Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2021:3993-1 Important: MozillaFirefox Critical Update

suse
Calendar Grey December 10, 2021
Dist Suse Esm H88
SUSE has released a vital security patch for MozillaFirefox, rectifying 9 vulnerabilities comprised of memory safety flaws and a buffer overflow issue.
An update that fixes 9 vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: Update to Extended Support Release 91.4.0 (bsc#1193485): - CVE-2021-43536: URL leakage when navigating while executing asynchronous function - CVE-2021-43537: Heap buffer overflow when using structured clone - CVE-2021-43538: Missing fullscreen and pointer lock notification when requesting both - CVE-2021-43539: GC rooting failure when calling wasm instance methods - CVE-2021-43541: External protocol handler parameters were unescaped - CVE-2021-43542: XMLHttpRequest error codes could have leaked the existence of an external protocol handler - CVE-2021-43543: Bypass of CSP sandbox directive when embedding - CVE-2021-43545: Denial of Service when using the Location API in a loop

References

#1193321 #1193485

Cross- CVE-2021-43536 CVE-2021-43537 CVE-2021-43538

CVE-2021-43539 CVE-2021-43541 CVE-2021-43542

CVE-2021-43543 CVE-2021-43545 CVE-2021-43546

CVSS scores:

CVE-2021-43537 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-43541 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVE-2021-43542 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15-SP3

SUSE Linux Enterprise Module for Desktop Applications 15-SP2

https://www.suse.com/security/cve/CVE-2021-43536.html

https://www.suse.com/security/cve/CVE-2021-43537.html

https://www.suse.com/security/cve/CVE-2021-43538.html

https://www.suse.com/security/cve/CVE-2021-43539.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3993-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here