SUSE-SU-2024:0211-1
Dashboard / Vulnerabilities / SUSE-SU-2024:0211-1
SUSE-SU-2024:0211-1
Summary: Security update for MozillaFirefox
Details: This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.7.0 ESR (MFSA 2024-02) (bsc#1218955): - CVE-2024-0741: Out of bounds write in ANGLE - CVE-2024-0742: Failure to update user input timestamp - CVE-2024-0746: Crash when listing printers on Linux - CVE-2024-0747: Bypass of Content Security Policy when directive unsafe-inline was set - CVE-2024-0749: Phishing site popup could show local origin in address bar - CVE-2024-0750: Potential permissions request bypass via clickjacking - CVE-2024-0751: Privilege escalation through devtools - CVE-2024-0753: HSTS policy on subdomain could bypass policy of upper domain - CVE-2024-0755: Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240211-1/, https://bugzilla.suse.com/1218955, https://www.suse.com/security/cve/CVE-2024-0741, https://www.suse.com/security/cve/CVE-2024-0742, https://www.suse.com/security/cve/CVE-2024-0746, https://www.suse.com/security/cve/CVE-2024-0747, https://www.suse.com/security/cve/CVE-2024-0749, https://www.suse.com/security/cve/CVE-2024-0750, https://www.suse.com/security/cve/CVE-2024-0751, https://www.suse.com/security/cve/CVE-2024-0753, https://www.suse.com/security/cve/CVE-2024-0755
Affected packages
Package
Name: MozillaFirefox
Purl: pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
