[SUSE-SU-2022:0676-1] Security update for MozillaFirefox

Severity Important
Affected Packages 32
CVEs 8

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 91.6.0 ESR / MFSA 2022-05 (bsc#1195682)

  • CVE-2022-22753: Privilege Escalation to SYSTEM on Windows via Maintenance Service
  • CVE-2022-22754: Extensions could have bypassed permission confirmation during update
  • CVE-2022-22756: Drag and dropping an image could have resulted in the dropped object being an executable
  • CVE-2022-22759: Sandboxed iframes could have executed script if the parent appended elements
  • CVE-2022-22760: Cross-Origin responses could be distinguished between script and non-script content-types
  • CVE-2022-22761: frame-ancestors Content Security Policy directive was not enforced for framed extension pages
  • CVE-2022-22763: Script Execution during invalid object state
  • CVE-2022-22764: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6

Firefox Extended Support Release 91.5.1 ESR (bsc#1195230)

  • Fixed an issue that allowed unexpected data to be submitted in some of our search telemetry
Package Affected Version
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15&sp=1 < 91.6.0-150.18.1
pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15 < 91.6.0-150.18.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15 suse MozillaFirefox < 91.6.0-150.18.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15 suse MozillaFirefox-translations-other < 91.6.0-150.18.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15 suse MozillaFirefox-translations-common < 91.6.0-150.18.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15 suse MozillaFirefox-devel < 91.6.0-150.18.1 sles-15 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...