Oval Definition:oval:org.opensuse.security:def:70017
Revision Date:2022-01-14Version:1
Title:Security update for MozillaFirefox (Important) (in QA)
Description:

This update for MozillaFirefox fixes the following issues:

- CVE-2021-4140: Fixed iframe sandbox bypass with XSLT (bsc#1194547). - CVE-2022-22737: Fixed race condition when playing audio files (bsc#1194547). - CVE-2022-22738: Fixed heap-buffer-overflow in blendGaussianBlur (bsc#1194547). - CVE-2022-22739: Fixed missing throttling on external protocol launch dialog (bsc#1194547). - CVE-2022-22740: Fixed use-after-free of ChannelEventQueue::mOwner (bsc#1194547). - CVE-2022-22741: Fixed browser window spoof using fullscreen mode (bsc#1194547). - CVE-2022-22742: Fixed out-of-bounds memory access when inserting text in edit mode (bsc#1194547). - CVE-2022-22743: Fixed browser window spoof using fullscreen mode (bsc#1194547). - CVE-2022-22744: Fixed possible command injection via the 'Copy as curl' feature in DevTools (bsc#1194547). - CVE-2022-22745: Fixed leaking cross-origin URLs through securitypolicyviolation event (bsc#1194547). - CVE-2022-22746: Fixed calling into reportValidity could have lead to fullscreen window spoof (bsc#1194547). - CVE-2022-22747: Fixed crash when handling empty pkcs7 sequence(bsc#1194547). - CVE-2022-22748: Fixed spoofed origin on external protocol launch dialog (bsc#1194547). - CVE-2022-22751: Fixed memory safety bugs (bsc#1194547).

This patch is currently in QA and not yet available for download.
Family:unixClass:patch
Status:Reference(s):1194547
CVE-2009-2285
CVE-2009-2347
CVE-2010-2065
CVE-2010-2067
CVE-2010-2233
CVE-2010-4665
CVE-2011-0192
CVE-2011-1167
CVE-2012-1173
CVE-2012-2113
CVE-2012-3401
CVE-2012-4564
CVE-2013-1960
CVE-2013-1961
CVE-2013-4231
CVE-2013-4232
CVE-2013-4243
CVE-2013-4244
CVE-2014-8127
CVE-2014-8128
CVE-2014-8129
CVE-2014-8130
CVE-2014-9655
CVE-2015-1547
CVE-2015-7554
CVE-2015-8665
CVE-2015-8683
CVE-2015-8781
CVE-2015-8782
CVE-2015-8783
CVE-2016-10092
CVE-2016-10093
CVE-2016-10094
CVE-2016-10095
CVE-2016-10266
CVE-2016-10267
CVE-2016-10268
CVE-2016-10269
CVE-2016-10270
CVE-2016-10271
CVE-2016-10272
CVE-2016-10371
CVE-2016-1601
CVE-2016-3186
CVE-2016-3622
CVE-2016-3623
CVE-2016-3658
CVE-2016-3945
CVE-2016-3990
CVE-2016-3991
CVE-2016-5314
CVE-2016-5316
CVE-2016-5317
CVE-2016-5318
CVE-2016-5320
CVE-2016-5321
CVE-2016-5323
CVE-2016-5652
CVE-2016-5875
CVE-2016-6223
CVE-2016-9273
CVE-2016-9297
CVE-2016-9448
CVE-2016-9453
CVE-2016-9538
CVE-2017-11613
CVE-2017-12944
CVE-2017-16232
CVE-2017-18013
CVE-2017-5225
CVE-2017-7592
CVE-2017-7593
CVE-2017-7594
CVE-2017-7595
CVE-2017-7596
CVE-2017-7597
CVE-2017-7598
CVE-2017-7599
CVE-2017-7600
CVE-2017-7601
CVE-2017-7602
CVE-2017-9403
CVE-2017-9404
CVE-2017-9935
CVE-2017-9936
CVE-2018-10779
CVE-2018-10963
CVE-2018-12900
CVE-2018-16335
CVE-2018-17000
CVE-2018-17100
CVE-2018-17101
CVE-2018-17795
CVE-2018-18557
CVE-2018-18661
CVE-2018-19210
CVE-2018-5784
CVE-2018-7456
CVE-2018-8905
CVE-2019-6128
CVE-2019-7663
CVE-2021-4140
CVE-2022-22737
CVE-2022-22738
CVE-2022-22739
CVE-2022-22740
CVE-2022-22741
CVE-2022-22742
CVE-2022-22743
CVE-2022-22744
CVE-2022-22745
CVE-2022-22746
CVE-2022-22747
CVE-2022-22748
CVE-2022-22751
Platform(s):SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Server 15 SP1-LTSS
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND yast2-users-4.2.11-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND libtiff5-32bit-4.0.9-5.27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 15 SP1-LTSS is installed
  • AND Package Information
  • MozillaFirefox-91.5.0-150.15.1 is installed
  • OR MozillaFirefox-devel-91.5.0-150.15.1 is installed
  • OR MozillaFirefox-translations-common-91.5.0-150.15.1 is installed
  • OR MozillaFirefox-translations-other-91.5.0-150.15.1 is installed
  • BACK