Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2022.0378
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2022-0378)
Summary:The remote host is missing an update for the 'firefox, firefox-l10n, nss' package(s) announced via the MGASA-2022-0378 advisory.
Description:Summary:
The remote host is missing an update for the 'firefox, firefox-l10n, nss' package(s) announced via the MGASA-2022-0378 advisory.

Vulnerability Insight:
A same-origin policy violation could have allowed the theft of
cross-origin URL entries, leaking the result of a redirect, via
performance.getEntries() (CVE-2022-42927).

Certain types of allocations were missing annotations that, if the Garbage
Collector was in a specific state, could have lead to memory corruption in
the JS engine and a potentially exploitable crash (CVE-2022-42928).

If a website called window.print() in a particular way, it could cause a
denial of service of the browser, which may persist beyond browser restart
depending on the user's session restore settings (CVE-2022-42929).

Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported
memory safety bugs present in Firefox ESR 102.3. Some of these bugs showed
evidence of memory corruption and we presume that with enough effort some
of these could have been exploited to run arbitrary code (CVE-2022-42932).

Affected Software/OS:
'firefox, firefox-l10n, nss' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-42927
https://bugzilla.mozilla.org/show_bug.cgi?id=1789128
https://www.mozilla.org/security/advisories/mfsa2022-44/
https://www.mozilla.org/security/advisories/mfsa2022-45/
https://www.mozilla.org/security/advisories/mfsa2022-46/
Common Vulnerability Exposure (CVE) ID: CVE-2022-42928
https://bugzilla.mozilla.org/show_bug.cgi?id=1791520
Common Vulnerability Exposure (CVE) ID: CVE-2022-42929
https://bugzilla.mozilla.org/show_bug.cgi?id=1789439
Common Vulnerability Exposure (CVE) ID: CVE-2022-42932
Memory safety bugs fixed in Firefox 106 and Firefox ESR 102.4
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1789729%2C1791363%2C1792041
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.