Oval Definition:
oval:org.opensuse.security:def:70026
Revision Date
:
2022-01-14
Version
:
1
Title
:
Security update for MozillaFirefox (Important) (in QA)
Description
:
This update for MozillaFirefox fixes the following issues:
- CVE-2021-4140: Fixed iframe sandbox bypass with XSLT (bsc#1194547). - CVE-2022-22737: Fixed race condition when playing audio files (bsc#1194547). - CVE-2022-22738: Fixed heap-buffer-overflow in blendGaussianBlur (bsc#1194547). - CVE-2022-22739: Fixed missing throttling on external protocol launch dialog (bsc#1194547). - CVE-2022-22740: Fixed use-after-free of ChannelEventQueue::mOwner (bsc#1194547). - CVE-2022-22741: Fixed browser window spoof using fullscreen mode (bsc#1194547). - CVE-2022-22742: Fixed out-of-bounds memory access when inserting text in edit mode (bsc#1194547). - CVE-2022-22743: Fixed browser window spoof using fullscreen mode (bsc#1194547). - CVE-2022-22744: Fixed possible command injection via the 'Copy as curl' feature in DevTools (bsc#1194547). - CVE-2022-22745: Fixed leaking cross-origin URLs through securitypolicyviolation event (bsc#1194547). - CVE-2022-22746: Fixed calling into reportValidity could have lead to fullscreen window spoof (bsc#1194547). - CVE-2022-22747: Fixed crash when handling empty pkcs7 sequence(bsc#1194547). - CVE-2022-22748: Fixed spoofed origin on external protocol launch dialog (bsc#1194547). - CVE-2022-22751: Fixed memory safety bugs (bsc#1194547).
This patch is currently in QA and not yet available for download.
Family
:
unix
Class
:
patch
Status
:
Reference(s)
:
1194547
CVE-2016-1238
CVE-2016-9962
CVE-2018-16873
CVE-2018-16874
CVE-2018-16875
CVE-2019-16884
CVE-2019-19921
CVE-2019-5736
CVE-2021-4140
CVE-2022-22737
CVE-2022-22738
CVE-2022-22739
CVE-2022-22740
CVE-2022-22741
CVE-2022-22742
CVE-2022-22743
CVE-2022-22744
CVE-2022-22745
CVE-2022-22746
CVE-2022-22747
CVE-2022-22748
CVE-2022-22751
Platform(s)
:
SUSE Linux Enterprise Module for Containers 15 SP2
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Server 15 SP2-BCL
Product(s)
:
Definition Synopsis
SUSE Linux Enterprise Module for Containers 15 SP2 is installed
AND
Package Information
docker-runc-1.0.0rc8+gitr3917_3e425f80a8c9-6.35 is installed
OR
runc-1.0.0~rc10-1.9 is installed
Definition Synopsis
SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
AND
perl-MIME-Charset-1.012.2-1 is installed
Definition Synopsis
SUSE Linux Enterprise Server 15 SP2-BCL is installed
AND
Package Information
MozillaFirefox-91.5.0-152.12.1 is installed
OR
MozillaFirefox-devel-91.5.0-152.12.1 is installed
OR
MozillaFirefox-translations-common-91.5.0-152.12.1 is installed
OR
MozillaFirefox-translations-other-91.5.0-152.12.1 is installed
BACK