MGASA-2024-0189 - Updated nss & firefox packages fix security vulnerabilities

Publication date: 21 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0189.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-4367,
     CVE-2024-4767,
     CVE-2024-4768,
     CVE-2024-4769,
     CVE-2024-4770,
     CVE-2024-4777

Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367)
IndexedDB files retained in private browsing mode. (CVE-2024-4767)
Potential permissions request bypass via clickjacking. (CVE-2024-4768)
Cross-origin responses could be distinguished between script and
non-script content-types. (CVE-2024-4769)
Use-after-free could occur when printing to PDF. (CVE-2024-4770)
Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and
Thunderbird 115.11. (CVE-2024-4777)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33211
- https://www.mozilla.org/en-US/firefox/115.11.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_100.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4367
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4767
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4768
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4769
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4770
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4777

SRPMS:
- 9/core/nss-3.100.0-1.mga9
- 9/core/firefox-115.11.0-1.mga9
- 9/core/firefox-l10n-115.11.0-1.mga9

Mageia 2024-0189: nss & firefox Security Advisory Updates

Arbitrary JavaScript execution in PDF.js

Summary

Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367) IndexedDB files retained in private browsing mode. (CVE-2024-4767) Potential permissions request bypass via clickjacking. (CVE-2024-4768) Cross-origin responses could be distinguished between script and non-script content-types. (CVE-2024-4769) Use-after-free could occur when printing to PDF. (CVE-2024-4770) Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. (CVE-2024-4777)

References

- https://bugs.mageia.org/show_bug.cgi?id=33211

- https://www.mozilla.org/en-US/firefox/115.11.0/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/

- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_100.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4367

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4767

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4768

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4769

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4770

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4777

Resolution

MGASA-2024-0189 - Updated nss & firefox packages fix security vulnerabilities

SRPMS

- 9/core/nss-3.100.0-1.mga9

- 9/core/firefox-115.11.0-1.mga9

- 9/core/firefox-l10n-115.11.0-1.mga9

Severity
Publication date: 21 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0189.html
Type: security
CVE: CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4777

Related News