SUSE-SU-2022:0565-1
Dashboard / Vulnerabilities / SUSE-SU-2022:0565-1
SUSE-SU-2022:0565-1
Summary: Security update for MozillaFirefox
Details: This update for MozillaFirefox fixes the following issues: Firefox Extended Support Release 91.6.0 ESR / MFSA 2022-05 (bsc#1195682) - CVE-2022-22753: Privilege Escalation to SYSTEM on Windows via Maintenance Service - CVE-2022-22754: Extensions could have bypassed permission confirmation during update - CVE-2022-22756: Drag and dropping an image could have resulted in the dropped object being an executable - CVE-2022-22759: Sandboxed iframes could have executed script if the parent appended elements - CVE-2022-22760: Cross-Origin responses could be distinguished between script and non-script content-types - CVE-2022-22761: frame-ancestors Content Security Policy directive was not enforced for framed extension pages - CVE-2022-22763: Script Execution during invalid object state - CVE-2022-22764: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6 Firefox Extended Support Release 91.5.1 ESR (bsc#1195230) - Fixed an issue that allowed unexpected data to be submitted in some of our search telemetry
References: https://www.suse.com/support/update/announcement/2022/suse-su-20220565-1/, https://bugzilla.suse.com/1195230, https://bugzilla.suse.com/1195682, https://www.suse.com/security/cve/CVE-2022-22753, https://www.suse.com/security/cve/CVE-2022-22754, https://www.suse.com/security/cve/CVE-2022-22756, https://www.suse.com/security/cve/CVE-2022-22759, https://www.suse.com/security/cve/CVE-2022-22760, https://www.suse.com/security/cve/CVE-2022-22761, https://www.suse.com/security/cve/CVE-2022-22763, https://www.suse.com/security/cve/CVE-2022-22764
Affected packages
Package
Name: MozillaFirefox
Purl: pkg:rpm/suse/MozillaFirefox&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
