firefox-91.9.0-1.el9.ML.1

エラータID: AXSA:2022-3990:29

Release date: 
Wednesday, November 2, 2022 - 09:13
Subject: 
firefox-91.9.0-1.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 91.9.0 ESR.

Security Fix(es):

* Mozilla: Bypassing permission prompt in nested browsing contexts (CVE-2022-29909)
* Mozilla: iframe Sandbox bypass (CVE-2022-29911)
* Mozilla: Fullscreen notification bypass using popups (CVE-2022-29914)
* Mozilla: Leaking browser history with CSS variables (CVE-2022-29916)
* Mozilla: Memory safety bugs fixed in Firefox 100 and Firefox ESR 91.9 (CVE-2022-29917)
* Mozilla: Reader mode bypassed SameSite cookies (CVE-2022-29912)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-29909
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2022-29911
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2022-29912
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2022-29914
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2022-29916
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2022-29917
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-91.9.0-1.el9.ML.1.src.rpm
    MD5: 1a3e2efa5df1e400aacc06dfd129069b
    SHA-256: 0d898f66153bd2e851e0f303f0b7cbffd8e8c24ea4de959b498e3b8ce99afb52
    Size: 495.24 MB

Asianux Server 9 for x86_64
  1. firefox-91.9.0-1.el9.ML.1.x86_64.rpm
    MD5: bf94fcf116a1314c2d89ba5de9ee1858
    SHA-256: 7137c7f000414837431feac874ab3d4df12224e8582120c568ce410e79700403
    Size: 103.33 MB