[SUSE-SU-2022:0819-1] Security update for MozillaFirefox

Severity Important
Affected Packages 32
CVEs 5

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 91.7.0 ESR (bsc#1196900):

  • CVE-2022-26383: Browser window spoof using fullscreen mode
  • CVE-2022-26384: iframe allow-scripts sandbox bypass
  • CVE-2022-26387: Time-of-check time-of-use bug when verifying add-on signatures
  • CVE-2022-26381: Use-after-free in text reflows
  • CVE-2022-26386: Temporary files downloaded to /tmp and accessible by other local users
Package Affected Version
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15&sp=1 < 91.7.0-150.24.1
pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15 < 91.7.0-150.24.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15 suse MozillaFirefox < 91.7.0-150.24.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15 suse MozillaFirefox-translations-other < 91.7.0-150.24.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15 suse MozillaFirefox-translations-common < 91.7.0-150.24.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=x86_64&distro=sles-15 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 x86_64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=s390x&distro=sles-15 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 s390x
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=ppc64le&distro=sles-15 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 ppc64le
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15&sp=1 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 aarch64
Affected pkg:rpm/suse/MozillaFirefox-devel?arch=aarch64&distro=sles-15 suse MozillaFirefox-devel < 91.7.0-150.24.1 sles-15 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...