[openSUSE-SU-2022:0821-1] Security update for MozillaFirefox

Severity Important
Affected Packages 20
CVEs 5

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 91.7.0 ESR (bsc#1196900):

  • CVE-2022-26383: Browser window spoof using fullscreen mode
  • CVE-2022-26384: iframe allow-scripts sandbox bypass
  • CVE-2022-26387: Time-of-check time-of-use bug when verifying add-on signatures
  • CVE-2022-26381: Use-after-free in text reflows
  • CVE-2022-26386: Temporary files downloaded to /tmp and accessible by other local users
Package Affected Version
pkg:rpm/opensuse/MozillaFirefox?arch=x86_64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox?arch=s390x&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox?arch=ppc64le&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox?arch=aarch64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=x86_64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=s390x&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=ppc64le&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=aarch64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=x86_64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=s390x&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=ppc64le&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=aarch64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-devel?arch=x86_64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-devel?arch=s390x&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-devel?arch=ppc64le&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-devel?arch=aarch64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=x86_64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=s390x&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=ppc64le&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=aarch64&distro=opensuse-leap-15.3 < 91.7.0-152.22.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/MozillaFirefox?arch=x86_64&distro=opensuse-leap-15.3 opensuse MozillaFirefox < 91.7.0-152.22.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox?arch=s390x&distro=opensuse-leap-15.3 opensuse MozillaFirefox < 91.7.0-152.22.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/MozillaFirefox?arch=ppc64le&distro=opensuse-leap-15.3 opensuse MozillaFirefox < 91.7.0-152.22.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/opensuse/MozillaFirefox?arch=aarch64&distro=opensuse-leap-15.3 opensuse MozillaFirefox < 91.7.0-152.22.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=x86_64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-other < 91.7.0-152.22.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=s390x&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-other < 91.7.0-152.22.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=ppc64le&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-other < 91.7.0-152.22.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/opensuse/MozillaFirefox-translations-other?arch=aarch64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-other < 91.7.0-152.22.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=x86_64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-common < 91.7.0-152.22.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=s390x&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-common < 91.7.0-152.22.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=ppc64le&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-common < 91.7.0-152.22.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/opensuse/MozillaFirefox-translations-common?arch=aarch64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-translations-common < 91.7.0-152.22.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/opensuse/MozillaFirefox-devel?arch=x86_64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-devel < 91.7.0-152.22.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-devel?arch=s390x&distro=opensuse-leap-15.3 opensuse MozillaFirefox-devel < 91.7.0-152.22.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/MozillaFirefox-devel?arch=ppc64le&distro=opensuse-leap-15.3 opensuse MozillaFirefox-devel < 91.7.0-152.22.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/opensuse/MozillaFirefox-devel?arch=aarch64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-devel < 91.7.0-152.22.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=x86_64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-branding-upstream < 91.7.0-152.22.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=s390x&distro=opensuse-leap-15.3 opensuse MozillaFirefox-branding-upstream < 91.7.0-152.22.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=ppc64le&distro=opensuse-leap-15.3 opensuse MozillaFirefox-branding-upstream < 91.7.0-152.22.1 opensuse-leap-15.3 ppc64le
Affected pkg:rpm/opensuse/MozillaFirefox-branding-upstream?arch=aarch64&distro=opensuse-leap-15.3 opensuse MozillaFirefox-branding-upstream < 91.7.0-152.22.1 opensuse-leap-15.3 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...