Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2021:14859-1 Important: MozillaFirefox Heap Overflow Risk

suse
Calendar Grey December 10, 2021
Dist Suse Esm H88
The latest release of MozillaFirefox resolves several vulnerabilities, including memory corruption and service disruptions specifically affecting SUSE Linux environments.
An update that fixes 9 vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: Update to Extended Support Release 91.4.0 (bsc#1193485): - CVE-2021-43536: URL leakage when navigating while executing asynchronous function - CVE-2021-43537: Heap buffer overflow when using structured clone - CVE-2021-43538: Missing fullscreen and pointer lock notification when requesting both - CVE-2021-43539: GC rooting failure when calling wasm instance methods - CVE-2021-43541: External protocol handler parameters were unescaped - CVE-2021-43542: XMLHttpRequest error codes could have leaked the existence of an external protocol handler - CVE-2021-43543: Bypass of CSP sandbox directive when embedding - CVE-2021-43545: Denial of Service when using the Location API in a loop

References

#1193321 #1193485

Cross- CVE-2021-43536 CVE-2021-43537 CVE-2021-43538

CVE-2021-43539 CVE-2021-43541 CVE-2021-43542

CVE-2021-43543 CVE-2021-43545 CVE-2021-43546

CVSS scores:

CVE-2021-43537 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-43541 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVE-2021-43542 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected Products:

SUSE Linux Enterprise Server 11-SP4-LTSS

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2021-43536.html

https://www.suse.com/security/cve/CVE-2021-43537.html

https://www.suse.com/security/cve/CVE-2021-43538.html

https://www.suse.com/security/cve/CVE-2021-43539.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:14859-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here