Oval Definition:oval:org.opensuse.security:def:58832
Revision Date:2021-09-22Version:1
Title:Security update for MozillaFirefox (Important)
Description:
This update for MozillaFirefox fixes the following issues:

This update contains the Firefox Extended Support Release 91.1.0 ESR.

* Fixed: Various stability, functionality, and security fixes

MFSA 2021-40 (bsc#1190269, bsc#1190274):

* CVE-2021-38492: Navigating to `mk:` URL scheme could load Internet Explorer
* CVE-2021-38495: Memory safety bugs fixed in Firefox 92 and Firefox ESR 91.1

Firefox 91.0.1esr ESR

* Fixed: Fixed an issue causing buttons on the tab bar to be
resized when loading certain websites (bug 1704404)
* Fixed: Fixed an issue which caused tabs from private windows
to be visible in non-private windows when viewing switch-to-
tab results in the address bar panel (bug 1720369)
* Fixed: Various stability fixes
* Fixed: Security fix MFSA 2021-37 (bsc#1189547)
* CVE-2021-29991 (bmo#1724896)
Header Splitting possible with HTTP/3 Responses

Firefox Extended Support Release 91.0 ESR

* New: Some of the highlights of the new Extended Support Release are:

- A number of user interface changes. For more information,
see the Firefox 89 release notes.
- Firefox now supports logging into Microsoft, work, and
school accounts using Windows single sign-on. Learn more
- On Windows, updates can now be applied in the background
while Firefox is not running.
- Firefox for Windows now offers a new page about:third-party
to help identify compatibility issues caused by third-party
applications
- Version 2 of Firefox's SmartBlock feature further improves
private browsing. Third party Facebook scripts are blocked to
prevent you from being tracked, but are now automatically
loaded 'just in time' if you decide to 'Log in with Facebook'
on any website.
- Enhanced the privacy of the Firefox Browser's Private
Browsing mode with Total Cookie Protection, which confines
cookies to the site where they were created, preventing
companis from using cookies to track your browsing across
sites. This feature was originally launched in Firefox's ETP
Strict mode.
- PDF forms now support JavaScript embedded in PDF files.
Some PDF forms use JavaScript for validation and other
interactive features.
- You'll encounter less website breakage in Private Browsing
and Strict Enhanced Tracking Protection with SmartBlock,
which provides stand-in scripts so that websites load
properly.
- Improved Print functionality with a cleaner design and
better integration with your computer's printer settings.
- Firefox now protects you from supercookies, a type of
tracker that can stay hidden in your browser and track you
online, even after you clear cookies. By isolating
supercookies, Firefox prevents them from tracking your web
browsing from one site to the next.
- Firefox now remembers your preferred location for saved
bookmarks, displays the bookmarks toolbar by default on new
tabs, and gives you easy access to all of your bookmarks via
a toolbar folder.
- Native support for macOS devices built with Apple Silicon
CPUs brings dramatic performance improvements over the non-
native build that was shipped in Firefox 83: Firefox launches
over 2.5 times faster and web apps are now twice as
responsive (per the SpeedoMeter 2.0 test). If you are on a
new Apple device, follow these steps to upgrade to the latest
Firefox.
- Pinch zooming will now be supported for our users with
Windows touchscreen devices and touchpads on Mac devices.
Firefox users may now use pinch to zoom on touch-capable
devices to zoom in and out of webpages.
- We’ve improved functionality and design for a number of
Firefox search features:
* Selecting a search engine at the bottom of the search
panel now enters search mode for that engine, allowing you to
see suggestions (if available) for your search terms. The old
behavior (immediately performing a search) is available with
a shift-click.
* When Firefox autocompletes the URL of one of your search
engines, you can now search with that engine directly in the
address bar by selecting the shortcut in the address bar
results.
* We’ve added buttons at the bottom of the search panel to
allow you to search your bookmarks, open tabs, and history.
- Firefox supports AcroForm, which will allow you to fill in,
print, and save supported PDF forms and the PDF viewer also
has a new fresh look.
- For our users in the US and Canada, Firefox can now save,
manage, and auto-fill credit card information for you, making
shopping on Firefox ever more convenient.
- In addition to our default, dark and light themes, with
this release, Firefox introduces the Alpenglow theme: a
colorful appearance for buttons, menus, and windows. You can
update your Firefox themes under settings or preferences.
* Changed: Firefox no longer supports Adobe Flash. There is no
setting available to re-enable Flash support.
* Enterprise: Various bug fixes and new policies have been
implemented in the latest version of Firefox. See more
details in the Firefox for Enterprise 91 Release Notes.

MFSA 2021-33 (bsc#1188891):

* CVE-2021-29986: Race condition when resolving DNS names could have led to
memory corruption
* CVE-2021-29981: Live range splitting could have led to conflicting
assignments in the JIT
* CVE-2021-29988: Memory corruption as a result of incorrect style treatment
* CVE-2021-29983: Firefox for Android could get stuck in fullscreen mode
* CVE-2021-29984: Incorrect instruction reordering during JIT optimization
* CVE-2021-29980: Uninitialized memory in a canvas object could have led to
memory corruption
* CVE-2021-29987: Users could have been tricked into accepting unwanted
permissions on Linux
* CVE-2021-29985: Use-after-free media channels
* CVE-2021-29982: Single bit data leak due to incorrect JIT optimization and
type confusion
* CVE-2021-29989: Memory safety bugs fixed in Firefox 91 and Firefox ESR 78.13
* CVE-2021-29990: Memory safety bugs fixed in Firefox 91
Family:unixClass:patch
Status:Reference(s):1012382
1031717
1042286
1046610
1057734
1061599
1062604
1064232
1065364
1070536
1075428
1075608
1076847
1077560
1082153
1082299
1082519
1082863
1083125
1083302
1083303
1083745
1083836
1084353
1084536
1084610
1084721
1084829
1085042
1085185
1085224
1085402
1085404
1086162
1086194
1087088
1087260
1087845
1088241
1088242
1088600
1088684
1088810
1089066
1089198
1089608
1089644
1089752
1090643
1092903
1094466
1095344
1096547
1097104
1099597
1099811
1099813
1099844
1099845
1099846
1099849
1099863
1099864
1099922
1099993
1099999
1100000
1100001
1100152
1102517
1102682
1102715
1102870
1103445
1104319
1104495
1105292
1105296
1105322
1105348
1105396
1105536
1106016
1106095
1106369
1106509
1106511
1106512
1106594
1106989
1106996
1107116
1107121
1107609
1107689
1107735
1107832
1107966
1108239
1108399
1109160
1109333
1118367
1118368
1120381
1122033
1124365
1124366
1124368
1124729
1124734
1128378
1128649
1130330
1131317
1132053
1132054
1132060
1137001
1139073
1141035
1153108
1154043
1155094
1155988
1156321
1156331
1157770
1162224
1162367
1162825
1165894
1171740
1188891
1189547
1190269
1190274
CVE-2010-3609
CVE-2014-2653
CVE-2014-3564
CVE-2014-6051
CVE-2014-6052
CVE-2014-6053
CVE-2014-6054
CVE-2014-6055
CVE-2015-5352
CVE-2015-5600
CVE-2015-6563
CVE-2015-6564
CVE-2015-8325
CVE-2016-0777
CVE-2016-0778
CVE-2016-10009
CVE-2016-10010
CVE-2016-10011
CVE-2016-10012
CVE-2016-1908
CVE-2016-3115
CVE-2016-4912
CVE-2016-6210
CVE-2016-6354
CVE-2016-6515
CVE-2016-7567
CVE-2016-8858
CVE-2017-15132
CVE-2017-18257
CVE-2018-10087
CVE-2018-10124
CVE-2018-10853
CVE-2018-1087
CVE-2018-10876
CVE-2018-10877
CVE-2018-10878
CVE-2018-10879
CVE-2018-10880
CVE-2018-10881
CVE-2018-10882
CVE-2018-10883
CVE-2018-10902
CVE-2018-10938
CVE-2018-10940
CVE-2018-12896
CVE-2018-13093
CVE-2018-13094
CVE-2018-13095
CVE-2018-14617
CVE-2018-14633
CVE-2018-14633
CVE-2018-14678
CVE-2018-15572
CVE-2018-15594
CVE-2018-16276
CVE-2018-16412
CVE-2018-16413
CVE-2018-16428
CVE-2018-16429
CVE-2018-16644
CVE-2018-16658
CVE-2018-17182
CVE-2018-20467
CVE-2018-20856
CVE-2018-5390
CVE-2018-5390
CVE-2018-5732
CVE-2018-5733
CVE-2018-5741
CVE-2018-6554
CVE-2018-6555
CVE-2018-7480
CVE-2018-7740
CVE-2018-7757
CVE-2018-8043
CVE-2018-8781
CVE-2018-8822
CVE-2018-8897
CVE-2018-9363
CVE-2019-10220
CVE-2019-10650
CVE-2019-11007
CVE-2019-11008
CVE-2019-11009
CVE-2019-11135
CVE-2019-11139
CVE-2019-12450
CVE-2019-13272
CVE-2019-18348
CVE-2019-6974
CVE-2019-7175
CVE-2019-7221
CVE-2019-7395
CVE-2019-7397
CVE-2019-7398
CVE-2019-9213
CVE-2019-9674
CVE-2019-9956
CVE-2020-8492
CVE-2020-8616
CVE-2020-8617
CVE-2021-29980
CVE-2021-29981
CVE-2021-29982
CVE-2021-29983
CVE-2021-29984
CVE-2021-29985
CVE-2021-29986
CVE-2021-29987
CVE-2021-29988
CVE-2021-29989
CVE-2021-29990
CVE-2021-29991
CVE-2021-38492
CVE-2021-38495
SUSE-SU-2018:0466-1
SUSE-SU-2018:0812-1
SUSE-SU-2018:1173-1
SUSE-SU-2018:3084-1
SUSE-SU-2018:3470-1
SUSE-SU-2019:1722-1
SUSE-SU-2019:2959-1
SUSE-SU-2020:0854-1
SUSE-SU-2020:1914-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • libidn2-0-2.0.4-lp150.1 is installed
  • OR libidn2-0-32bit-2.0.4-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND openfortivpn-1.12.0-lp151.2.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • dovecot22-2.2.31-19.5 is installed
  • OR dovecot22-backend-mysql-2.2.31-19.5 is installed
  • OR dovecot22-backend-pgsql-2.2.31-19.5 is installed
  • OR dovecot22-backend-sqlite-2.2.31-19.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND ucode-intel-20191112-13.53 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.108 is installed
  • OR ImageMagick-config-6-SUSE-6.8.8.1-71.108 is installed
  • OR ImageMagick-config-6-upstream-6.8.8.1-71.108 is installed
  • OR libMagickCore-6_Q16-1-6.8.8.1-71.108 is installed
  • OR libMagickWand-6_Q16-1-6.8.8.1-71.108 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kernel-default-4.4.121-92.95 is installed
  • OR kernel-default-base-4.4.121-92.95 is installed
  • OR kernel-default-devel-4.4.121-92.95 is installed
  • OR kernel-default-man-4.4.121-92.95 is installed
  • OR kernel-devel-4.4.121-92.95 is installed
  • OR kernel-macros-4.4.121-92.95 is installed
  • OR kernel-source-4.4.121-92.95 is installed
  • OR kernel-syms-4.4.121-92.95 is installed
  • OR kgraft-patch-4_4_121-92_95-default-1-3.4 is installed
  • OR kgraft-patch-SLE12-SP2_Update_25-1-3.4 is installed
  • OR lttng-modules-2.7.1-9.6 is installed
  • OR lttng-modules-kmp-default-2.7.1_k4.4.121_92.95-9.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • gpgme-1.5.1-1 is installed
  • OR libgpgme11-1.5.1-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND ucode-intel-20190618-13.47 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.24.4-2.47 is installed
  • OR libwebkit2gtk-4_0-37-2.24.4-2.47 is installed
  • OR libwebkit2gtk3-lang-2.24.4-2.47 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.24.4-2.47 is installed
  • OR typelib-1_0-WebKit2-4_0-2.24.4-2.47 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.24.4-2.47 is installed
  • OR webkit2gtk3-2.24.4-2.47 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • bzip2-1.0.6-30.8 is installed
  • OR bzip2-doc-1.0.6-30.8 is installed
  • OR libbz2-1-1.0.6-30.8 is installed
  • OR libbz2-1-32bit-1.0.6-30.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • MozillaFirefox-91.1.0-112.71.1 is installed
  • OR MozillaFirefox-branding-SLE-91-35.6.6 is installed
  • OR MozillaFirefox-devel-91.1.0-112.71.1 is installed
  • OR MozillaFirefox-translations-common-91.1.0-112.71.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • cpp48-4.8.5-31.17 is installed
  • OR gcc48-4.8.5-31.17 is installed
  • OR gcc48-32bit-4.8.5-31.17 is installed
  • OR gcc48-c++-4.8.5-31.17 is installed
  • OR gcc48-info-4.8.5-31.17 is installed
  • OR gcc48-locale-4.8.5-31.17 is installed
  • OR libasan0-4.8.5-31.17 is installed
  • OR libasan0-32bit-4.8.5-31.17 is installed
  • OR libstdc++48-devel-4.8.5-31.17 is installed
  • OR libstdc++48-devel-32bit-4.8.5-31.17 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • MozillaFirefox-68.2.0-109.95 is installed
  • OR MozillaFirefox-translations-common-68.2.0-109.95 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND Package Information
  • grub2-2.02-12.31 is installed
  • OR grub2-i386-pc-2.02-12.31 is installed
  • OR grub2-snapper-plugin-2.02-12.31 is installed
  • OR grub2-systemd-sleep-plugin-2.02-12.31 is installed
  • OR grub2-x86_64-efi-2.02-12.31 is installed
  • OR grub2-x86_64-xen-2.02-12.31 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • curl-7.37.0-37.47 is installed
  • OR libcurl4-7.37.0-37.47 is installed
  • OR libcurl4-32bit-7.37.0-37.47 is installed
  • BACK