Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/F0223DBB6A743FCA0D21915E7414F53B
HistoryDec 22, 2022 - 12:00 a.m.

Security fix for the ALT Linux 10 package firefox-esr version 102.6.0-alt1

2022-12-2200:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
20
alt linux 10
firefox-esr
security fixes
webgl
arbitrary file read
memory corruption
drag and dropped
download protections
memory safety bugs

EPSS

0.011

Percentile

84.8%

102.6.0-alt1 built Dec. 22, 2022 Pavel Vasenkov in task #311776

Dec. 14, 2022 Pavel Vasenkov

- New ESR version.
- Security fixes
  + CVE-2022-46880 Use-after-free in WebGL
  + CVE-2022-46872 Arbitrary file read from a compromised content process
  + CVE-2022-46881 Memory corruption in WebGL
  + CVE-2022-46874 Drag and Dropped Filenames could have been truncated to malicious extensions
  + CVE-2022-46875 Download Protections were bypassed by .atloc and .ftploc files on Mac OS
  + CVE-2022-46882 Use-after-free in WebGL
  + CVE-2022-46878 Memory safety bugs fixed in Firefox 108 and Firefox ESR 102.6