openSUSE-SU-2021:3993-1

    Dashboard / Vulnerabilities / openSUSE-SU-2021:3993-1

    openSUSE-SU-2021:3993-1

    Published: 10 Dec 2021Last Modified: 4 Feb 2026

    Summary: Security update for MozillaFirefox

    Details: This update for MozillaFirefox fixes the following issues: Update to Extended Support Release 91.4.0 (bsc#1193485): - CVE-2021-43536: URL leakage when navigating while executing asynchronous function - CVE-2021-43537: Heap buffer overflow when using structured clone - CVE-2021-43538: Missing fullscreen and pointer lock notification when requesting both - CVE-2021-43539: GC rooting failure when calling wasm instance methods - CVE-2021-43541: External protocol handler parameters were unescaped - CVE-2021-43542: XMLHttpRequest error codes could have leaked the existence of an external protocol handler - CVE-2021-43543: Bypass of CSP sandbox directive when embedding - CVE-2021-43545: Denial of Service when using the Location API in a loop - CVE-2021-43546: Cursor spoofing could overlay user interface when native cursor is zoomed - Memory safety bugs fixed in Firefox 95 and Firefox ESR 91.4 - Removed x-scheme-handler/ftp from MozillaFirefox.desktop (bsc#1193321)

    Affected packages

    Package

    Name: MozillaFirefox

    Purl: pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -91.4.0-152.9.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2021:3993-1 | CVE-DB