[SUSE-SU-2021:3721-1] Security update for MozillaFirefox

Severity Important
Affected Packages 39
CVEs 8

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

MozillaFirefox was updated to Extended Support Release 91.3.0 ESR

  • Fixed: Various stability, functionality, and security fixes

MFSA 2021-49 (bsc#1192250)

  • CVE-2021-38503: iframe sandbox rules did not apply to XSLT stylesheets
  • CVE-2021-38504: Use-after-free in file picker dialog
  • CVE-2021-38505: Windows 10 Cloud Clipboard may have recorded sensitive user data
  • CVE-2021-38506: Firefox could be coaxed into going into fullscreen mode without notification or warning
  • CVE-2021-38507: Opportunistic Encryption in HTTP2 could be used to bypass the Same-Origin-Policy on services hosted on other ports
  • CVE-2021-38508: Permission Prompt could be overlaid, resulting in user confusion and potential spoofing
  • CVE-2021-38509: Javascript alert box could have been spoofed onto an arbitrary domain
  • CVE-2021-38510: Download Protections were bypassed by .inetloc files on Mac OS
  • MOZ-2021-0008: Use-after-free in HTTP2 Session object
  • MOZ-2021-0007: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3
Package Affected Version
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=2 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=2 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=2 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-12&sp=3 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-12&sp=5 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-12&sp=4 < 91.3.0-112.80.2
pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-12&sp=3 < 91.3.0-112.80.2
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=5 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=4 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=3 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-12&sp=2 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-12&sp=5 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-12&sp=4 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-12&sp=3 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-12&sp=5 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-12&sp=4 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-12&sp=3 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-12&sp=5 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-12&sp=4 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-12&sp=3 suse MozillaFirefox < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=5 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=4 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=3 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-12&sp=2 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-12&sp=5 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-12&sp=4 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-12&sp=3 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-12&sp=5 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-12&sp=4 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-12&sp=3 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-12&sp=5 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-12&sp=4 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-12&sp=3 suse MozillaFirefox-translations-common < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=5 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=4 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=3 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-12&sp=2 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-12&sp=5 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-12&sp=4 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-12&sp=3 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 s390x
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-12&sp=5 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-12&sp=4 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-12&sp=3 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-12&sp=5 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-12&sp=4 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 aarch64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-12&sp=3 suse MozillaFirefox-devel < 91.3.0-112.80.2 sles-12 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...