MGASA-2021-0163
Dashboard / Vulnerabilities / MGASA-2021-0163
MGASA-2021-0163
Summary: Updated firefox packages fix security vulnerabilities
Details: Texture upload into an unbound backing buffer resulted in an out-of-bound read. (CVE-2021-23981) Angle graphics library out of date. (CVE-2021-4127) Internal network hosts could have been probed by a malicious webpage. (CVE-2021-23982) Malicious extensions could have spoofed popup information. (CVE-2021-23984) Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9 (CVE-2021-23987).
References: https://advisories.mageia.org/MGASA-2021-0163.html, https://bugs.mageia.org/show_bug.cgi?id=28641, https://www.mozilla.org/en-US/firefox/78.9.0/releasenotes/, https://www.mozilla.org/en-US/security/advisories/mfsa2021-11/, https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.63_release_notes, https://groups.google.com/g/mozilla.dev.tech.nspr/c/wwXfLFWZRlA
Affected packages
Package
Name: nss
Purl: pkg:rpm/mageia/nss?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
