|
|
Log in / Subscribe / Register

Arch Linux alert ASA-202109-2 (firefox)

From:  Jonas Witschel via arch-security <arch-security@lists.archlinux.org>
To:  arch-security@lists.archlinux.org
Subject:  [ASA-202109-2] firefox: multiple issues
Date:  Wed, 15 Sep 2021 10:48:07 +0200
Message-ID:  <20210915084807.ejjfhrrelgolikd7@archlinux.org>
Cc:  Jonas Witschel <diabonas@archlinux.org>

Arch Linux Security Advisory ASA-202109-2 ========================================= Severity: High Date : 2021-09-14 CVE-ID : CVE-2021-38491 CVE-2021-38494 Package : firefox Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2350 Summary ======= The package firefox before version 92.0-1 is vulnerable to multiple issues including arbitrary code execution and insufficient validation. Resolution ========== Upgrade to 92.0-1. # pacman -Syu "firefox>=92.0-1" The problems have been fixed upstream in version 92.0. Workaround ========== None. Description =========== - CVE-2021-38491 (insufficient validation) In Firefox before version 92, mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. - CVE-2021-38494 (arbitrary code execution) Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and Mozilla presumes that with enough effort some of these could have been exploited to run arbitrary code. Impact ====== A remote attacker could execute arbitrary code through crafted web content, or load content over HTTP on a web page otherwise served through HTTPS. References ========== https://www.mozilla.org/security/advisories/mfsa2021-38/ https://bugzilla.mozilla.org/show_bug.cgi?id=1551886 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1723920%2... https://security.archlinux.org/CVE-2021-38491 https://security.archlinux.org/CVE-2021-38494


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds