Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.883620
Kategorie:CentOS Local Security Checks
Titel:CentOS: Security Advisory for firefox (CESA-2021:5014)
Zusammenfassung:The remote host is missing an update for the 'firefox'; package(s) announced via the CESA-2021:5014 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'firefox'
package(s) announced via the CESA-2021:5014 advisory.

Vulnerability Insight:
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.

This update upgrades Firefox to version 91.4.0 ESR.

Security Fix(es):

* Mozilla: Memory safety bugs fixed in Firefox 95 and Firefox ESR 91.4

* Mozilla: URL leakage when navigating while executing asynchronous
function (CVE-2021-43536)

* Mozilla: Heap buffer overflow when using structured clone
(CVE-2021-43537)

* Mozilla: Missing fullscreen and pointer lock notification when requesting
both (CVE-2021-43538)

* Mozilla: GC rooting failure when calling wasm instance methods
(CVE-2021-43539)

* Mozilla: External protocol handler parameters were unescaped
(CVE-2021-43541)

* Mozilla: XMLHttpRequest error codes could have leaked the existence of an
external protocol handler (CVE-2021-43542)

* Mozilla: Bypass of CSP sandbox directive when embedding (CVE-2021-43543)

* Mozilla: Denial of Service when using the Location API in a loop
(CVE-2021-43545)

* Mozilla: Cursor spoofing could overlay user interface when native cursor
is zoomed (CVE-2021-43546)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Affected Software/OS:
'firefox' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2021-43536
Debian Security Information: DSA-5026 (Google Search)
https://www.debian.org/security/2021/dsa-5026
Debian Security Information: DSA-5034 (Google Search)
https://www.debian.org/security/2022/dsa-5034
https://security.gentoo.org/glsa/202202-03
https://security.gentoo.org/glsa/202208-14
https://bugzilla.mozilla.org/show_bug.cgi?id=1730120
https://www.mozilla.org/security/advisories/mfsa2021-52/
https://www.mozilla.org/security/advisories/mfsa2021-53/
https://www.mozilla.org/security/advisories/mfsa2021-54/
https://lists.debian.org/debian-lts-announce/2021/12/msg00030.html
https://lists.debian.org/debian-lts-announce/2022/01/msg00001.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-43537
https://bugzilla.mozilla.org/show_bug.cgi?id=1738237
Common Vulnerability Exposure (CVE) ID: CVE-2021-43538
https://bugzilla.mozilla.org/show_bug.cgi?id=1739091
Common Vulnerability Exposure (CVE) ID: CVE-2021-43539
https://bugzilla.mozilla.org/show_bug.cgi?id=1739683
Common Vulnerability Exposure (CVE) ID: CVE-2021-43541
https://bugzilla.mozilla.org/show_bug.cgi?id=1696685
Common Vulnerability Exposure (CVE) ID: CVE-2021-43542
https://bugzilla.mozilla.org/show_bug.cgi?id=1723281
Common Vulnerability Exposure (CVE) ID: CVE-2021-43543
https://bugzilla.mozilla.org/show_bug.cgi?id=1738418
Common Vulnerability Exposure (CVE) ID: CVE-2021-43545
https://bugzilla.mozilla.org/show_bug.cgi?id=1720926
Common Vulnerability Exposure (CVE) ID: CVE-2021-43546
https://bugzilla.mozilla.org/show_bug.cgi?id=1737751
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.