This update upgrades Firefox to version 91.6.0 ESR. * Mozilla: Extensions could have bypassed permission confirmation during update (CVE-2022-22754) * Mozilla: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6 (CVE-2022-22764) * Mozilla: Drag and dropping an image could have resulted in the dropped object being an executable (CVE-2022-22756) * Mozilla: Sandboxed iframes could have [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2022:0514-1 Issue Date: 2022-02-14 CVE Numbers: CVE-2022-22754 CVE-2022-22756 CVE-2022-22760 CVE-2022-22761 CVE-2022-22763 CVE-2022-22759 CVE-2022-22764 -- This update upgrades Firefox to version 91.6.0 ESR. Security Fix(es): * Mozilla: Extensions could have bypassed permission confirmation during update (CVE-2022-22754) * Mozilla: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6 (CVE-2022-22764) * Mozilla: Drag and dropping an image could have resulted in the dropped object being an executable (CVE-2022-22756) * Mozilla: Sandboxed iframes could have executed script if the parent appended elements (CVE-2022-22759) * Mozilla: Cross-Origin responses could be distinguished between script and non-script content-types (CVE-2022-22760) * Mozilla: frame-ancestors Content Security Policy directive was not enforced for framed extension pages (CVE-2022-22761) * Mozilla: Script Execution during invalid object state (CVE-2022-22763) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 firefox-91.6.0-1.el7_9.x86_64.rpm firefox-debuginfo-91.6.0-1.el7_9.x86_64.rpm firefox-91.6.0-1.el7_9.i686.rpm - Scientific Linux Development Team . Google addresses multiple vulnerabilities in Chrome 94.5.0. Review key enhancements and safety patches from CentOS.. Firefox Update, Security Advisory,Scientific Linux, Memory Safety, Permissions Fix. . Severity: Important. LinuxSecurity.com Team
Critical: firefox security update. Date: Fri, 13 Dec 2013 15:05:25 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Critical: firefox on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Critical: firefox security update Advisory ID: SLSA-2013:1812-1 Issue Date: 2013-12-11 CVE Numbers: CVE-2013-5609 CVE-2013-5612 CVE-2013-5614 CVE-2013-5616 CVE-2013-5618 CVE-2013-6671 CVE-2013-5613 -- Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to terminate unexpectedly or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2013-5609, CVE-2013-5616, CVE-2013-5618, CVE-2013-6671, CVE-2013-5613) A flaw was found in the way Firefox rendered web content with missing character encoding information. An attacker could use this flaw to possibly bypass same-origin inheritance and perform cross-site scripting (XSS) attacks. (CVE-2013-5612) It was found that certain malicious web content could bypass restrictions applied by sandboxed iframes. An attacker could combine this flaw with other vulnerabilities to execute arbitrary code with the privileges of the user running Firefox. (CVE-2013-5614) After installing the update, Firefox must be restarted for the changes to take effect. -- SL5 x86_64 firefox-24.2.0-1.el5_10.i386.rpm firefox-24.2.0-1.el5_10.x86_64.rpm firefox-debuginfo-24.2.0-1.el5_10.i386.rpm firefox-debuginfo-24.2.0-1.el5_10.x86_64.rpm i386 firefox-24.2.0-1.el5_10.i386.rpm firefox-debuginfo-24.2.0-1.el5_10.i386.rpm SL6 x86_64 firefox-24.2.0-1.el6_5.i686.rpm firefox-24.2.0-1.el6_5.x86_64.rpm firefox-debuginfo-24.2.0-1.el6_5.i686.rpm firefox-debuginfo-24.2.0-1.el6_5.x86_64.rpm i386 firefox-24.2.0-1.el6_5.i686.rpm firefox-debuginfo-24.2.0-1.el6_5.i686.rpm - Scientific Linux Development Team . Essential Firefox security patch for Scientific Linux SL5.x and SL6.x addressing majorvulnerabilities. System reboot necessary following the update.. SL5,x86_64,firefox update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.