[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2022:8554-01 -- Redhat firefox

ID: oval:org.secpod.oval:def:507413Date: (C)2022-12-01   (M)2023-08-16
Class: PATCHFamily: unix




Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.5.0 ESR. Security Fix: * Mozilla: Service Workers might have learned size of cross-origin media files * Mozilla: Fullscreen notification bypass * Mozilla: Use-after-free in InputStream implementation * Mozilla: Use-after-free of a JavaScript Realm * Mozilla: Fullscreen notification bypass via windowName * Mozilla: Use-after-free in Garbage Collection * Mozilla: Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5 * Mozilla: ServiceWorker-intercepted requests bypassed SameSite cookie policy * Mozilla: Cross-Site Tracing was possible via non-standard override headers * Mozilla: Symlinks may resolve to partially uninitialized buffers * Mozilla: Keystroke Side-Channel Leakage * Mozilla: Custom mouse cursor could have been drawn over browser UI * Mozilla: Iframe contents could be rendered outside the iframe For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Platform:
Red Hat Enterprise Linux 8
Product:
firefox
Reference:
RHSA-2022:8554-01
CVE-2022-45403
CVE-2022-45404
CVE-2022-45405
CVE-2022-45406
CVE-2022-45408
CVE-2022-45409
CVE-2022-45410
CVE-2022-45411
CVE-2022-45412
CVE-2022-45416
CVE-2022-45418
CVE-2022-45420
CVE-2022-45421
CVE    13
CVE-2022-45404
CVE-2022-45403
CVE-2022-45412
CVE-2022-45408
...
CPE    2
cpe:/o:redhat:enterprise_linux:8
cpe:/a:mozilla:firefox

© SecPod Technologies