Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages (CVE-2022-46872). A drag-and-dropped file with a long filename could have had its filename . MGASA-2022-0475 - Updated firefox packages fix security vulnerability Publication date: 17 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0475.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-46872, CVE-2022-46874, CVE-2022-46878, CVE-2022-46880, CVE-2022-46881, CVE-2022-46882 An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages (CVE-2022-46872). A drag-and-dropped file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code (CVE-2022-46874). Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox ESR 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2022-46878). A missing check related to tex units could have led to a use-after-free in WebGL and potentially exploitable crash (CVE-2022-46880). An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash (CVE-2022-46881). A use-after-free in WebGL extensions could have led to a potentially exploitable crash (CVE-2022-46882). References: - https://bugs.mageia.org/show_bug.cgi?id=31272 - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/NqCkaX216zY - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_86.html - https://www.mozilla.org/en-US/security/advisories/mfsa2022-52/ - https://www.cve.org/CVERecord?id=CVE-2022-46872 -https://www.cve.org/CVERecord?id=CVE-2022-46874 - https://www.cve.org/CVERecord?id=CVE-2022-46878 - https://www.cve.org/CVERecord?id=CVE-2022-46880 - https://www.cve.org/CVERecord?id=CVE-2022-46881 - https://www.cve.org/CVERecord?id=CVE-2022-46882 SRPMS: - 8/core/firefox-102.6.0-1.mga8 - 8/core/firefox-l10n-102.6.0-1.mga8 - 8/core/nss-3.86.0-1.mga8 . Mageia 8 Security Notice for Firefox addresses various vulnerabilities and resolutions that affect user safety and system reliability.. Firefox Security,Mageia Advisory,Memory Safety Issues,Sandbox Escape,Malicious Exploits. . Severity: Critical. LinuxSecurity.com Team
. The malware researcher 'kafeine' found an 0day in Flash used by Angler EK malware. CVE-2014-8440 CVE-2015-0310 CVE-2015-0311 Description: Actual Version flash version in archlinux: flashplugin 11.2.202.429-1 Is our version vulnerable too? Have somebody some information about this? According to the information provided by Adobe in [1], I think so. Unfortunately there is not much information available on the issue and no fix available as far as I know, therefore I would recommend completely disabling the flash plugin, which might be a good idea if you care about security anyway. Oh and please don't hijack existing unrelated thread for starting a new topic :) [1]: . Cybersecurity specialist reveals unaddressed vulnerability in Flash impacting ArchLinux users. Users advised to turn off the plugin to enhance security.. 0day Attack, Adobe Flash Issue, ArchLinux Security, Angler EK Malware, Flash Plugin Risk. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.