Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8 MGASA-2022-0093 Critical: Firefox Use-After-Free Issues

mageia
Calendar Grey March 8, 2022
Dist Mageia Esm H88
The recent security patch for Firefox in Mageia tackles several threats identified after 08 March 2022.
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash (CVE-2022-26381)

Summary

An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash (CVE-2022-26381).
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification (CVE-2022-26383).
If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox (CVE-2022-26384).
Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in /tmp, but this behavior was changed to download them to /tmp where they could be affected by other local users. This behavior was reverted to the original, user-specific directory (CVE-2022-26386).
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been mod...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=30134

- https://www.mozilla.org/en-US/security/advisories/mfsa2022-11/

- https://www.cve.org/CVERecord?id=CVE-2022-26381

- https://www.cve.org/CVERecord?id=CVE-2022-26383

- https://www.cve.org/CVERecord?id=CVE-2022-26384

- https://www.cve.org/CVERecord?id=CVE-2022-26386

- https://www.cve.org/CVERecord?id=CVE-2022-26387

Resolution

SRPMS

- 8/core/firefox-91.7.0-1.mga8

- 8/core/firefox-l10n-91.7.0-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 08 Mar 2022
URL: https://advisories.mageia.org/MGASA-2022-0093.html
Type: security
CVE: CVE-2022-26381, CVE-2022-26383, CVE-2022-26384, CVE-2022-26386, CVE-2022-26387

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here