An update for firefox is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2022:8580-02 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8580 Issue date: 2022-11-22 CVE Names: CVE-2022-45403 CVE-2022-45404 CVE-2022-45405 CVE-2022-45406 CVE-2022-45408 CVE-2022-45409 CVE-2022-45410 CVE-2022-45411 CVE-2022-45412 CVE-2022-45416 CVE-2022-45418 CVE-2022-45420 CVE-2022-45421 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.5.0 ESR. Security Fix(es): * Mozilla: Service Workers might have learned size of cross-origin media files (CVE-2022-45403) * Mozilla: Fullscreen notification bypass (CVE-2022-45404) * Mozilla: Use-after-free in InputStream implementation (CVE-2022-45405) * Mozilla: Use-after-free of a JavaScript Realm (CVE-2022-45406) * Mozilla: Fullscreennotification bypass via windowName (CVE-2022-45408) * Mozilla: Use-after-free in Garbage Collection (CVE-2022-45409) * Mozilla: Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5 (CVE-2022-45421) * Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy (CVE-2022-45410) * Mozilla: Cross-Site Tracing was possible via non-standard override headers (CVE-2022-45411) * Mozilla: Symlinks may resolve to partially uninitialized buffers(CVE-2022-45412) * Mozilla: Keystroke Side-Channel Leakage (CVE-2022-45416) * Mozilla: Custom mouse cursor could have been drawn over browser UI (CVE-2022-45418) * Mozilla: Iframe contents could be rendered outside the iframe (CVE-2022-45420) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2143197 - CVE-2022-45403 Mozilla: Service Workers might have learned size of cross-origin media files 2143198 - CVE-2022-45404 Mozilla: Fullscreen notification bypass 2143199 - CVE-2022-45405 Mozilla: Use-after-free in InputStream implementation 2143200 - CVE-2022-45406 Mozilla: Use-after-free of a JavaScript Realm 2143201 - CVE-2022-45408 Mozilla: Fullscreen notification bypass via windowName 2143202 - CVE-2022-45409 Mozilla: Use-after-free in Garbage Collection 2143203 - CVE-2022-45410 Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy 2143204 - CVE-2022-45411 Mozilla: Cross-Site Tracing was possible via non-standard override headers2143205 - CVE-2022-45412 Mozilla: Symlinks may resolve to partially uninitialized buffers2143240 - CVE-2022-45416 Mozilla: Keystroke Side-Channel Leakage 2143241 -CVE-2022-45418 Mozilla: Custom mouse cursor could have been drawn over browser UI 2143242 - CVE-2022-45420 Mozilla: Iframe contents could be rendered outside the iframe 2143243 - CVE-2022-45421 Mozilla: Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: firefox-102.5.0-1.el9_1.src.rpm aarch64: firefox-102.5.0-1.el9_1.aarch64.rpm firefox-debuginfo-102.5.0-1.el9_1.aarch64.rpm firefox-debugsource-102.5.0-1.el9_1.aarch64.rpm ppc64le: firefox-102.5.0-1.el9_1.ppc64le.rpm firefox-debuginfo-102.5.0-1.el9_1.ppc64le.rpm firefox-debugsource-102.5.0-1.el9_1.ppc64le.rpm s390x: firefox-102.5.0-1.el9_1.s390x.rpm firefox-debuginfo-102.5.0-1.el9_1.s390x.rpm firefox-debugsource-102.5.0-1.el9_1.s390x.rpm x86_64: firefox-102.5.0-1.el9_1.x86_64.rpm firefox-debuginfo-102.5.0-1.el9_1.x86_64.rpm firefox-debugsource-102.5.0-1.el9_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-45403 https://access.redhat.com/security/cve/CVE-2022-45404 https://access.redhat.com/security/cve/CVE-2022-45405 https://access.redhat.com/security/cve/CVE-2022-45406 https://access.redhat.com/security/cve/CVE-2022-45408 https://access.redhat.com/security/cve/CVE-2022-45409 https://access.redhat.com/security/cve/CVE-2022-45410 https://access.redhat.com/security/cve/CVE-2022-45411 https://access.redhat.com/security/cve/CVE-2022-45412 https://access.redhat.com/security/cve/CVE-2022-45416 https://access.redhat.com/security/cve/CVE-2022-45418 https://access.redhat.com/security/cve/CVE-2022-45420 https://access.redhat.com/security/cve/CVE-2022-45421 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBY30bJNzjgjWX9erEAQjMNg/+LNWOOp0chbfCOhhzud7rJUwhYExagD6i KtRJCOwVZ50PAcqZ3DD9s53GNTOifh5S2jt+I71o7Aw4SM2oZW6xhsQvYAcxQy6s KIbhxwflouzjsQfOPhFoz8NVp8Ky5cY4cESwmvFUEMZIbTlaUZvoD+fDnDT/USVJ 8kmeyeyEHtKhiuV+vzmMIg7bDbmElFj0nSo5T2LxNCuy12M3dYM9CfXAjea+C4lu IgwnNx/AyhUvJgr4DkSNFGzKbKsH0WQ5PAHndftbDIVYnAYzpEwmx1mvYAcP5+C5 dfESQO0VSf90ibIbmHvl5MuUwrN6N9/OC0do6TO2LnnELOqO8OhSa+TYCCVtZ5kc NBDfWUCbdG9w1niuR9XwTLS/agAsc8uD293aPi1mOJd/5nQtHlBvnv9CIjCxB/X1 SnzhwS8TeuBvm4x9ZlQJJL/IAfC+joVX4q4Hc6qVdkuYMvo94n5UkSrcve7JHuSD 66hFa4LJslEG/U79gTQBNYCen9ux6UDQ9VZ9DzP0GfHSAowFMKIj90Jrko2skSuM +exfsYEZ7wVvyyPZnY5/KPn+mgMgkXq8ATsk99meWr+fVLfoabstt1v3vsnz+zgY nthxvl5TCj26uudlbbKHR+26KPXVEbROLa4OQ6LghBbleIuhnSp5+tuDqSG2JxVJ hB/k4b3CqhA=5TAs -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2022:8553-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8553 Issue date: 2022-11-21 CVE Names: CVE-2022-45403 CVE-2022-45404 CVE-2022-45405 CVE-2022-45406 CVE-2022-45408 CVE-2022-45409 CVE-2022-45410 CVE-2022-45411 CVE-2022-45412 CVE-2022-45416 CVE-2022-45418 CVE-2022-45420 CVE-2022-45421 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - ppc64le, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.5.0 ESR. Security Fix(es): * Mozilla: Service Workers might have learned size of cross-origin media files (CVE-2022-45403) * Mozilla: Fullscreen notification bypass (CVE-2022-45404) * Mozilla: Use-after-free in InputStream implementation (CVE-2022-45405) * Mozilla: Use-after-free of a JavaScript Realm (CVE-2022-45406) * Mozilla: Fullscreen notificationbypass via windowName (CVE-2022-45408) * Mozilla: Use-after-free in Garbage Collection (CVE-2022-45409) * Mozilla: Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5 (CVE-2022-45421) * Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy (CVE-2022-45410) * Mozilla: Cross-Site Tracing was possible via non-standard override headers (CVE-2022-45411) * Mozilla: Symlinks may resolve to partially uninitialized buffers(CVE-2022-45412) * Mozilla: Keystroke Side-Channel Leakage (CVE-2022-45416) * Mozilla: Custom mouse cursor could have been drawn over browser UI (CVE-2022-45418) * Mozilla: Iframe contents could be rendered outside the iframe (CVE-2022-45420) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2143197 - CVE-2022-45403 Mozilla: Service Workers might have learned size of cross-origin media files 2143198 - CVE-2022-45404 Mozilla: Fullscreen notification bypass 2143199 - CVE-2022-45405 Mozilla: Use-after-free in InputStream implementation 2143200 - CVE-2022-45406 Mozilla: Use-after-free of a JavaScript Realm 2143201 - CVE-2022-45408 Mozilla: Fullscreen notification bypass via windowName 2143202 - CVE-2022-45409 Mozilla: Use-after-free in Garbage Collection 2143203 - CVE-2022-45410 Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy 2143204 - CVE-2022-45411 Mozilla: Cross-Site Tracing was possible via non-standard override headers2143205 - CVE-2022-45412 Mozilla: Symlinks may resolve to partially uninitialized buffers2143240 - CVE-2022-45416 Mozilla: Keystroke Side-Channel Leakage 2143241 - CVE-2022-45418 Mozilla:Custom mouse cursor could have been drawn over browser UI 2143242 - CVE-2022-45420 Mozilla: Iframe contents could be rendered outside the iframe 2143243 - CVE-2022-45421 Mozilla: Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.1): Source: firefox-102.5.0-1.el8_1.src.rpm ppc64le: firefox-102.5.0-1.el8_1.ppc64le.rpm firefox-debuginfo-102.5.0-1.el8_1.ppc64le.rpm firefox-debugsource-102.5.0-1.el8_1.ppc64le.rpm x86_64: firefox-102.5.0-1.el8_1.x86_64.rpm firefox-debuginfo-102.5.0-1.el8_1.x86_64.rpm firefox-debugsource-102.5.0-1.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-45403 https://access.redhat.com/security/cve/CVE-2022-45404 https://access.redhat.com/security/cve/CVE-2022-45405 https://access.redhat.com/security/cve/CVE-2022-45406 https://access.redhat.com/security/cve/CVE-2022-45408 https://access.redhat.com/security/cve/CVE-2022-45409 https://access.redhat.com/security/cve/CVE-2022-45410 https://access.redhat.com/security/cve/CVE-2022-45411 https://access.redhat.com/security/cve/CVE-2022-45412 https://access.redhat.com/security/cve/CVE-2022-45416 https://access.redhat.com/security/cve/CVE-2022-45418 https://access.redhat.com/security/cve/CVE-2022-45420 https://access.redhat.com/security/cve/CVE-2022-45421 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY3vJrtzjgjWX9erEAQgm4w/7BiWsAX8FsWUc7kDNOtAdiNs3tmgmrJKS bIiM/nuALBnphSokhKgTx3Mmk5FqSGpzVihv6AlZKXrgI5Xpf6UA4xfohTm+vTRs VbX6fO6puLontD4jY2Bj2XM6rxONbVqbjqo+RT1hEVAaaj9VQdY7GQbG55Dqv3/w OlTARORqICSyVVYPpacFRbtM2KkuWOhG3iVqDnTJuZbg29fcTtQu9bStMQGcxad/ vxYSqoAXyDARKlHozyc1w6mT9sw/7mh4kZyWWrKwuyB6QXUeMt8gBxA1B82mT/i5 kZkzU8EwjH3mTBgnqhgLHf6yLMUVE72jcxRCqvtRNoye9X6DKKFWzpnDlNwdvbTk nmgYF7FLAvNEncqpo/uUIgF2yOE/de5isaZS5oj7hwOLBDXaC47Di/DnrEIOXqw6 5roe4Tue3mKbUtwHO/ofzQ0jM7uBA8B24ItmVJz3HlxDSF33Iz5n6YPl3omqzqTS OluSiyH2CjYrhy9yJV6id9rKP1cDlET+D6mbBArhNiAESKn3/jqFxLE1S65Joiae azsUxWowNkAS1okjK/LnTCjUkPJcJ5r4KLJjXgBxaJpzaqJ3IUbBIyIU2NqyGX9P 9BCFfZ08N1BXMOSgXeS7hJiVrZgrEhB9FovkB4Dx2Os7IXB+5GgVctPaVDCW/2YJ pGMGZbNrc3I=YIHI -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Service Workers might have learned size of cross-origin media files. (CVE-2022-45403) Fullscreen notification bypass. (CVE-2022-45404) . MGASA-2022-0428 - Updated thunderbird packages fix security vulnerability Publication date: 17 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0428.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-45403, CVE-2022-45404, CVE-2022-45405, CVE-2022-45406, CVE-2022-45408, CVE-2022-45409, CVE-2022-45410, CVE-2022-45411, CVE-2022-45412, CVE-2022-45416, CVE-2022-45418, CVE-2022-45420, CVE-2022-45421 Service Workers might have learned size of cross-origin media files. (CVE-2022-45403) Fullscreen notification bypass. (CVE-2022-45404) Use-after-free in InputStream implementation. (CVE-2022-45405) Use-after-free of a JavaScript Realm. (CVE-2022-45406) Fullscreen notification bypass via windowName. (CVE-2022-45408) Use-after-free in Garbage Collection. (CVE-2022-45409) ServiceWorker-intercepted requests bypassed SameSite cookie policy. (CVE-2022-45410) Cross-Site Tracing was possible via non-standard override headers. (CVE-2022-45411) Symlinks may resolve to partially uninitialized buffers. (CVE-2022-45412) Keystroke Side-Channel Leakage. (CVE-2022-45416) Custom mouse cursor could have been drawn over browser UI. (CVE-2022-45418) Iframe contents could be rendered outside the iframe. (CVE-2022-45420) Memory safety bugs fixed in Thunderbird 102.5. (CVE-2022-45421) References: - https://bugs.mageia.org/show_bug.cgi?id=31131 - https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2022-49/ - https://www.cve.org/CVERecord?id=CVE-2022-45403 - https://www.cve.org/CVERecord?id=CVE-2022-45404 - https://www.cve.org/CVERecord?id=CVE-2022-45405 - https://www.cve.org/CVERecord?id=CVE-2022-45406 - https://www.cve.org/CVERecord?id=CVE-2022-45408 - https://www.cve.org/CVERecord?id=CVE-2022-45409 -https://www.cve.org/CVERecord?id=CVE-2022-45410 - https://www.cve.org/CVERecord?id=CVE-2022-45411 - https://www.cve.org/CVERecord?id=CVE-2022-45412 - https://www.cve.org/CVERecord?id=CVE-2022-45416 - https://www.cve.org/CVERecord?id=CVE-2022-45418 - https://www.cve.org/CVERecord?id=CVE-2022-45420 - https://www.cve.org/CVERecord?id=CVE-2022-45421 SRPMS: - 8/core/thunderbird-102.5.0-1.mga8 - 8/core/thunderbird-l10n-102.5.0-1.mga8 . Mageia has issued new advisory updates to address severe security flaws in Thunderbird. Delve into the specifics.. Mageia Security Advisory, Thunderbird Security Update, Cross-Origin Issues. . LinuxSecurity.com Team
An update that fixes 6 vulnerabilities is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1731-1 Rating: important References: #1198970 Cross-References: CVE-2022-29909 CVE-2022-29911 CVE-2022-29912 CVE-2022-29914 CVE-2022-29916 CVE-2022-29917 CVSS scores: CVE-2022-29909 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29911 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29912 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2022-29914 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29916 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29917 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server for SAP 15-SP1 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: Firefox Extended Support Release 91.9.0 ESR (MFSA 2022-17)(bsc#1198970): -CVE-2022-29914: Fullscreen notification bypass using popups - CVE-2022-29909: Bypassing permission prompt in nested browsing contexts - CVE-2022-29916: Leaking browser history with CSS variables - CVE-2022-29911: iframe Sandbox bypass - CVE-2022-29912: Reader mode bypassed SameSite cookies - CVE-2022-29917: Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-1731=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2022-1731=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-1731=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-1731=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2022-1731=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-1731=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-1731=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-1731=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-1731=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-1731=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlledway. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise HighPerformance Computing 15-SP1-LTSS (aarch64 x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE Enterprise Storage 6 (aarch64 x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 - SUSE CaaS Platform 4.0(x86_64): MozillaFirefox-91.9.0-150000.150.38.3 MozillaFirefox-debuginfo-91.9.0-150000.150.38.3 MozillaFirefox-debugsource-91.9.0-150000.150.38.3 MozillaFirefox-devel-91.9.0-150000.150.38.3 MozillaFirefox-translations-common-91.9.0-150000.150.38.3 MozillaFirefox-translations-other-91.9.0-150000.150.38.3 References: https://www.suse.com/security/cve/CVE-2022-29909.html https://www.suse.com/security/cve/CVE-2022-29911.html https://www.suse.com/security/cve/CVE-2022-29912.html https://www.suse.com/security/cve/CVE-2022-29914.html https://www.suse.com/security/cve/CVE-2022-29916.html https://www.suse.com/security/cve/CVE-2022-29917.html https://bugzilla.suse.com/1198970 . SUSE security patch: critical update for Firefox resolving several vulnerabilities. Discover the best practices for secure updates.. MozillaFirefox Security Update, SUSE Important Update, Memory Safety Issues. . Severity: Important. LinuxSecurity.com Team
An update that fixes 8 vulnerabilities is now available. . SUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1719-1 Rating: important References: #1198970 Cross-References: CVE-2022-1520 CVE-2022-29909 CVE-2022-29911 CVE-2022-29912 CVE-2022-29913 CVE-2022-29914 CVE-2022-29916 CVE-2022-29917 CVSS scores: CVE-2022-1520 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVE-2022-29909 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29911 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29912 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2022-29913 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2022-29914 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29916 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-29917 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Workstation Extension 15-SP3 SUSELinux Enterprise Workstation Extension 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: Various security fixes MFSA 2022-18 (bsc#1198970): - CVE-2022-1520: Incorrect security status shown after viewing an attached email (bmo#1745019). - CVE-2022-29914: Fullscreen notification bypass using popups (bmo#1746448). - CVE-2022-29909: Bypassing permission prompt in nested browsing contexts (bmo#1755081). - CVE-2022-29916: Leaking browser history with CSS variables (bmo#1760674). - CVE-2022-29911: iframe sandbox bypass (bmo#1761981). - CVE-2022-29912: Reader mode bypassed SameSite cookies (bmo#1692655). - CVE-2022-29913: Speech Synthesis feature not properly disabled (bmo#1764778). - CVE-2022-29917: Memory safety bugs fixed in Thunderbird 91.9 (bmo#1684739, bmo#1706441, bmo#1753298, bmo#1762614, bmo#1762620). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1719=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1719=1 - SUSE Linux Enterprise Workstation Extension 15-SP4: zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2022-1719=1 - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2022-1719=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2022-1719=1 - SUSE Linux Enterprise Module for PackagehubSubpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-1719=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): MozillaThunderbird-91.9.0-150200.8.68.2 MozillaThunderbird-debuginfo-91.9.0-150200.8.68.2 MozillaThunderbird-debugsource-91.9.0-150200.8.68.2 MozillaThunderbird-translations-common-91.9.0-150200.8.68.2 MozillaThunderbird-translations-other-91.9.0-150200.8.68.2 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): MozillaThunderbird-91.9.0-150200.8.68.2 MozillaThunderbird-debuginfo-91.9.0-150200.8.68.2 MozillaThunderbird-debugsource-91.9.0-150200.8.68.2 MozillaThunderbird-translations-common-91.9.0-150200.8.68.2 MozillaThunderbird-translations-other-91.9.0-150200.8.68.2 - SUSE Linux Enterprise Workstation Extension 15-SP4 (x86_64): MozillaThunderbird-91.9.0-150200.8.68.2 MozillaThunderbird-debuginfo-91.9.0-150200.8.68.2 MozillaThunderbird-debugsource-91.9.0-150200.8.68.2 MozillaThunderbird-translations-common-91.9.0-150200.8.68.2 MozillaThunderbird-translations-other-91.9.0-150200.8.68.2 - SUSE Linux Enterprise Workstation Extension 15-SP3 (x86_64): MozillaThunderbird-91.9.0-150200.8.68.2 MozillaThunderbird-debuginfo-91.9.0-150200.8.68.2 MozillaThunderbird-debugsource-91.9.0-150200.8.68.2 MozillaThunderbird-translations-common-91.9.0-150200.8.68.2 MozillaThunderbird-translations-other-91.9.0-150200.8.68.2 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (aarch64 ppc64le s390x): MozillaThunderbird-91.9.0-150200.8.68.2 MozillaThunderbird-debuginfo-91.9.0-150200.8.68.2 MozillaThunderbird-debugsource-91.9.0-150200.8.68.2 MozillaThunderbird-translations-common-91.9.0-150200.8.68.2 MozillaThunderbird-translations-other-91.9.0-150200.8.68.2 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (aarch64 ppc64le s390x): MozillaThunderbird-91.9.0-150200.8.68.2 MozillaThunderbird-debuginfo-91.9.0-150200.8.68.2 MozillaThunderbird-debugsource-91.9.0-150200.8.68.2 MozillaThunderbird-translations-common-91.9.0-150200.8.68.2 MozillaThunderbird-translations-other-91.9.0-150200.8.68.2 References: https://www.suse.com/security/cve/CVE-2022-1520.html https://www.suse.com/security/cve/CVE-2022-29909.html https://www.suse.com/security/cve/CVE-2022-29911.html https://www.suse.com/security/cve/CVE-2022-29912.html https://www.suse.com/security/cve/CVE-2022-29913.html https://www.suse.com/security/cve/CVE-2022-29914.html https://www.suse.com/security/cve/CVE-2022-29916.html https://www.suse.com/security/cve/CVE-2022-29917.html https://bugzilla.suse.com/1198970 . Security patch for Mozilla Thunderbird: SUSE notice addresses various vulnerabilities with significant threats involved.. SUSE Security Update, MozillaThunderbird Patch, Important Security Fix. . Severity: Important. LinuxSecurity.com Team
Incorrect security status shown after viewing an attached email. (CVE-2022-1520) Fullscreen notification bypass using popups. (CVE-2022-29914) Bypassing permission prompt in nested browsing contexts. (CVE-2022-29909) Leaking browser history with CSS variables. (CVE-2022-29916) . MGASA-2022-0163 - Updated thunderbird packages fix security vulnerability Publication date: 06 May 2022 URL: https://advisories.mageia.org/MGASA-2022-0163.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-1520, CVE-2022-29909, CVE-2022-29911, CVE-2022-29912, CVE-2022-29913, CVE-2022-29914, CVE-2022-29916, CVE-2022-29917 Incorrect security status shown after viewing an attached email. (CVE-2022-1520) Fullscreen notification bypass using popups. (CVE-2022-29914) Bypassing permission prompt in nested browsing contexts. (CVE-2022-29909) Leaking browser history with CSS variables. (CVE-2022-29916) iframe sandbox bypass. (CVE-2022-29911) Reader mode bypassed SameSite cookies. (CVE-2022-29912) Speech Synthesis feature not properly disabled. (CVE-2022-29913) Memory safety bugs fixed in Thunderbird 91.9. (CVE-2022-29917) References: - https://bugs.mageia.org/show_bug.cgi?id=30374 - https://www.mozilla.org/en-US/security/advisories/mfsa2022-18/ - https://www.thunderbird.net/en-US/thunderbird/91.9.0/releasenotes/ - https://www.cve.org/CVERecord?id=CVE-2022-1520 - https://www.cve.org/CVERecord?id=CVE-2022-29909 - https://www.cve.org/CVERecord?id=CVE-2022-29911 - https://www.cve.org/CVERecord?id=CVE-2022-29912 - https://www.cve.org/CVERecord?id=CVE-2022-29913 - https://www.cve.org/CVERecord?id=CVE-2022-29914 - https://www.cve.org/CVERecord?id=CVE-2022-29916 - https://www.cve.org/CVERecord?id=CVE-2022-29917 SRPMS: - 8/core/thunderbird-91.9.0-1.mga8 - 8/core/thunderbird-l10n-91.9.0-1.mga8 . Firefox security patches tackle numerous vulnerabilities, such as access violations and misleading alerts for notifications.. Thunderbird Update, Mageia 8, Email Security Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.