Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
203

Mageia 8: 2022-0344 Critical Security Advisory for Firefox Exploits

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead (CVE-2022-40956). By injecting a cookie with certain special characters, an attacker on a . MGASA-2022-0344 - Updated firefox packages fix security vulnerabilities Publication date: 21 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0344.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-40956, CVE-2022-40958, CVE-2022-40959, CVE-2022-40960, CVE-2022-40962 When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead (CVE-2022-40956). By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks (CVE-2022-40958). During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments (CVE-2022-40959). Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash (CVE-2022-40960). Mozilla developers Nika Layzell, Timothy Nikkel, Jeff Muizelaar, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox ESR 102.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2022-40962). References: - https://bugs.mageia.org/show_bug.cgi?id=30867 - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/K4hptojx5CQ - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AZdgucrnRTQ - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_83.html - https://www.mozilla.org/en-US/security/advisories/mfsa2022-41/ -https://www.cve.org/CVERecord?id=CVE-2022-40956 - https://www.cve.org/CVERecord?id=CVE-2022-40958 - https://www.cve.org/CVERecord?id=CVE-2022-40959 - https://www.cve.org/CVERecord?id=CVE-2022-40960 - https://www.cve.org/CVERecord?id=CVE-2022-40962 SRPMS: - 8/core/rootcerts-20220907.00-1.mga8 - 8/core/nspr-4.35-1.mga8 - 8/core/nss-3.83.0-1.mga8 - 8/core/firefox-102.3.0-1.mga8 - 8/core/firefox-l10n-102.3.0-1.mga8 . The newest security patch for Firefox on Mageia addresses multiple vulnerabilities, enhancing online safety in the face of rising cyber threats.. Firefox Updates,Mageia Security,CSP Bypass,Memory Safety Issues,Web Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 21, 2022 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here