
CVE-2018-4372
CVE-2018-4373
CVE-2018-4375
CVE-2018-4376
CVE-2018-4378
CVE-2018-4382
CVE-2018-4386
CVE-2018-4392
CVE-2018-4416
CVE-2018-5150
CVE-2018-5154
CVE-2018-5155
CVE-2018-5157
CVE-2018-5158
CVE-2018-5159
CVE-2018-5168
CVE-2018-5174
CVE-2018-5178
CVE-2018-5183
CVE-2018-8781
CVE-2018-8897
CVE-2019-10161
CVE-2019-10167
CVE-2019-10650
CVE-2019-11007
CVE-2019-11008
CVE-2019-11009
CVE-2019-2894
CVE-2019-2933
CVE-2019-2945
CVE-2019-2949
CVE-2019-2958
CVE-2019-2962
CVE-2019-2964
CVE-2019-2973
CVE-2019-2978
CVE-2019-2981
CVE-2019-2983
CVE-2019-2987
CVE-2019-2988
CVE-2019-2989
CVE-2019-2992
CVE-2019-2999
CVE-2019-3498
CVE-2019-3855
CVE-2019-3856
CVE-2019-3857
CVE-2019-3858
CVE-2019-3859
CVE-2019-3860
CVE-2019-3861
CVE-2019-3862
CVE-2019-3863
CVE-2019-7175
CVE-2019-7395
CVE-2019-7397
CVE-2019-7398
CVE-2019-9956
CVE-2020-12243
CVE-2020-15705
CVE-2020-3899
CVE-2021-29980
CVE-2021-29981
CVE-2021-29982
CVE-2021-29983
CVE-2021-29984
CVE-2021-29985
CVE-2021-29986
CVE-2021-29987
CVE-2021-29988
CVE-2021-29989
CVE-2021-29990
CVE-2021-29991
CVE-2021-38492
CVE-2021-38495
SUSE-SU-2016:2971-1
SUSE-SU-2018:1334-1
SUSE-SU-2018:1518-1
SUSE-SU-2018:2331-1
SUSE-SU-2018:2975-1
SUSE-SU-2018:3582-1
SUSE-SU-2018:4064-1
SUSE-SU-2019:0059-1
SUSE-SU-2019:0483-1
SUSE-SU-2019:0655-1
SUSE-SU-2019:1033-1
SUSE-SU-2019:1450-1
SUSE-SU-2019:2105-1
SUSE-SU-2019:3084-1
SUSE-SU-2020:1193-1
SUSE-SU-2020:1211-1
SUSE-SU-2020:2308-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • lame-3.100-lp150.1 is installed
  • OR libmp3lame0-3.100-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • cargo-1.36.0-lp151.5.4 is installed
  • OR cargo-doc-1.36.0-lp151.5.4 is installed
  • OR clippy-1.36.0-lp151.5.4 is installed
  • OR rls-1.36.0-lp151.5.4 is installed
  • OR rust-1.36.0-lp151.5.4 is installed
  • OR rust-analysis-1.36.0-lp151.5.4 is installed
  • OR rust-cbindgen-0.8.7-lp151.2 is installed
  • OR rust-doc-1.36.0-lp151.5.4 is installed
  • OR rust-gdb-1.36.0-lp151.5.4 is installed
  • OR rust-src-1.36.0-lp151.5.4 is installed
  • OR rust-std-static-1.36.0-lp151.5.4 is installed
  • OR rustfmt-1.36.0-lp151.5.4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • java-1_7_0-openjdk-1.7.0.241-43.30 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.241-43.30 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.241-43.30 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.241-43.30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • libpcre1-8.39-5 is installed
  • OR libpcre1-32bit-8.39-5 is installed
  • OR libpcre16-0-8.39-5 is installed
  • OR pcre-8.39-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • apache2-2.4.23-29.27 is installed
  • OR apache2-doc-2.4.23-29.27 is installed
  • OR apache2-example-pages-2.4.23-29.27 is installed
  • OR apache2-prefork-2.4.23-29.27 is installed
  • OR apache2-utils-2.4.23-29.27 is installed
  • OR apache2-worker-2.4.23-29.27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libopenssl-devel-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-32bit-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-hmac-1.0.2j-60.39 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.39 is installed
  • OR openssl-1.0.2j-60.39 is installed
  • OR openssl-doc-1.0.2j-60.39 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_103-92_53-default-6-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_16-6-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • apache2-mod_apparmor-2.8.2-49 is installed
  • OR apparmor-docs-2.8.2-49 is installed
  • OR apparmor-parser-2.8.2-49 is installed
  • OR apparmor-profiles-2.8.2-49 is installed
  • OR apparmor-utils-2.8.2-49 is installed
  • OR libapparmor1-2.8.2-49 is installed
  • OR libapparmor1-32bit-2.8.2-49 is installed
  • OR pam_apparmor-2.8.2-49 is installed
  • OR pam_apparmor-32bit-2.8.2-49 is installed
  • OR perl-apparmor-2.8.2-49 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • MozillaFirefox-68.1.0-109.89 is installed
  • OR MozillaFirefox-branding-SLE-68-32.8 is installed
  • OR MozillaFirefox-translations-common-68.1.0-109.89 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • MozillaFirefox-91.1.0-112.71.1 is installed
  • OR MozillaFirefox-branding-SLE-91-35.6.6 is installed
  • OR MozillaFirefox-devel-91.1.0-112.71.1 is installed
  • OR MozillaFirefox-translations-common-91.1.0-112.71.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • MozillaFirefox-68.2.0-109.95 is installed
  • OR MozillaFirefox-translations-common-68.2.0-109.95 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • openssh-7.2p2-74.30 is installed
  • OR openssh-askpass-gnome-7.2p2-74.30 is installed
  • OR openssh-fips-7.2p2-74.30 is installed
  • OR openssh-helpers-7.2p2-74.30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libvirt-4.0.0-6 is installed
  • OR libvirt-admin-4.0.0-6 is installed
  • OR libvirt-client-4.0.0-6 is installed
  • OR libvirt-daemon-4.0.0-6 is installed
  • OR libvirt-daemon-config-network-4.0.0-6 is installed
  • OR libvirt-daemon-config-nwfilter-4.0.0-6 is installed
  • OR libvirt-daemon-driver-interface-4.0.0-6 is installed
  • OR libvirt-daemon-driver-libxl-4.0.0-6 is installed
  • OR libvirt-daemon-driver-lxc-4.0.0-6 is installed
  • OR libvirt-daemon-driver-network-4.0.0-6 is installed
  • OR libvirt-daemon-driver-nodedev-4.0.0-6 is installed
  • OR libvirt-daemon-driver-nwfilter-4.0.0-6 is installed
  • OR libvirt-daemon-driver-qemu-4.0.0-6 is installed
  • OR libvirt-daemon-driver-secret-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-core-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-disk-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-iscsi-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-logical-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-mpath-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-rbd-4.0.0-6 is installed
  • OR libvirt-daemon-driver-storage-scsi-4.0.0-6 is installed
  • OR libvirt-daemon-hooks-4.0.0-6 is installed
  • OR libvirt-daemon-lxc-4.0.0-6 is installed
  • OR libvirt-daemon-qemu-4.0.0-6 is installed
  • OR libvirt-daemon-xen-4.0.0-6 is installed
  • OR libvirt-doc-4.0.0-6 is installed
  • OR libvirt-libs-4.0.0-6 is installed
  • OR libvirt-lock-sanlock-4.0.0-6 is installed
  • OR libvirt-nss-4.0.0-6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND ucode-intel-20180807-13.29 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND ansible-2.4.6.0-3.6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND python-SQLAlchemy-1.2.10-3.3 is installed
  • BACK