[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2023:0296 -- centos 7 firefox

ID: oval:org.secpod.oval:def:205997Date: (C)2023-02-07   (M)2024-03-27
Class: PATCHFamily: unix




Security Fix: Mozilla: libusrsctp library out of date Mozilla: Arbitrary file read from GTK drag and drop on Linux Mozilla: Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7 Mozilla: Malicious command could be hidden in devtools output Mozilla: URL being dragged from cross-origin iframe into same tab triggers navigation Mozilla: Content Security Policy wasn#39;t being correctly applied to WebSockets in WebWorkers Mozilla: Fullscreen notification bypass Mozilla: Calls to lt;codegt;console.loglt;/codegt; allowed bypasing Content Security Policy via format directive For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

Platform:
CentOS 7
Product:
firefox
Reference:
CESA-2023:0296
CVE-2022-46871
CVE-2023-23598
CVE-2023-23605
CVE-2023-23599
CVE-2023-23601
CVE-2023-23602
CVE-2022-46877
CVE-2023-23603
CVE    8
CVE-2022-46877
CVE-2022-46871
CVE-2023-23603
CVE-2023-23602
...

© SecPod Technologies