MGASA-2022-0271 - Updated firefox packages fix security vulnerability

Publication date: 29 Jul 2022
URL: https://advisories.mageia.org/MGASA-2022-0271.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-36318,
     CVE-2022-36319

When visiting directory listings for chrome:// URLs as source text, some
parameters were reflected (CVE-2022-36318).
When combining CSS properties for overflow and transform, the mouse cursor
could interact with different coordinates than displayed (CVE-2022-36319).

References:
- https://bugs.mageia.org/show_bug.cgi?id=30669
- https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/jYrL4b47r3A
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_81.html
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-29/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36318
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36319

SRPMS:
- 8/core/firefox-91.12.0-1.mga8
- 8/core/firefox-l10n-91.12.0-1.mga8

Mageia 2022-0271: firefox security update

When visiting directory listings for chrome:// URLs as source text, some parameters were reflected (CVE-2022-36318)

Summary

When visiting directory listings for chrome:// URLs as source text, some parameters were reflected (CVE-2022-36318). When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed (CVE-2022-36319).

References

- https://bugs.mageia.org/show_bug.cgi?id=30669

- https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/jYrL4b47r3A

- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_81.html

- https://www.mozilla.org/en-US/security/advisories/mfsa2022-29/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36318

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36319

Resolution

MGASA-2022-0271 - Updated firefox packages fix security vulnerability

SRPMS

- 8/core/firefox-91.12.0-1.mga8

- 8/core/firefox-l10n-91.12.0-1.mga8

Severity
Publication date: 29 Jul 2022
URL: https://advisories.mageia.org/MGASA-2022-0271.html
Type: security
CVE: CVE-2022-36318, CVE-2022-36319

Related News