[MFSA-2022-29] Security Vulnerabilities fixed in Firefox ESR 91.12
Severity
Moderate
Affected Packages
1
Fixed Packages
1
CVEs
2
CVE-2022-36318: Directory indexes for bundled resources reflected URL parameters (moderate)
When visiting directory listings forchrome://
URLs as source text, some parameters were reflected.CVE-2022-36319: Mouse Position spoofing with CSS transforms (moderate)
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed.
Package | Affected Version |
---|---|
pkg:mozilla/Firefox%20ESR | < 91.12 |
Package | Fixed Version |
---|---|
pkg:mozilla/Firefox%20ESR | = 91.12 |
- ID
- MFSA-2022-29
- Severity
- moderate
- URL
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-29
- Published
-
2022-07-26T00:00:00
(2 years ago) - Modified
-
2022-07-26T00:00:00
(2 years ago) - Other Advisories
-
- ALAS2-2022-1855
- ALPINE:CVE-2022-36318
- ALPINE:CVE-2022-36319
- ALSA-2022:5767
- ALSA-2022:5774
- ALSA-2022:5777
- DSA-5193-1
- DSA-5195-1
- ELSA-2022-5767
- ELSA-2022-5773
- ELSA-2022-5774
- ELSA-2022-5776
- ELSA-2022-5777
- ELSA-2022-5778
- GLSA-202208-08
- GLSA-202208-14
- MFSA-2022-28
- MFSA-2022-30
- MFSA-2022-31
- MFSA-2022-32
- RHSA-2022:5767
- RHSA-2022:5773
- RHSA-2022:5774
- RHSA-2022:5776
- RHSA-2022:5777
- RHSA-2022:5778
- RLSA-2022:5774
- RLSA-2022:5777
- SUSE-SU-2022:2596-1
- SUSE-SU-2022:2602-1
- SUSE-SU-2022:2611-1
- SUSE-SU-2022:2748-1
- SUSE-SU-2022:3272-1
- SUSE-SU-2022:3273-1
- SUSE-SU-2022:3281-1
- SUSE-SU-2022:3396-1
- USN-5536-1
- USN-5663-1
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1771774 | https://bugzilla.mozilla.org/show_bug.cgi?id=1771774 | |
Bugzilla | 1737722 | https://bugzilla.mozilla.org/show_bug.cgi?id=1737722 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:mozilla/Firefox%20ESR | Firefox ESR | < 91.12 | ||||
Fixed | pkg:mozilla/Firefox%20ESR | Firefox ESR | = 91.12 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |