[GLSA-202102-01] Mozilla Firefox: Multiple vulnerabilities

Severity Normal
Affected Packages 2
Unaffected Packages 4
CVEs 12

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Background
Mozilla Firefox is a popular open-source web browser from the Mozilla
project.

Description
Multiple vulnerabilities have been discovered in Mozilla Firefox. Please
review the CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All Mozilla Firefox ESR users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-78.7.0"

All Mozilla Firefox ESR binary users should upgrade to the latest
version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-bin-78.7.0"

All Mozilla Firefox users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-85.0"

All Mozilla Firefox binary users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-bin-85.0"

Source # ID Name URL
CVE CVE-2021-23953 CVE-2021-23953 https://nvd.nist.gov/vuln/detail/CVE-2021-23953
CVE CVE-2021-23954 CVE-2021-23954 https://nvd.nist.gov/vuln/detail/CVE-2021-23954
CVE CVE-2021-23955 CVE-2021-23955 https://nvd.nist.gov/vuln/detail/CVE-2021-23955
CVE CVE-2021-23956 CVE-2021-23956 https://nvd.nist.gov/vuln/detail/CVE-2021-23956
CVE CVE-2021-23958 CVE-2021-23958 https://nvd.nist.gov/vuln/detail/CVE-2021-23958
CVE CVE-2021-23960 CVE-2021-23960 https://nvd.nist.gov/vuln/detail/CVE-2021-23960
CVE CVE-2021-23961 CVE-2021-23961 https://nvd.nist.gov/vuln/detail/CVE-2021-23961
CVE CVE-2021-23962 CVE-2021-23962 https://nvd.nist.gov/vuln/detail/CVE-2021-23962
CVE CVE-2021-23963 CVE-2021-23963 https://nvd.nist.gov/vuln/detail/CVE-2021-23963
CVE CVE-2021-23964 CVE-2021-23964 https://nvd.nist.gov/vuln/detail/CVE-2021-23964
CVE CVE-2021-23965 CVE-2021-23965 https://nvd.nist.gov/vuln/detail/CVE-2021-23965
CVE CVE-2021-26976 CVE-2021-26976 https://nvd.nist.gov/vuln/detail/CVE-2021-26976
Vendor Upstream advisory (MFSA-2021-03) https://www.mozilla.org/en-US/security/advisories/mfsa2021-03/
Vendor Upstream advisory (MFSA-2021-04) https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/
Bugzilla 767334 Bugzilla #767334 https://bugs.gentoo.org/show_bug.cgi?id=767334
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/www-client/firefox?distro=gentoo www-client firefox < 85.0 gentoo
Unaffected pkg:ebuild/www-client/firefox?distro=gentoo www-client firefox >= 78.7.0 gentoo
Unaffected pkg:ebuild/www-client/firefox?distro=gentoo www-client firefox >= 85.0 gentoo
Affected pkg:ebuild/www-client/firefox-bin?distro=gentoo www-client firefox-bin < 85.0 gentoo
Unaffected pkg:ebuild/www-client/firefox-bin?distro=gentoo www-client firefox-bin >= 78.7.0 gentoo
Unaffected pkg:ebuild/www-client/firefox-bin?distro=gentoo www-client firefox-bin >= 85.0 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...