* bsc#1221850 Cross-References: * CVE-2024-29944 . # Security update for MozillaFirefox Announcement ID: SUSE-SU-2024:1000-1 Rating: critical References: * bsc#1221850 Cross-References: * CVE-2024-29944 CVSS scores: Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Firefox Extended Support Release 115.9.1esr ESR MFSA 2024-16 (bsc#1221850) * CVE-2024-29944: Privileged JavaScript Execution via Event Handlers (bmo#1886852). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1000=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1000=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1000=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1000=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debugsource-115.9.1-112.206.1 * MozillaFirefox-debuginfo-115.9.1-112.206.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch) * MozillaFirefox-devel-115.9.1-112.206.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * MozillaFirefox-115.9.1-112.206.1 * MozillaFirefox-debugsource-115.9.1-112.206.1 * MozillaFirefox-debuginfo-115.9.1-112.206.1 *MozillaFirefox-translations-common-115.9.1-112.206.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * MozillaFirefox-devel-115.9.1-112.206.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.9.1-112.206.1 * MozillaFirefox-debugsource-115.9.1-112.206.1 * MozillaFirefox-debuginfo-115.9.1-112.206.1 * MozillaFirefox-translations-common-115.9.1-112.206.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * MozillaFirefox-devel-115.9.1-112.206.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * MozillaFirefox-115.9.1-112.206.1 * MozillaFirefox-debugsource-115.9.1-112.206.1 * MozillaFirefox-debuginfo-115.9.1-112.206.1 * MozillaFirefox-translations-common-115.9.1-112.206.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * MozillaFirefox-devel-115.9.1-112.206.1 ## References: * https://www.suse.com/security/cve/CVE-2024-29944.html * https://bugzilla.suse.com/show_bug.cgi?id=1221850 . Important security update for MozillaFirefox targeting unauthorized privilege escalation vulnerabilities. Apply the fix for SUSE platforms immediately.. MozillaFirefox Security Update, SUSE Linux Advisory, Critical Patch Instructions. . Severity: Critical. LinuxSecurity.com Team
New ntfs-3g packages are available for Slackware 14.2 and 15.0 to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] ntfs-3g (SSA:2023-145-01) New ntfs-3g packages are available for Slackware 14.2 and 15.0 to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/ntfs-3g-2022.10.3-i586-1_slack15.0.txz: Upgraded. Fixed vulnerabilities that may allow an attacker using a maliciously crafted NTFS-formatted image file or external storage to potentially execute arbitrary privileged code or cause a denial of service. Thanks to opty. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-40284 https://www.cve.org/CVERecord?id=CVE-2022-30789 https://www.cve.org/CVERecord?id=CVE-2022-30788 https://www.cve.org/CVERecord?id=CVE-2022-30787 https://www.cve.org/CVERecord?id=CVE-2022-30786 https://www.cve.org/CVERecord?id=CVE-2022-30785 https://www.cve.org/CVERecord?id=CVE-2022-30784 https://www.cve.org/CVERecord?id=CVE-2022-30783 https://www.cve.org/CVERecord?id=CVE-2021-46790 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/ntfs-3g-2022.10.3-i586-1_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/ntfs-3g-2022.10.3-x86_64-1_slack14.2.txz Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/ntfs-3g-2022.10.3-i586-1_slack15.0.txz Updated package for Slackware x86_6415.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/ntfs-3g-2022.10.3-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/ntfs-3g-2022.10.3-i586-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/a/ntfs-3g-2022.10.3-x86_64-1.txz MD5 signatures: +-------------+ Slackware 14.2 package: 4fd4d0dbf6d6f6d5fd222c1a4b875872 ntfs-3g-2022.10.3-i586-1_slack14.2.txz Slackware x86_64 14.2 package: c02b2abfe4735f2d885799bb66ab58d5 ntfs-3g-2022.10.3-x86_64-1_slack14.2.txz Slackware 15.0 package: a2d2a53d0bd94c0af2560630dc4e4892 ntfs-3g-2022.10.3-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 01a47f1c64b435840f928e519800d844 ntfs-3g-2022.10.3-x86_64-1_slack15.0.txz Slackware -current package: fdd91ebb929dd37264305084eaa40974 a/ntfs-3g-2022.10.3-i586-1.txz Slackware x86_64 -current package: 6ec7a1cd9a675f093857bcb2c03f4efa a/ntfs-3g-2022.10.3-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg ntfs-3g-2022.10.3-i586-1_slack15.0.txz +-----+ . The latest ntfs-3g patches for Slackware address serious vulnerabilities and enhance overall system protection. Update today to ensure greater security.. ntfs-3g Security, Slackware Update, Security Fixes. . Severity: Critical. LinuxSecurity.com Team
Firefox could be made to execute JavaScript in a privileged context if it opened a malicious website.. =========================================================================Ubuntu Security Notice USN-5434-1 May 23, 2022 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Firefox could be made to execute JavaScript in a privileged context if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: It was discovered that the methods of an Array object could be corrupted as a result of prototype pollution by sending a message to the parent process. If a user were tricked into opening a specially crafted website, an attacker could exploit this to execute JavaScript in a privileged context. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 100.0.2+build1-0ubuntu0.21.10.1 Ubuntu 20.04 LTS: firefox 100.0.2+build1-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: firefox 100.0.2+build1-0ubuntu0.18.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5434-1 CVE-2022-1529, CVE-2022-1802 Package Information: https://launchpad.net/ubuntu/+source/firefox/100.0.2+build1-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/firefox/100.0.2+build1-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/firefox/100.0.2+build1-0ubuntu0.18.04.1 . The Ubuntu Security Notice USN-5435-2 highlights critical vulnerabilities within Thunderbird, which may cause severe data exposure threats.. Firefox Vulnerability, Privileged Execution, Ubuntu Security Advisory. . Severity: Critical.LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.