Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:3272-1 Important Security Update For MozillaFirefox

suse
Calendar Grey September 14, 2022
Dist Suse Esm H88
An important security patch for openSUSE focusing on 28 vulnerabilities in Mozilla Firefox to bolster system security.
An update that fixes 28 vulnerabilities is now available

Summary

This update for MozillaFirefox fixes the following issues: Mozilla Firefox was updated to 102.2.0esr ESR: * Fixed: Various stability, functionality, and security fixes. - MFSA 2022-34 (bsc#1202645) * CVE-2022-38472 (bmo#1769155) Address bar spoofing via XSLT error handling * CVE-2022-38473 (bmo#1771685) Cross-origin XSLT Documents would have inherited the parent's permissions * CVE-2022-38476 (bmo#1760998) Data race and potential use-after-free in PK11_ChangePW * CVE-2022-38477 (bmo#1760611, bmo#1770219, bmo#1771159, bmo#1773363) Memory safety bugs fixed in Firefox 104 and Firefox ESR 102.2 * CVE-2022-38478 (bmo#1770630, bmo#1776658) Memory safety bugs fixed in Firefox 104, Firefox ESR 102.2, and Firefox ESR 91.13 Firefox Extended Support Release 102.1 ESR

References

#1200793 #1201758 #1202645

Cross- CVE-2022-2200 CVE-2022-2505 CVE-2022-34468

CVE-2022-34469 CVE-2022-34470 CVE-2022-34471

CVE-2022-34472 CVE-2022-34473 CVE-2022-34474

CVE-2022-34475 CVE-2022-34476 CVE-2022-34477

CVE-2022-34478 CVE-2022-34479 CVE-2022-34480

CVE-2022-34481 CVE-2022-34482 CVE-2022-34483

CVE-2022-34484 CVE-2022-34485 CVE-2022-36314

CVE-2022-36318 CVE-2022-36319 CVE-2022-38472

CVE-2022-38473 CVE-2022-38476 CVE-2022-38477

CVE-2022-38478

CVSS scores:

CVE-2022-2505 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2022-36314 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE-2022-36318 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3272-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here