Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/26C26BC08F581183AF3E26775831702F
HistoryJun 29, 2022 - 12:00 a.m.

Security fix for the ALT Linux 10 package firefox-esr version 91.11.0-alt1

2022-06-2900:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
17

0.004 Low

EPSS

Percentile

73.2%

June 29, 2022 Pavel Vasenkov 91.11.0-alt1

- New ESR version.
- Security fixes:
  + CVE-2022-34479 A popup window could be resized in a way to overlay the address bar with web content
  + CVE-2022-34470 Use-after-free in nsSHistory
  + CVE-2022-34468 CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI
  + CVE-2022-34481 Potential integer overflow in ReplaceElementsAt
  + CVE-2022-31744 CSP bypass enabling stylesheet injection
  + CVE-2022-34472 Unavailable PAC file resulted in OCSP requests being blocked
  + CVE-2022-34478 Microsoft protocols can be attacked if a user accepts a prompt
  + CVE-2022-2200 Undesired attributes could be set as part of prototype pollution
  + CVE-2022-34484 Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11