Bug 55441 - firefox-esr: Multiple issues (5.0)
firefox-esr: Multiple issues (5.0)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 5.0
All Linux
: P3 normal (vote)
: UCS 5.0-2-errata
Assigned To: Quality Assurance
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-21 09:06 CET by Quality Assurance
Modified: 2022-11-23 16:08 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2022-11-21 09:06:43 CET
New Debian firefox-esr 102.5.0esr-1~deb10u1 fixes:
This update addresses the following issues:
* Service Workers might have learned size of cross-origin media files  (CVE-2022-45403)
* Fullscreen notification bypass (CVE-2022-45404)
* Use-after-free in InputStream implementation (CVE-2022-45405)
* Use-after-free of a JavaScript Realm (CVE-2022-45406)
* Fullscreen notification bypass via windowName (CVE-2022-45408)
* Use-after-free in Garbage Collection (CVE-2022-45409)
* ServiceWorker-intercepted requests bypassed SameSite cookie policy  (CVE-2022-45410)
* Cross-Site Tracing was possible via non-standard override headers  (CVE-2022-45411)
* Symlinks may resolve to partially uninitialized buffers (CVE-2022-45412)
* Keystroke Side-Channel Leakage (CVE-2022-45416)
* Custom mouse cursor could have been drawn over browser UI (CVE-2022-45418)
* Iframe contents could be rendered outside the iframe (CVE-2022-45420)
* Memory safety bugs fixed in Firefox 107 and Firefox ESR 102.5  (CVE-2022-45421)
Comment 1 Quality Assurance univentionstaff 2022-11-21 10:00:18 CET
--- mirror/ftp/pool/main/f/firefox-esr/firefox-esr_102.4.0esr-1~deb10u1.dsc
+++ apt/ucs_5.0-0-errata5.0-2/source/firefox-esr_102.5.0esr-1~deb10u1.dsc
@@ -1,3 +1,24 @@
+102.5.0esr-1~deb10u1 [Wed, 16 Nov 2022 09:39:25 +0100] Emilio Pozuelo Monfort <pochu@debian.org>:
+
+  * Backport to buster.
+
+102.5.0esr-1 [Wed, 16 Nov 2022 06:20:30 +0900] Mike Hommey <glandium@debian.org>:
+
+  * New upstream release.
+  * Fixes for mfsa2022-48, also known as:
+    CVE-2022-45403, CVE-2022-45404, CVE-2022-45405, CVE-2022-45406,
+    CVE-2022-45408, CVE-2022-45409, CVE-2022-45410, CVE-2022-45411,
+    CVE-2022-45412, CVE-2022-45416, CVE-2022-45418, CVE-2022-45420,
+    CVE-2022-45421.
+
+  * debian/rules:
+    - Use internal libevent on buster.
+    - Invoke python with PYTHONDONTWRITEBYTECODE instead of -B.
+
+  * ipc/chromium/src/third_party/libevent/linux/event2/event-config.h,
+    toolkit/crashreporter/client/ping.cpp: Avoid build bustage when
+    building against glibc 2.36 or newer. bz#1782988.
+
 102.4.0esr-1~deb10u1 [Wed, 19 Oct 2022 16:25:38 +0200] Emilio Pozuelo Monfort <pochu@debian.org>:
 
   * Backport to buster. Remaining changes:

<http://piuparts.knut.univention.de/5.0-2/#2483631063684907410>
Comment 2 Philipp Hahn univentionstaff 2022-11-22 08:50:36 CET
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[5.0-2] 0f812309b2 Bug #55441: firefox-esr 102.5.0esr-1~deb10u1
 doc/errata/staging/firefox-esr.yaml | 15 +++++++--------
 1 file changed, 7 insertions(+), 8 deletions(-)

[5.0-2] d028d42cc3 Bug #55441: firefox-esr 102.5.0esr-1~deb10u1
 doc/errata/staging/firefox-esr.yaml | 40 +++++++++++++++++++++++++++++++++++++
 1 file changed, 40 insertions(+)