Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/116FE8C50C4A8E5B752FCCA93D54E1E2
HistoryNov 09, 2021 - 12:00 a.m.

Security fix for the ALT Linux 10 package firefox-esr version 91.3.0-alt1

2021-11-0900:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
6

0.005 Low

EPSS

Percentile

76.3%

91.3.0-alt1 built Nov. 9, 2021 Andrey Cherepanov in task #288753

Nov. 2, 2021 Andrey Cherepanov

- New ESR version.
- Security fixes:
  + CVE-2021-38503 iframe sandbox rules did not apply to XSLT stylesheets
  + CVE-2021-38504 Use-after-free in file picker dialog
  + CVE-2021-38505 Windows 10 Cloud Clipboard may have recorded sensitive user data
  + CVE-2021-38506 Firefox could be coaxed into going into fullscreen mode without notification or warning
  + CVE-2021-38507 Opportunistic Encryption in HTTP2 could be used to bypass the Same-Origin-Policy on services hosted on other ports
  + CVE-2021-38508 Permission Prompt could be overlaid, resulting in user confusion and potential spoofing
  + CVE-2021-38509 Javascript alert box could have been spoofed onto an arbitrary domain
  + CVE-2021-38510 Download Protections were bypassed by .inetloc files on Mac OS