Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/6760FD74984CA96BCB5D838EB9D98F43
HistoryFeb 16, 2022 - 12:00 a.m.

Security fix for the ALT Linux 10 package firefox-esr version 91.6.0-alt1

2022-02-1600:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
14

0.002 Low

EPSS

Percentile

52.6%

91.6.0-alt1 built Feb. 16, 2022 Pavel Vasenkov in task #295122

Feb. 9, 2022 Pavel Vasenkov

- New ESR version.
- Security fixes:
  + CVE-2022-22753 Privilege Escalation to SYSTEM on Windows via Maintenance Service
  + CVE-2022-22754 Extensions could have bypassed permission confirmation during update
  + CVE-2022-22756 Drag and dropping an image could have resulted in the dropped object being an executable
  + CVE-2022-22759 Sandboxed iframes could have executed script if the parent appended elements
  + CVE-2022-22760 Cross-Origin responses could be distinguished between script and non-script content-types
  + CVE-2022-22761 frame-ancestors Content Security Policy directive was not enforced for framed extension pages
  + CVE-2022-22763 Script Execution during invalid object state
  + CVE-2022-22764 Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6