Advisories ยป MGASA-2024-0189

Updated nss & firefox packages fix security vulnerabilities

Publication date: 21 May 2024
Modification date: 21 May 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-4367 , CVE-2024-4767 , CVE-2024-4768 , CVE-2024-4769 , CVE-2024-4770 , CVE-2024-4777

Description

Arbitrary JavaScript execution in PDF.js. (CVE-2024-4367)
IndexedDB files retained in private browsing mode. (CVE-2024-4767)
Potential permissions request bypass via clickjacking. (CVE-2024-4768)
Cross-origin responses could be distinguished between script and
non-script content-types. (CVE-2024-4769)
Use-after-free could occur when printing to PDF. (CVE-2024-4770)
Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and
Thunderbird 115.11. (CVE-2024-4777)
                

References

SRPMS

9/core