Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202210-34 ] Mozilla Firefox: Multiple Vulnerabilities
Date: Mon, 31 Oct 2022 20:07:33
Message-Id: 166724667623.9.17443895077602995344@90bb6a0775af
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202210-34
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Mozilla Firefox: Multiple Vulnerabilities
9 Date: October 31, 2022
10 Bugs: #877773
11 ID: 202210-34
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Mozilla Firefox, the worst
19 of which could result in arbitrary code execution.
20
21 Background
22 ==========
23
24 Mozilla Firefox is a popular open-source web browser from the Mozilla
25 project.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-client/firefox < 102.4.0:esr >= 102.4.0:esr
34 < 106.0:rapid >= 106.0:rapid
35 2 www-client/firefox-bin < 102.4.0:esr >= 102.4.0:esr
36 < 106.0:rapid >= 106.0:rapid
37
38 Description
39 ===========
40
41 Multiple vulnerabilities have been discovered in Mozilla Firefox. Please
42 review the CVE identifiers referenced below for details.
43
44 Impact
45 ======
46
47 Please review the referenced CVE identifiers for details.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Mozilla Firefox ESR users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=www-client/firefox-102.4.0"
61
62 All Mozilla Firefox ESR binary users should upgrade to the latest
63 version:
64
65 # emerge --sync
66 # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-102.4.0"
67
68 All Mozilla Firefox users should upgrade to the latest version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose ">=www-client/firefox-106.0"
72
73 All Mozilla Firefox binary users should upgrade to the latest version:
74
75 # emerge --sync
76 # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-106.0"
77
78 References
79 ==========
80
81 [ 1 ] CVE-2022-42927
82 https://nvd.nist.gov/vuln/detail/CVE-2022-42927
83 [ 2 ] CVE-2022-42928
84 https://nvd.nist.gov/vuln/detail/CVE-2022-42928
85 [ 3 ] CVE-2022-42929
86 https://nvd.nist.gov/vuln/detail/CVE-2022-42929
87 [ 4 ] CVE-2022-42930
88 https://nvd.nist.gov/vuln/detail/CVE-2022-42930
89 [ 5 ] CVE-2022-42931
90 https://nvd.nist.gov/vuln/detail/CVE-2022-42931
91 [ 6 ] CVE-2022-42932
92 https://nvd.nist.gov/vuln/detail/CVE-2022-42932
93
94 Availability
95 ============
96
97 This GLSA and any updates to it are available for viewing at
98 the Gentoo Security Website:
99
100 https://security.gentoo.org/glsa/202210-34
101
102 Concerns?
103 =========
104
105 Security is a primary focus of Gentoo Linux and ensuring the
106 confidentiality and security of our users' machines is of utmost
107 importance to us. Any security concerns should be addressed to
108 security@g.o or alternatively, you may file a bug at
109 https://bugs.gentoo.org.
110
111 License
112 =======
113
114 Copyright 2022 Gentoo Foundation, Inc; referenced text
115 belongs to its owner(s).
116
117 The contents of this document are licensed under the
118 Creative Commons - Attribution / Share Alike license.
119
120 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature