Univention Bugzilla – Bug 55441
firefox-esr: Multiple issues (5.0)
Last modified: 2022-11-23 16:08:31 CET
New Debian firefox-esr 102.5.0esr-1~deb10u1 fixes: This update addresses the following issues: * Service Workers might have learned size of cross-origin media files (CVE-2022-45403) * Fullscreen notification bypass (CVE-2022-45404) * Use-after-free in InputStream implementation (CVE-2022-45405) * Use-after-free of a JavaScript Realm (CVE-2022-45406) * Fullscreen notification bypass via windowName (CVE-2022-45408) * Use-after-free in Garbage Collection (CVE-2022-45409) * ServiceWorker-intercepted requests bypassed SameSite cookie policy (CVE-2022-45410) * Cross-Site Tracing was possible via non-standard override headers (CVE-2022-45411) * Symlinks may resolve to partially uninitialized buffers (CVE-2022-45412) * Keystroke Side-Channel Leakage (CVE-2022-45416) * Custom mouse cursor could have been drawn over browser UI (CVE-2022-45418) * Iframe contents could be rendered outside the iframe (CVE-2022-45420) * Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5 (CVE-2022-45421)
--- mirror/ftp/pool/main/f/firefox-esr/firefox-esr_102.4.0esr-1~deb10u1.dsc +++ apt/ucs_5.0-0-errata5.0-2/source/firefox-esr_102.5.0esr-1~deb10u1.dsc @@ -1,3 +1,24 @@ +102.5.0esr-1~deb10u1 [Wed, 16 Nov 2022 09:39:25 +0100] Emilio Pozuelo Monfort <pochu@debian.org>: + + * Backport to buster. + +102.5.0esr-1 [Wed, 16 Nov 2022 06:20:30 +0900] Mike Hommey <glandium@debian.org>: + + * New upstream release. + * Fixes for mfsa2022-48, also known as: + CVE-2022-45403, CVE-2022-45404, CVE-2022-45405, CVE-2022-45406, + CVE-2022-45408, CVE-2022-45409, CVE-2022-45410, CVE-2022-45411, + CVE-2022-45412, CVE-2022-45416, CVE-2022-45418, CVE-2022-45420, + CVE-2022-45421. + + * debian/rules: + - Use internal libevent on buster. + - Invoke python with PYTHONDONTWRITEBYTECODE instead of -B. + + * ipc/chromium/src/third_party/libevent/linux/event2/event-config.h, + toolkit/crashreporter/client/ping.cpp: Avoid build bustage when + building against glibc 2.36 or newer. bz#1782988. + 102.4.0esr-1~deb10u1 [Wed, 19 Oct 2022 16:25:38 +0200] Emilio Pozuelo Monfort <pochu@debian.org>: * Backport to buster. Remaining changes: <http://piuparts.knut.univention.de/5.0-2/#2483631063684907410>
OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-2] 0f812309b2 Bug #55441: firefox-esr 102.5.0esr-1~deb10u1 doc/errata/staging/firefox-esr.yaml | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) [5.0-2] d028d42cc3 Bug #55441: firefox-esr 102.5.0esr-1~deb10u1 doc/errata/staging/firefox-esr.yaml | 40 +++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x495>