-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2022:5766-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:5766 Issue date: 2022-08-01 CVE Names: CVE-2022-2505 CVE-2022-36318 CVE-2022-36319 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - ppc64le, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 91.12.0 ESR. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 103 and 102.1 (CVE-2022-2505) * Mozilla: Directory indexes for bundled resources reflected URL parameters (CVE-2022-36318) * Mozilla: Mouse Position spoofing with CSS transforms (CVE-2022-36319) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2111907 - CVE-2022-36319 Mozilla: Mouse Position spoofing with CSS transforms 2111908 - CVE-2022-36318 Mozilla: Directory indexes for bundled resources reflected URL parameters 2111910 - CVE-2022-2505 Mozilla: Memory safety bugs fixed in Firefox 103 and 102.1 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.1): Source: firefox-91.12.0-2.el8_1.src.rpm ppc64le: firefox-91.12.0-2.el8_1.ppc64le.rpm firefox-debuginfo-91.12.0-2.el8_1.ppc64le.rpm firefox-debugsource-91.12.0-2.el8_1.ppc64le.rpm x86_64: firefox-91.12.0-2.el8_1.x86_64.rpm firefox-debuginfo-91.12.0-2.el8_1.x86_64.rpm firefox-debugsource-91.12.0-2.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-2505 https://access.redhat.com/security/cve/CVE-2022-36318 https://access.redhat.com/security/cve/CVE-2022-36319 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYuqtD9zjgjWX9erEAQiVVBAAlwFmT2vc3sENgpmZ+8/q8ZVoBTf1mPDw uncOUQpxdt2F09swMu+yigMmxl/bhhOY6rpBh3pgWswkpfKRAuNDmDZCmeyjQv7C UcR+DOVggFiSrwt2SAbWLEnOE6+H6gddpyXIZqaUcIesEtopHy65ZN51pZMCv9HF D2s63iapGQJ3/ZsiQBEGWpxsnGbP2lNCc9GYtXXAJdj8EcBX5bBCCRxD3QUtT0EW 2M6RDsUJOp1XndO4hQ7w4EuMbqKyUb2/rAywSpgrAOksLscBz+m/JcXraiERz0IB DzER4GBXPhZshALzWhHGJbOsezodYMureyHdusm/KLF233d+wQsfirOojt+eGQ40 NFvZcxBukRViXILyF8DCrxARN5zDqEJDB6NNZ0BolSVLLGJTXYk9eb5iQRCQGI/s sCL8DpfGyCq09ZmvWvm9oQJYj5UG1b0D2MWHN5UT4zL2rRqEdhcSgVkEac2HAg04 pyjxlcfHCat48g2UxjdTgRiQ8p0Ugaw1kTRq2QmCzceEfWAJTg7YUGJJYp9e56jq ihWOLc0JUcD3L2GRKVWmi7RhI+j/ubzS58g+mOOdFB/hZm0xckhrYx86O+Nm1BiA pjjt5rPE+qN87KTYRD/89Cq7xqKAZ//Gd/tdF6F+21YD/9jYFzEftiHzZ4kuWi+W FYZF4CvZp00