Mageia 2022-0427: firefox security update
Summary
In libexpat through 2.4.9, there is a use-after free caused by overeager
destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory
situations (CVE-2022-43680).
Service Workers should not be able to infer information about opaque
cross-origin responses; but timing information for cross-origin media combined
with Range requests might have allowed them to determine the presence or
length of a media file (CVE-2022-45403).
Through a series of popup and window.print() calls, an attacker can cause a
window to go fullscreen without the user seeing the notification prompt,
resulting in potential user confusion or spoofing attacks (CVE-2022-45404).
Freeing arbitrary nsIInputStream's on a different thread than creation could
have led to a use-after-free and potentially exploitable crash
(CVE-2022-45405).
If an out-of-memory condition occurred when creating a JavaScript global, a
JavaScript realm may be deleted while references to it lived on in a
BaseShape. This could lead...
References
- https://bugs.mageia.org/show_bug.cgi?id=31128
- https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/fHvKAhUTnLs
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_85.html
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-48/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43680
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45403
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45404
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45405
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45406
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45408
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45409
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45410
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45411
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45412
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45416
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45418
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45420
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45421
Resolution
MGASA-2022-0427 - Updated firefox packages fix security vulnerability
SRPMS
- 8/core/firefox-102.5.0-1.mga8
- 8/core/firefox-l10n-102.5.0-1.mga8
- 8/core/nss-3.85.0-1.mga8