QID 174740

Date Published: 2021-04-19

QID 174740: SUSE Enterprise Linux Security update for MozillaFirefox (SUSE-SU-2021:0246-1)



This update for MozillaFirefox fixes the following issues:

- Firefox Extended Support Release 78.7.0 ESR (MFSA 2021-04, bsc#1181414)
* CVE-2021-23953: Fixed a Cross-origin information leakage via
redirected PDF requests
* CVE-2021-23954: Fixed a type confusion when using logical assignment
operators in JavaScript switch statements
* CVE-2020-26976: Fixed an issue where HTTPS pages could have been
intercepted by a registered service worker when they should not have
been
* CVE-2021-23960: Fixed a use-after-poison for incorrectly redeclared
JavaScript variables during GC
* CVE-2021-23964: Fixed Memory safety bugs


Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: https://lists.suse.com/pipermail/sle-security-updates/2021-January/008257.html to address this issue and obtain further details.
    Software Advisories
    Advisory ID Software Component Link