An update that fixes 6 vulnerabilities is now available. . openSUSE Security Update: Security update for opera ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10130-1 Rating: important References: Cross-References: CVE-2022-3196 CVE-2022-3197 CVE-2022-3198 CVE-2022-3199 CVE-2022-3200 CVE-2022-3201 Affected Products: openSUSE Leap 15.3:NonFree ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for opera fixes the following issues: Update to 91.0.4516.20 - CHR-9019 Update chromium on desktop-stable-105-4516 to 105.0.5195.127 - DNA-101312 Allow changing logged in user with BrowserAPI - The update to chromium 105.0.5195.127 fixes following issues: CVE-2022-3196, CVE-2022-3197, CVE-2022-3198, CVE-2022-3199, CVE-2022-3200, CVE-2022-3201 Update to 91.0.4516.16 - CHR-9010 Update chromium on desktop-stable-105-4516 to 105.0.5195.102 - DNA-101447 Incorrect translation in Russian - DNA-101482 Crash at ProfileKey::GetProtoDatabaseProvider() - DNA-101495 Performance Stint 2022 - DNA-101551 Add version number info to browser API - DNA-101662 Suppress 'Allowing special test code paths' warning on buildbot - DNA-101753 News don't show after close browser - DNA-101760 Translations for O91 - DNA-101799 Crash at opera::SuggestionList::SortAndCull - DNA-101812 Sponsored site gets chosen as default entry when typing part of top-level domain - DNA-101876 Promote 91 to stable - Complete Opera 91.0 changelog at: https://blogs.opera.com/desktop/changelog-for-91/ Update to 90.0.4480.107 - DNA-100664 Shopping corner widget - DNA-101495 Performance Stint 2022 - DNA-101753 News don???t show after close browser - DNA-101799 Crash atopera::SuggestionList::SortAndCull Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3:NonFree: zypper in -t patch openSUSE-2022-10130=1 Package List: - openSUSE Leap 15.3:NonFree (x86_64): opera-91.0.4516.20-lp153.2.63.1 References: https://www.suse.com/security/cve/CVE-2022-3196.html https://www.suse.com/security/cve/CVE-2022-3197.html https://www.suse.com/security/cve/CVE-2022-3198.html https://www.suse.com/security/cve/CVE-2022-3199.html https://www.suse.com/security/cve/CVE-2022-3200.html https://www.suse.com/security/cve/CVE-2022-3201.html . Addresses various vulnerabilities in Opera through a significant update for openSUSE. Discover further information regarding the patch specifics.. openSUSE Update, Opera Security Fix, Browser Update. . Severity: Important. LinuxSecurity.com Team
Updated thunderbird packages fix security vulnerabilities: The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame (CVE-2021-38503). . MGASA-2021-0506 - Updated thunderbird packages fix security vulnerabilities Publication date: 10 Nov 2021 URL: https://advisories.mageia.org/MGASA-2021-0506.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-XXXX Updated thunderbird packages fix security vulnerabilities: The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame (CVE-2021-38503). When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash (CVE-2021-38504). Through a series of navigations, Thunderbird could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing (CVE-2021-38506). The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port on the same IP address (e.g. port 8443) did not opt-in to opportunistic encryption; a network attacker could forward a connection from the browser to port 443 to port 8443, causing the browser to treat the content of port 8443 as same-origin with HTTP. This was resolved by disabling the Opportunistic Encryption feature, which had low usage (CVE-2021-38507). A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash (MOZ-2021-0008). By displaying a form validity message in the correctlocation at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission (CVE-2021-38508). Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing (CVE-2021-38509). Mozilla developers and community members Christian Holler, Valentin Gosu, and Andrew McCreight reported memory safety bugs present in Thunderbird 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (MOZ-2021-0007). References: - https://bugs.mageia.org/show_bug.cgi?id=29625 - https://www.mozilla.org/en-US/security/advisories/mfsa2021-50/ - https://www.thunderbird.net/en-US/thunderbird/91.3.0/releasenotes/ - https://www.cve.org/CVERecord?id=CVE-2021-XXXX SRPMS: - 8/core/thunderbird-91.3.0-1.mga8 - 8/core/thunderbird-l10n-91.3.0-1.mga8 . Revised Firefox distributions tackle critical vulnerabilities like memory leaks, confinement failures, and web impersonation threats.. Thunderbird Security,Mageia Updates,Iframe Threats,Memory Corruption Fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.