Mageia 2022-0057: firefox security update
Summary
If a user installed an extension of a particular type, the extension could
have auto-updated itself and while doing so, bypass the prompt which grants
the new version the new requested permissions (CVE-2022-22754).
If a user was convinced to drag and drop an image to their desktop or other
folder, the resulting object could have been changed into an executable script
which would have run arbitrary code after the user clicked on it
(CVE-2022-22756).
If a document created a sandboxed iframe without allow-scripts, and
subsequently appended an element to the iframe's document that e.g. had a
JavaScript event handler - the event handler would have run despite the
iframe's sandbox (CVE-2022-22759).
When importing resources using Web Workers, error messages would distinguish
the difference between application/javascript responses and non-script
responses. This could have been abused to learn information cross-origin
(CVE-2022-22760).
Web-accessible extension pages (pages with a moz-extensi...
References
- https://bugs.mageia.org/show_bug.cgi?id=30009
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_75.html
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-05/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22754
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22756
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22759
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22760
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22761
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22763
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22764
Resolution
MGASA-2022-0057 - Updated firefox packages fix security vulnerability
SRPMS
- 8/core/firefox-91.6.0-1.mga8
- 8/core/firefox-l10n-91.6.0-1.mga8
- 8/core/nss-3.75.0-1.mga8