ArchLinux: 202109-2: firefox: multiple issues
Summary
- CVE-2021-38491 (insufficient validation)
In Firefox before version 92, mixed-content checks were unable to
analyze opaque origins which led to some mixed content being loaded.
- CVE-2021-38494 (arbitrary code execution)
Mozilla developers reported memory safety bugs present in Firefox 91.
Some of these bugs showed evidence of memory corruption and Mozilla
presumes that with enough effort some of these could have been
exploited to run arbitrary code.
Resolution
Upgrade to 92.0-1.
# pacman -Syu "firefox>=92.0-1"
The problems have been fixed upstream in version 92.0.
References
https://www.mozilla.org/en-US/security/advisories/mfsa2021-38/ https://bugzilla.mozilla.org/show_bug.cgi?id=1551886 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1723920%2C1725638 https://security.archlinux.org/CVE-2021-38491 https://security.archlinux.org/CVE-2021-38494
Workaround
None.