Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.883620
Categoría:CentOS Local Security Checks
Título:CentOS: Security Advisory for firefox (CESA-2021:5014)
Resumen:The remote host is missing an update for the 'firefox'; package(s) announced via the CESA-2021:5014 advisory.
Descripción:Summary:
The remote host is missing an update for the 'firefox'
package(s) announced via the CESA-2021:5014 advisory.

Vulnerability Insight:
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.

This update upgrades Firefox to version 91.4.0 ESR.

Security Fix(es):

* Mozilla: Memory safety bugs fixed in Firefox 95 and Firefox ESR 91.4

* Mozilla: URL leakage when navigating while executing asynchronous
function (CVE-2021-43536)

* Mozilla: Heap buffer overflow when using structured clone
(CVE-2021-43537)

* Mozilla: Missing fullscreen and pointer lock notification when requesting
both (CVE-2021-43538)

* Mozilla: GC rooting failure when calling wasm instance methods
(CVE-2021-43539)

* Mozilla: External protocol handler parameters were unescaped
(CVE-2021-43541)

* Mozilla: XMLHttpRequest error codes could have leaked the existence of an
external protocol handler (CVE-2021-43542)

* Mozilla: Bypass of CSP sandbox directive when embedding (CVE-2021-43543)

* Mozilla: Denial of Service when using the Location API in a loop
(CVE-2021-43545)

* Mozilla: Cursor spoofing could overlay user interface when native cursor
is zoomed (CVE-2021-43546)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Affected Software/OS:
'firefox' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2021-43536
Debian Security Information: DSA-5026 (Google Search)
https://www.debian.org/security/2021/dsa-5026
Debian Security Information: DSA-5034 (Google Search)
https://www.debian.org/security/2022/dsa-5034
https://security.gentoo.org/glsa/202202-03
https://security.gentoo.org/glsa/202208-14
https://bugzilla.mozilla.org/show_bug.cgi?id=1730120
https://www.mozilla.org/security/advisories/mfsa2021-52/
https://www.mozilla.org/security/advisories/mfsa2021-53/
https://www.mozilla.org/security/advisories/mfsa2021-54/
https://lists.debian.org/debian-lts-announce/2021/12/msg00030.html
https://lists.debian.org/debian-lts-announce/2022/01/msg00001.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-43537
https://bugzilla.mozilla.org/show_bug.cgi?id=1738237
Common Vulnerability Exposure (CVE) ID: CVE-2021-43538
https://bugzilla.mozilla.org/show_bug.cgi?id=1739091
Common Vulnerability Exposure (CVE) ID: CVE-2021-43539
https://bugzilla.mozilla.org/show_bug.cgi?id=1739683
Common Vulnerability Exposure (CVE) ID: CVE-2021-43541
https://bugzilla.mozilla.org/show_bug.cgi?id=1696685
Common Vulnerability Exposure (CVE) ID: CVE-2021-43542
https://bugzilla.mozilla.org/show_bug.cgi?id=1723281
Common Vulnerability Exposure (CVE) ID: CVE-2021-43543
https://bugzilla.mozilla.org/show_bug.cgi?id=1738418
Common Vulnerability Exposure (CVE) ID: CVE-2021-43545
https://bugzilla.mozilla.org/show_bug.cgi?id=1720926
Common Vulnerability Exposure (CVE) ID: CVE-2021-43546
https://bugzilla.mozilla.org/show_bug.cgi?id=1737751
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.