If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions (CVE-2022-22754). If a user was convinced to drag and drop an image to their desktop or other . MGASA-2022-0061 - Updated thunderbird packages fix security vulnerability Publication date: 12 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0061.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-22754, CVE-2022-22756, CVE-2022-22759, CVE-2022-22760, CVE-2022-22761, CVE-2022-22763, CVE-2022-22764 If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions (CVE-2022-22754). If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it (CVE-2022-22756). If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox (CVE-2022-22759). When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin (CVE-2022-22760). Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy (CVE-2022-22761). When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible (CVE-2022-22763). Mozilla developers and community members Paul Adenot and the Mozilla Fuzzing Teamreported memory safety bugs present in Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2022-22764). References: - https://bugs.mageia.org/show_bug.cgi?id=30012 - https://www.thunderbird.net/en-US/thunderbird/91.6.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2022-06/ - https://www.cve.org/CVERecord?id=CVE-2022-22754 - https://www.cve.org/CVERecord?id=CVE-2022-22756 - https://www.cve.org/CVERecord?id=CVE-2022-22759 - https://www.cve.org/CVERecord?id=CVE-2022-22760 - https://www.cve.org/CVERecord?id=CVE-2022-22761 - https://www.cve.org/CVERecord?id=CVE-2022-22763 - https://www.cve.org/CVERecord?id=CVE-2022-22764 SRPMS: - 8/core/thunderbird-91.6.0-1.mga8 - 8/core/thunderbird-l10n-91.6.0-1.mga8 . Enhancements for Thunderbird address multiple vulnerabilities, addressing sandboxing weaknesses and risks of possible arbitrary code execution.. Thunderbird Security,Mageia Updates,Sandbox Flaws,Code Execution Risks. . LinuxSecurity.com Team
The Java sandbox environment in Konqueror can be bypassed to access arbitrary packages, allowing untrusted Java applets to perform unrestricted actions on the host system. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Konqueror: Java sandbox vulnerabilities Date: January 11, 2005 Bugs: #72750 ID: 200501-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= The Java sandbox environment in Konqueror can be bypassed to access arbitrary packages, allowing untrusted Java applets to perform unrestricted actions on the host system. Background ========= KDE is a feature-rich graphical desktop environment for Linux and Unix-like Operating Systems. Konqueror is the KDE web browser and file manager. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 kde-base/kdelibs < 3.3.2 > = 3.3.2 Description ========== Konqueror contains two errors that allow JavaScript scripts and Java applets to have access to restricted Java classes. Impact ===== A remote attacker could embed a malicious Java applet in a web page and entice a victim to view it. This applet can then bypass security restrictions and execute any command, or access any file with the rights of the user running Konqueror. Workaround ========= There is no known workaround at this time. Resolution ========= All kdelibs users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbosekde-base/kdelibs Note: There is currently no fixed stable version for sparc. References ========= [ 1 ] KDE Security Advisory: Konqueror Java Vulnerability https://kde.org/info/security/advisory-20041220-1.txt [ 2 ] CAN 2004-1145 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1145 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-16 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.