[SUSE-SU-2021:0246-1] Security update for MozillaFirefox
Severity
Important
Affected Packages
16
CVEs
5
Security update for MozillaFirefox
This update for MozillaFirefox fixes the following issues:
- Firefox Extended Support Release 78.7.0 ESR (MFSA 2021-04, bsc#1181414)
- CVE-2021-23953: Fixed a Cross-origin information leakage via redirected PDF requests
- CVE-2021-23954: Fixed a type confusion when using logical assignment operators in JavaScript switch statements
- CVE-2020-26976: Fixed an issue where HTTPS pages could have been intercepted by a registered service worker when they should not have been
- CVE-2021-23960: Fixed a use-after-poison for incorrectly redeclared JavaScript variables during GC
- CVE-2021-23964: Fixed Memory safety bugs
- ID
- SUSE-SU-2021:0246-1
- Severity
- important
- URL
- https://www.suse.com/support/update/announcement/2021/suse-su-20210246-1/
- Published
-
2021-01-29T12:13:47
(3 years ago) - Modified
-
2021-01-29T12:13:47
(3 years ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALAS2-2021-1603
- ALPINE:CVE-2020-26976
- ALPINE:CVE-2021-23953
- ALPINE:CVE-2021-23954
- ALPINE:CVE-2021-23960
- ALPINE:CVE-2021-23964
- ASA-202012-25
- ASA-202102-1
- ASA-202102-2
- DSA-4840-1
- DSA-4842-1
- ELSA-2021-0288
- ELSA-2021-0290
- ELSA-2021-0297
- ELSA-2021-0298
- GLSA-202102-01
- GLSA-202102-02
- MFSA-2020-54
- MFSA-2021-03
- MFSA-2021-04
- MFSA-2021-05
- openSUSE-SU-2021:0208-1
- openSUSE-SU-2021:0209-1
- openSUSE-SU-2021:0222-1
- openSUSE-SU-2021:0223-1
- RHSA-2021:0288
- RHSA-2021:0290
- RHSA-2021:0297
- RHSA-2021:0298
- SUSE-SU-2021:0241-1
- SUSE-SU-2021:0245-1
- SUSE-SU-2021:0257-1
- SUSE-SU-2021:0259-1
- USN-4671-1
- USN-4717-1
- USN-4736-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/suse-su-2021_0246-1.json | |
Suse | URL for SUSE-SU-2021:0246-1 | https://www.suse.com/support/update/announcement/2021/suse-su-20210246-1/ | |
Suse | E-Mail link for SUSE-SU-2021:0246-1 | https://lists.suse.com/pipermail/sle-security-updates/2021-January/008257.html | |
Bugzilla | SUSE Bug 1181414 | https://bugzilla.suse.com/1181414 | |
CVE | SUSE CVE CVE-2020-26976 page | https://www.suse.com/security/cve/CVE-2020-26976/ | |
CVE | SUSE CVE CVE-2021-23953 page | https://www.suse.com/security/cve/CVE-2021-23953/ | |
CVE | SUSE CVE CVE-2021-23954 page | https://www.suse.com/security/cve/CVE-2021-23954/ | |
CVE | SUSE CVE CVE-2021-23960 page | https://www.suse.com/security/cve/CVE-2021-23960/ | |
CVE | SUSE CVE CVE-2021-23964 page | https://www.suse.com/security/cve/CVE-2021-23964/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15&sp=1 | suse | MozillaFirefox | < 78.7.0-3.128.2 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15&sp=1 | suse | MozillaFirefox | < 78.7.0-3.128.2 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15&sp=1 | suse | MozillaFirefox | < 78.7.0-3.128.2 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15&sp=1 | suse | MozillaFirefox | < 78.7.0-3.128.2 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-other | < 78.7.0-3.128.2 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-other | < 78.7.0-3.128.2 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-other | < 78.7.0-3.128.2 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-other | < 78.7.0-3.128.2 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-common | < 78.7.0-3.128.2 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-common | < 78.7.0-3.128.2 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-common | < 78.7.0-3.128.2 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15&sp=1 | suse | MozillaFirefox-translations-common | < 78.7.0-3.128.2 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15&sp=1 | suse | MozillaFirefox-devel | < 78.7.0-3.128.2 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15&sp=1 | suse | MozillaFirefox-devel | < 78.7.0-3.128.2 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15&sp=1 | suse | MozillaFirefox-devel | < 78.7.0-3.128.2 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15&sp=1 | suse | MozillaFirefox-devel | < 78.7.0-3.128.2 | sles-15 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |