Bugzilla – Bug 1188275
VUL-0: MozillaFirefox,MozillaThunderbird: update to 90 and 78.12.0esr
Last modified: 2022-09-06 16:44:57 UTC
Mozilla Foundation Security Advisory 2021-28 Security Vulnerabilities fixed in Firefox 90 [0]: - CVE-2021-29970: Use-after-free in accessibility features of a document - CVE-2021-29971: Granted permissions only compared host; omitting scheme and port on Android - CVE-2021-30547: Out of bounds write in ANGLE - CVE-2021-29972: Use of out-of-date library included use-after-free vulnerability - CVE-2021-29973: Password autofill on HTTP websites was enabled without user interaction on Android - CVE-2021-29974: HSTS errors could be overridden when network partitioning was enabled - CVE-2021-29975: Text message could be overlaid on top of another website - CVE-2021-29976: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 - CVE-2021-29977: Memory safety bugs fixed in Firefox 90 Mozilla Foundation Security Advisory 2021-29 Security Vulnerabilities fixed in Firefox ESR 78.12 [1]: - CVE-2021-29970: Use-after-free in accessibility features of a document - CVE-2021-30547: Out of bounds write in ANGLE - CVE-2021-30547: Out of bounds write in ANGLE [0] https://www.mozilla.org/en-US/security/advisories/mfsa2021-28/ [1] https://www.mozilla.org/en-US/security/advisories/mfsa2021-29/
copy & paste error: (In reply to Robert Frohl from comment #0) > Mozilla Foundation Security Advisory 2021-29 > > Security Vulnerabilities fixed in Firefox ESR 78.12 [1]: > > - CVE-2021-29970: Use-after-free in accessibility features of a document > - CVE-2021-30547: Out of bounds write in ANGLE - CVE-2021-29976: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 > > [1] https://www.mozilla.org/en-US/security/advisories/mfsa2021-29/
This is an autogenerated message for OBS integration: This bug (1188275) was mentioned in https://build.opensuse.org/request/show/906332 Factory / MozillaThunderbird
This is an autogenerated message for OBS integration: This bug (1188275) was mentioned in https://build.opensuse.org/request/show/906586 Factory / MozillaFirefox
SUSE-SU-2021:14766-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): MozillaFirefox-78.12.0-78.134.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): MozillaFirefox-78.12.0-78.134.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:2389-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): MozillaFirefox-78.12.0-112.65.1 SUSE OpenStack Cloud Crowbar 8 (src): MozillaFirefox-78.12.0-112.65.1 SUSE OpenStack Cloud 9 (src): MozillaFirefox-78.12.0-112.65.1 SUSE OpenStack Cloud 8 (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Server for SAP 12-SP3 (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Server 12-SP5 (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Server 12-SP3-LTSS (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Server 12-SP3-BCL (src): MozillaFirefox-78.12.0-112.65.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): MozillaFirefox-78.12.0-112.65.1 HPE Helion Openstack 8 (src): MozillaFirefox-78.12.0-112.65.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:2393-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: openSUSE Leap 15.3 (src): MozillaFirefox-78.12.0-8.46.1
SUSE-SU-2021:2393-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): MozillaFirefox-78.12.0-8.46.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src): MozillaFirefox-78.12.0-8.46.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1066-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: openSUSE Leap 15.2 (src): MozillaFirefox-78.12.0-lp152.2.61.1
openSUSE-SU-2021:2458-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29969,CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: openSUSE Leap 15.3 (src): MozillaThunderbird-78.12.0-8.33.1
SUSE-SU-2021:2458-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29969,CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 15-SP3 (src): MozillaThunderbird-78.12.0-8.33.1 SUSE Linux Enterprise Workstation Extension 15-SP2 (src): MozillaThunderbird-78.12.0-8.33.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:2478-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: SUSE Manager Server 4.0 (src): MozillaFirefox-78.12.0-3.147.1 SUSE Manager Retail Branch Server 4.0 (src): MozillaFirefox-78.12.0-3.147.1 SUSE Manager Proxy 4.0 (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise Server for SAP 15 (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise Server 15-LTSS (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): MozillaFirefox-78.12.0-3.147.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): MozillaFirefox-78.12.0-3.147.1 SUSE Enterprise Storage 6 (src): MozillaFirefox-78.12.0-3.147.1 SUSE CaaS Platform 4.0 (src): MozillaFirefox-78.12.0-3.147.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1091-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1188275 CVE References: CVE-2021-29969,CVE-2021-29970,CVE-2021-29976,CVE-2021-30547 JIRA References: Sources used: openSUSE Leap 15.2 (src): MozillaThunderbird-78.12.0-lp152.2.48.2
done