144 lines
6.0 KiB
JSON
144 lines
6.0 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20247980",
|
|
"Version": "oval:org.altlinux.errata:def:20247980",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2024-7980: package `firefox-esr` update to version 115.11.0-alt1",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch p11"
|
|
],
|
|
"Products": [
|
|
"ALT Container"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2024-7980",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-7980",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2024-4367",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-4367",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2024-4767",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-4767",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2024-4768",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-4768",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2024-4769",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-4769",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2024-4770",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-4770",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2024-4777",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-4777",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades firefox-esr to version 115.11.0-alt1. \nSecurity Fix(es):\n\n * CVE-2024-4367: A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox \u003c 126, Firefox ESR \u003c 115.11, and Thunderbird \u003c 115.11.\n\n * CVE-2024-4767: If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox \u003c 126, Firefox ESR \u003c 115.11, and Thunderbird \u003c 115.11.\n\n * CVE-2024-4768: A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox \u003c 126, Firefox ESR \u003c 115.11, and Thunderbird \u003c 115.11.\n\n * CVE-2024-4769: When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox \u003c 126, Firefox ESR \u003c 115.11, and Thunderbird \u003c 115.11.\n\n * CVE-2024-4770: When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox \u003c 126, Firefox ESR \u003c 115.11, and Thunderbird \u003c 115.11.\n\n * CVE-2024-4777: Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox \u003c 126, Firefox ESR \u003c 115.11, and Thunderbird \u003c 115.11.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "Low",
|
|
"Rights": "Copyright 2024 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2024-05-19"
|
|
},
|
|
"Updated": {
|
|
"Date": "2024-05-19"
|
|
},
|
|
"BDUs": null,
|
|
"CVEs": [
|
|
{
|
|
"ID": "CVE-2024-4367",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-4367",
|
|
"Impact": "None",
|
|
"Public": "20240514"
|
|
},
|
|
{
|
|
"ID": "CVE-2024-4767",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-4767",
|
|
"Impact": "None",
|
|
"Public": "20240514"
|
|
},
|
|
{
|
|
"ID": "CVE-2024-4768",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-4768",
|
|
"Impact": "None",
|
|
"Public": "20240514"
|
|
},
|
|
{
|
|
"ID": "CVE-2024-4769",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-4769",
|
|
"Impact": "None",
|
|
"Public": "20240514"
|
|
},
|
|
{
|
|
"ID": "CVE-2024-4770",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-4770",
|
|
"Impact": "None",
|
|
"Public": "20240514"
|
|
},
|
|
{
|
|
"ID": "CVE-2024-4777",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-4777",
|
|
"Impact": "None",
|
|
"Public": "20240514"
|
|
}
|
|
],
|
|
"AffectedCPEs": {
|
|
"CPEs": [
|
|
"cpe:/o:alt:container:11"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20247980001",
|
|
"Comment": "firefox-esr is earlier than 0:115.11.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20247980002",
|
|
"Comment": "firefox-esr-config-privacy is earlier than 0:115.11.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20247980003",
|
|
"Comment": "firefox-esr-wayland is earlier than 0:115.11.0-alt1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |