This update for MozillaFirefox fixes the following issues:
This update contains the Firefox Extended Support Release 91.2.0 ESR.
Firefox Extended Support Release 91.2.0 ESR
Fixed: Various stability, functionality, and security fixes MFSA 2021-45 (bsc#1191332)
CVE-2021-38496: Use-after-free in MessageTask
CVE-2021-38497: Validation message could have been overlaid on another origin
CVE-2021-38498: Use-after-free of nsLanguageAtomService object
CVE-2021-32810: Data race in crossbeam-deque
https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-pqqp-xmhj-wgcw)
CVE-2021-38500 (bmo#1725854, bmo#1728321) Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2
CVE-2021-38501 (bmo#1685354, bmo#1715755, bmo#1723176) Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2
MFSA 2021-40 (bsc#1190269, bsc#1190274):
mk: URL scheme could load Internet ExplorerFirefox Extended Support Release 91.0.1 ESR
Firefox Extended Support Release 91.0 ESR
New: Some of the highlights of the new Extended Support Release are:
Changed: Firefox no longer supports Adobe Flash. There is no setting available to re-enable Flash support.
Enterprise: Various bug fixes and new policies have been implemented in the latest version of Firefox. See more details in the Firefox for Enterprise 91 Release Notes.
MFSA 2021-33 (bsc#1188891):
CVE-2021-29986: Race condition when resolving DNS names could have led to memory corruption
CVE-2021-29981: Live range splitting could have led to conflicting assignments in the JIT
CVE-2021-29988: Memory corruption as a result of incorrect style treatment
CVE-2021-29983: Firefox for Android could get stuck in fullscreen mode
CVE-2021-29984: Incorrect instruction reordering during JIT optimization
CVE-2021-29980: Uninitialized memory in a canvas object could have led to memory corruption
CVE-2021-29987: Users could have been tricked into accepting unwanted permissions on Linux
CVE-2021-29985: Use-after-free media channels
CVE-2021-29982: Single bit data leak due to incorrect JIT optimization and type confusion
CVE-2021-29989: Memory safety bugs fixed in Firefox 91 and Firefox ESR 78.13
CVE-2021-29990: Memory safety bugs fixed in Firefox 91
This update was imported from the SUSE:SLE-15:Update update project.
{
"binaries": [
{
"MozillaFirefox": "91.2.0-lp152.2.67.1",
"MozillaFirefox-branding-upstream": "91.2.0-lp152.2.67.1",
"MozillaFirefox-devel": "91.2.0-lp152.2.67.1",
"MozillaFirefox-translations-common": "91.2.0-lp152.2.67.1",
"MozillaFirefox-translations-other": "91.2.0-lp152.2.67.1",
"rust-cbindgen": "0.19.0-lp152.2.7.1"
}
]
}
{
"binaries": [
{
"MozillaFirefox": "91.2.0-lp152.2.67.1",
"MozillaFirefox-branding-upstream": "91.2.0-lp152.2.67.1",
"MozillaFirefox-devel": "91.2.0-lp152.2.67.1",
"MozillaFirefox-translations-common": "91.2.0-lp152.2.67.1",
"MozillaFirefox-translations-other": "91.2.0-lp152.2.67.1",
"rust-cbindgen": "0.19.0-lp152.2.7.1"
}
]
}