[RHSA-2022:0124] firefox security update

Severity Important
Affected Packages 5
CVEs 12

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 91.5.0 ESR.

Security Fix(es):

  • Mozilla: Iframe sandbox bypass with XSLT (CVE-2021-4140)

  • Mozilla: Race condition when playing audio files (CVE-2022-22737)

  • Mozilla: Heap-buffer-overflow in blendGaussianBlur (CVE-2022-22738)

  • Mozilla: Use-after-free of ChannelEventQueue::mOwner (CVE-2022-22740)

  • Mozilla: Browser window spoof using fullscreen mode (CVE-2022-22741)

  • Mozilla: Out-of-bounds memory access when inserting text in edit mode (CVE-2022-22742)

  • Mozilla: Browser window spoof using fullscreen mode (CVE-2022-22743)

  • Mozilla: Memory safety bugs fixed in Firefox 96 and Firefox ESR 91.5 (CVE-2022-22751)

  • Mozilla: Leaking cross-origin URLs through securitypolicyviolation event (CVE-2022-22745)

  • Mozilla: Spoofed origin on external protocol launch dialog (CVE-2022-22748)

  • Mozilla: Missing throttling on external protocol launch dialog (CVE-2022-22739)

  • Mozilla: Crash when handling empty pkcs7 sequence (CVE-2022-22747)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Source # ID Name URL
Bugzilla 2039561 https://bugzilla.redhat.com/2039561
Bugzilla 2039563 https://bugzilla.redhat.com/2039563
Bugzilla 2039564 https://bugzilla.redhat.com/2039564
Bugzilla 2039565 https://bugzilla.redhat.com/2039565
Bugzilla 2039566 https://bugzilla.redhat.com/2039566
Bugzilla 2039567 https://bugzilla.redhat.com/2039567
Bugzilla 2039568 https://bugzilla.redhat.com/2039568
Bugzilla 2039569 https://bugzilla.redhat.com/2039569
Bugzilla 2039570 https://bugzilla.redhat.com/2039570
Bugzilla 2039572 https://bugzilla.redhat.com/2039572
Bugzilla 2039573 https://bugzilla.redhat.com/2039573
Bugzilla 2039574 https://bugzilla.redhat.com/2039574
RHSA RHSA-2022:0124 https://access.redhat.com/errata/RHSA-2022:0124
CVE CVE-2021-4140 https://access.redhat.com/security/cve/CVE-2021-4140
CVE CVE-2022-22737 https://access.redhat.com/security/cve/CVE-2022-22737
CVE CVE-2022-22738 https://access.redhat.com/security/cve/CVE-2022-22738
CVE CVE-2022-22739 https://access.redhat.com/security/cve/CVE-2022-22739
CVE CVE-2022-22740 https://access.redhat.com/security/cve/CVE-2022-22740
CVE CVE-2022-22741 https://access.redhat.com/security/cve/CVE-2022-22741
CVE CVE-2022-22742 https://access.redhat.com/security/cve/CVE-2022-22742
CVE CVE-2022-22743 https://access.redhat.com/security/cve/CVE-2022-22743
CVE CVE-2022-22745 https://access.redhat.com/security/cve/CVE-2022-22745
CVE CVE-2022-22747 https://access.redhat.com/security/cve/CVE-2022-22747
CVE CVE-2022-22748 https://access.redhat.com/security/cve/CVE-2022-22748
CVE CVE-2022-22751 https://access.redhat.com/security/cve/CVE-2022-22751
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-7.9 redhat firefox < 91.5.0-1.el7_9 redhat-7.9 x86_64
Affected pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-7.9 redhat firefox < 91.5.0-1.el7_9 redhat-7.9 s390x
Affected pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-7.9 redhat firefox < 91.5.0-1.el7_9 redhat-7.9 ppc64le
Affected pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-7.9 redhat firefox < 91.5.0-1.el7_9 redhat-7.9 ppc64
Affected pkg:rpm/redhat/firefox?arch=i686&distro=redhat-7.9 redhat firefox < 91.5.0-1.el7_9 redhat-7.9 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...