An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2022:0511-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:0511 Issue date: 2022-02-14 CVE Names: CVE-2022-22754 CVE-2022-22756 CVE-2022-22759 CVE-2022-22760 CVE-2022-22761 CVE-2022-22763 CVE-2022-22764 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.4) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 91.6.0 ESR. Security Fix(es): * Mozilla: Extensions could have bypassed permission confirmation during update (CVE-2022-22754) * Mozilla: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6 (CVE-2022-22764) * Mozilla: Drag and dropping an image could have resulted in the dropped object being an executable (CVE-2022-22756) * Mozilla: Sandboxed iframes could have executed script if the parent appended elements (CVE-2022-22759) * Mozilla: Cross-Origin responses could be distinguishedbetween script and non-script content-types (CVE-2022-22760) * Mozilla: frame-ancestors Content Security Policy directive was not enforced for framed extension pages (CVE-2022-22761) * Mozilla: Script Execution during invalid object state (CVE-2022-22763) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2053236 - CVE-2022-22754 Mozilla: Extensions could have bypassed permission confirmation during update 2053237 - CVE-2022-22756 Mozilla: Drag and dropping an image could have resulted in the dropped object being an executable 2053238 - CVE-2022-22760 Mozilla: Cross-Origin responses could be distinguished between script and non-script content-types 2053239 - CVE-2022-22761 Mozilla: frame-ancestors Content Security Policy directive was not enforced for framed extension pages 2053240 - CVE-2022-22763 Mozilla: Script Execution during invalid object state 2053242 - CVE-2022-22759 Mozilla: Sandboxed iframes could have executed script if the parent appended elements 2053243 - CVE-2022-22764 Mozilla: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.4): Source: firefox-91.6.0-1.el8_4.src.rpm aarch64: firefox-91.6.0-1.el8_4.aarch64.rpm firefox-debuginfo-91.6.0-1.el8_4.aarch64.rpm firefox-debugsource-91.6.0-1.el8_4.aarch64.rpm ppc64le: firefox-91.6.0-1.el8_4.ppc64le.rpm firefox-debuginfo-91.6.0-1.el8_4.ppc64le.rpm firefox-debugsource-91.6.0-1.el8_4.ppc64le.rpm s390x: firefox-91.6.0-1.el8_4.s390x.rpm firefox-debuginfo-91.6.0-1.el8_4.s390x.rpm firefox-debugsource-91.6.0-1.el8_4.s390x.rpm x86_64: firefox-91.6.0-1.el8_4.x86_64.rpm firefox-debuginfo-91.6.0-1.el8_4.x86_64.rpm firefox-debugsource-91.6.0-1.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-22754 https://access.redhat.com/security/cve/CVE-2022-22756 https://access.redhat.com/security/cve/CVE-2022-22759 https://access.redhat.com/security/cve/CVE-2022-22760 https://access.redhat.com/security/cve/CVE-2022-22761 https://access.redhat.com/security/cve/CVE-2022-22763 https://access.redhat.com/security/cve/CVE-2022-22764 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYgorMNzjgjWX9erEAQjp3w/+KmqtOpeRJ/rvfJhfAIaNXGeA92dYMd1A J81TJ83Y4xVq3Er+1wXG9ONXc/f73iuIA+6wrW410FJiFEgt6vYh0QBApfbW8fKN P7p65J2xAG4WQPsGPhYQ/LRP5F9tzq97qSQY1BWPSu0kdh36PBPxas/C4Cyc7zWS Cwa6rg4ZKuw2Pvo63Ti88mBdxotmeBlDqlLn72F8DZ9PnuE1W2rp29Ehu+nKf6f6 3YB4vebjPDLeP++CyYWy0L2dzm7vQNpNj6n56f+RDDdnPv2dCp+5gUpyolA5uBgQ QhL04WrY4bIV4PVBGCEfRewxA8jn2JdYoAortPcJU01Mkoze6IIp7K2pNB/jwcfA T2nIG0c0NM3f/80l67cPxw8z8A2c7+MU+4EZqJc7SQhXsIsoSGBd3KV99C8mauH4 gzqLOdQj9fbCyYPdvHLvM0WXsonVf09LRXj0m5f0I01JEXP21ItsrdyC3LWZ5Ssp ufWuT1h7nJZpi4TkoQ4Mc8Ep1W/lLftPpIEuuzL8Q3Fm26+LiRL4sOrBrNyzx0rm nUtqLpWdU0YQsQ0IQdAK1PAc6C/VqN4VRwEtu6v81AqG0Q23DEj8kR6M2KcXo2v/ Y9lFu/ctW+0KF1h111FW4HlProqKwUWO3DfBJPXDWbSpvvAspYZO+rgXZKKyBNn7 Uf3Y7LigTck=PV71 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for firefox is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2017:0459-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2017:0459.html Issue date: 2017-03-08 CVE Names: CVE-2017-5398 CVE-2017-5400 CVE-2017-5401 CVE-2017-5402 CVE-2017-5404 CVE-2017-5405 CVE-2017-5407 CVE-2017-5408 CVE-2017-5410 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - x86_64 3. Description: Mozilla Firefox is an open source web browser. This update upgrades Firefox to version 45.8.0 ESR. Security Fix(es): * Multiple flawswere found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2017-5398, CVE-2017-5400, CVE-2017-5401, CVE-2017-5402, CVE-2017-5404, CVE-2017-5407, CVE-2017-5408, CVE-2017-5410, CVE-2017-5405) Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Nils, Jerri Rice, Rh0, Anton Eliasson, David Kohlbrenner, Ivan Fratric of Google Project Zero, Anonymous, Eric Lawrence of Chrome Security, Boris Zbarsky, Christian Holler, Honza Bambas, Jon Coppeard, Randell Jesup, André Bargull, Kan-Ru Chen, and Nathan Froyd as the original reporters. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1429778 - CVE-2017-5400 Mozilla: asm.js JIT-spray bypass of ASLR and DEP (MFSA 2017-06) 1429779 - CVE-2017-5401 Mozilla: Memory Corruption when handling ErrorResult (MFSA 2017-06) 1429780 - CVE-2017-5402 Mozilla: Use-after-free working with events in FontFace objects (MFSA 2017-06) 1429781 - CVE-2017-5404 Mozilla: Use-after-free working with ranges in selections (MFSA 2017-06) 1429782 - CVE-2017-5407 Mozilla: Pixel and history stealing via floating-point timing side channel with SVG filters (MFSA 2017-06) 1429783 - CVE-2017-5410 Mozilla: Memory corruption during JavaScript garbage collection incremental sweeping (MFSA 2017-06) 1429784 - CVE-2017-5408 Mozilla: Cross-origin reading of video captions in violation of CORS (MFSA 2017-06) 1429785 - CVE-2017-5405 Mozilla: FTP response codes can cause use of uninitialized values for ports (MFSA 2017-06) 1429786 - CVE-2017-5398 Mozilla: Memory safety bugs fixed in Firefox 52 and Firefox ESR 45.8 (MFSA 2017-06) 6. Package List: Red Hat Enterprise LinuxDesktop (v. 5 client): Source: firefox-45.8.0-2.el5_11.src.rpm i386: firefox-45.8.0-2.el5_11.i386.rpm firefox-debuginfo-45.8.0-2.el5_11.i386.rpm x86_64: firefox-45.8.0-2.el5_11.i386.rpm firefox-45.8.0-2.el5_11.x86_64.rpm firefox-debuginfo-45.8.0-2.el5_11.i386.rpm firefox-debuginfo-45.8.0-2.el5_11.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: firefox-45.8.0-2.el5_11.src.rpm i386: firefox-45.8.0-2.el5_11.i386.rpm firefox-debuginfo-45.8.0-2.el5_11.i386.rpm ppc: firefox-45.8.0-2.el5_11.ppc64.rpm firefox-debuginfo-45.8.0-2.el5_11.ppc64.rpm s390x: firefox-45.8.0-2.el5_11.s390.rpm firefox-45.8.0-2.el5_11.s390x.rpm firefox-debuginfo-45.8.0-2.el5_11.s390.rpm firefox-debuginfo-45.8.0-2.el5_11.s390x.rpm x86_64: firefox-45.8.0-2.el5_11.i386.rpm firefox-45.8.0-2.el5_11.x86_64.rpm firefox-debuginfo-45.8.0-2.el5_11.i386.rpm firefox-debuginfo-45.8.0-2.el5_11.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: firefox-45.8.0-2.el6_8.src.rpm i386: firefox-45.8.0-2.el6_8.i686.rpm firefox-debuginfo-45.8.0-2.el6_8.i686.rpm x86_64: firefox-45.8.0-2.el6_8.x86_64.rpm firefox-debuginfo-45.8.0-2.el6_8.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): x86_64: firefox-45.8.0-2.el6_8.i686.rpm firefox-debuginfo-45.8.0-2.el6_8.i686.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: firefox-45.8.0-2.el6_8.src.rpm x86_64: firefox-45.8.0-2.el6_8.i686.rpm firefox-45.8.0-2.el6_8.x86_64.rpm firefox-debuginfo-45.8.0-2.el6_8.i686.rpm firefox-debuginfo-45.8.0-2.el6_8.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: firefox-45.8.0-2.el6_8.src.rpm i386: firefox-45.8.0-2.el6_8.i686.rpm firefox-debuginfo-45.8.0-2.el6_8.i686.rpm ppc64: firefox-45.8.0-2.el6_8.ppc64.rpm firefox-debuginfo-45.8.0-2.el6_8.ppc64.rpm s390x: firefox-45.8.0-2.el6_8.s390x.rpm firefox-debuginfo-45.8.0-2.el6_8.s390x.rpm x86_64: firefox-45.8.0-2.el6_8.x86_64.rpm firefox-debuginfo-45.8.0-2.el6_8.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): ppc64: firefox-45.8.0-2.el6_8.ppc.rpm firefox-debuginfo-45.8.0-2.el6_8.ppc.rpm s390x: firefox-45.8.0-2.el6_8.s390.rpm firefox-debuginfo-45.8.0-2.el6_8.s390.rpm x86_64: firefox-45.8.0-2.el6_8.i686.rpm firefox-debuginfo-45.8.0-2.el6_8.i686.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: firefox-45.8.0-2.el6_8.src.rpm i386: firefox-45.8.0-2.el6_8.i686.rpm firefox-debuginfo-45.8.0-2.el6_8.i686.rpm x86_64: firefox-45.8.0-2.el6_8.x86_64.rpm firefox-debuginfo-45.8.0-2.el6_8.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): x86_64: firefox-45.8.0-2.el6_8.i686.rpm firefox-debuginfo-45.8.0-2.el6_8.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-5398 https://access.redhat.com/security/cve/CVE-2017-5400 https://access.redhat.com/security/cve/CVE-2017-5401 https://access.redhat.com/security/cve/CVE-2017-5402 https://access.redhat.com/security/cve/CVE-2017-5404 https://access.redhat.com/security/cve/CVE-2017-5405 https://access.redhat.com/security/cve/CVE-2017-5407 https://access.redhat.com/security/cve/CVE-2017-5408 https://access.redhat.com/security/cve/CVE-2017-5410 https://access.redhat.com/security/updates/classification/#critical https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYwDESXlSAg2UNWIIRAnjwAKCdfWTRC98zhFV8g4cN9y2iLmZA1ACfbhez PNgicWgxJKDjkzmbQWkBwY4=9w9S -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.