QID 174866

QID 174866: SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:0966-1)

This update for MozillaFirefox fixes the following issues:

- Firefox was updated to 78.9.0 ESR (MFSA 2021-11, bsc#1183942)
* CVE-2021-23981: Texture upload into an unbound backing buffer resulted
in an out-of-bound read
* CVE-2021-23982: Internal network hosts could have been probed by a
malicious webpage
* CVE-2021-23984: Malicious extensions could have spoofed popup
information
* CVE-2021-23987: Memory safety bugs

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:0966-1 to address this issue and obtain further details.

    CVEs related to QID 174866

    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:0966-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-March/008561.html