firefox-91.8.0-1.0.1.el7.AXS7

エラータID: AXSA:2022-3144:08

Release date: 
Wednesday, April 13, 2022 - 06:07
Subject: 
firefox-91.8.0-1.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.

This update upgrades Firefox to version 91.8.0 ESR.

Security Fix(es):

Mozilla: Use-after-free in NSSToken objects (CVE-2022-1097)
Mozilla: Out of bounds write due to unexpected WebAuthN Extensions
(CVE-2022-28281)
Mozilla: Memory safety bugs fixed in Firefox 99 and Firefox ESR 91.8
(CVE-2022-28289)
Mozilla: Use-after-free after VR Process destruction (CVE-2022-1196)
Mozilla: Use-after-free in DocumentL10n::TranslateDocument (CVE-2022-28282)
Mozilla: Incorrect AliasSet used in JIT Codegen (CVE-2022-28285)
Mozilla: Denial of Service via complex regular expressions (CVE-2022-24713)
Mozilla: iframe contents could be rendered outside the border
(CVE-2022-28286)

CVE(s):
CVE-2022-1097
CVE-2022-1196
CVE-2022-24713
CVE-2022-28281
CVE-2022-28282
CVE-2022-28285
CVE-2022-28286
CVE-2022-28289

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-91.8.0-1.0.1.el7.AXS7.src.rpm
    MD5: 412ec6eacdc74fb4ceb6acaaf8b33de3
    SHA-256: 9a0405280938eca7ade7622a688769ca086b67b203e67c5f4717647913c46880
    Size: 495.17 MB

Asianux Server 7 for x86_64
  1. firefox-91.8.0-1.0.1.el7.AXS7.x86_64.rpm
    MD5: aedbd1000077fdb9ef2a87591e62241f
    SHA-256: 9993a7302d498b152d7581694e53881eb84f8e62f4859f04c49e40d05532d377
    Size: 106.20 MB
  2. firefox-91.8.0-1.0.1.el7.AXS7.i686.rpm
    MD5: 75981829a1c54bffb1e74aa42bbd6f69
    SHA-256: 56c8b43cc878ec919aa15e8305554f154b02c3fa7477cc0b6c5191b1f1727ebd
    Size: 107.96 MB