1
0
MozillaFirefox/firefox-102.0.source.tar.xz.asc
Wolfgang Rosenauer a756387aa3 - Firefox 102.0
* You can now disable automatic opening of the download panel
    every time a new download starts
  * Firefox now mitigates query parameter tracking when navigating
    sites in ETP strict mode
  * Improved security by moving audio decoding into a separate
    process with stricter sandboxing, thus improving process isolation
  * https://www.mozilla.org/en-US/firefox/102.0/releasenotes
  MFSA 2022-24 (bsc#1200793)
  * CVE-2022-34479 (bmo#1745595)
    A popup window could be resized in a way to overlay the
    address bar with web content
  * CVE-2022-34470 (bmo#1765951)
    Use-after-free in nsSHistory
  * CVE-2022-34468 (bmo#1768537)
    CSP sandbox header without `allow-scripts` can be bypassed
    via retargeted javascript: URI
  * CVE-2022-34482 (bmo#845880)
    Drag and drop of malicious image could have led to malicious
    executable and potential code execution
  * CVE-2022-34483 (bmo#1335845)
    Drag and drop of malicious image could have led to malicious
    executable and potential code execution
  * CVE-2022-34476 (bmo#1387919)
    ASN.1 parser could have been tricked into accepting malformed ASN.1
  * CVE-2022-34481 (bmo#1483699, bmo#1497246)
    Potential integer overflow in ReplaceElementsAt
  * CVE-2022-34474 (bmo#1677138)
    Sandboxed iframes could redirect to external schemes
  * CVE-2022-34469 (bmo#1721220)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaFirefox?expand=0&rev=983
2022-06-29 07:44:18 +00:00

17 lines
833 B
Plaintext

-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEQ2D+IQnEl2MYb44h6+QekPbxL20FAmK0EykACgkQ6+QekPbx
L21IKhAAlliNZ1t49JNYbvinEpFprZBGjvpQqPv9Ydl9sTgjQlD9KMzeSWOccFtR
1IY65ANkbIq53nETF0bxT3ON+KY/r8J8BZ6VkqNFx6sJE7XoLfTu8VUoTqoG7crs
XZXhBFDBdJ0dn1rOqE+K3Jv8e+yIcUSmZrBZSARk0o4wGNx9kWO93xPTCwiB2NnD
XPIQOAVHmENhQ7U0X5zHMymnCWHuFcsfjVMoqh5wtUNVt3DLwCFipaDPAAH6EhN5
jRwzhH6uusaRzi8fRpQjO++kN+aFTPHFnP0Yg6zlqFN4N0r0PtvO7kP8y1rH8OoF
+ZpJyvzO4Bpx/y1/zW5IwdKUeeTPBIYmHQLITyktR06JzLiT/lEENcL0OaFABV9L
gOsYAxVFlX9fhwEWt4posW3oQGM8qchR37bHeaI1Ssy2R8BFWcZaZR3QubcnxCUG
rfdq4htPjFMHI+s/7A3Xlc7tAcr+VwUCiBmjTOSNCdoZrKor/ahD2Wjiq6AjQfcS
2bWQBUFY7j8d0GutvHnxJGH3z33YG0lBkzzCPPIxYIcMUkp3CwMrCmlBjRzcm1p8
jXHGuV/yfWt7soEZ8VMKCD9/bjZ7RI9y/HLprzYbNphrhOl1t0aEG3htqX2n7sRP
Wtu0zhOS/7qX+ZzpeIqi2ldEQ+VjpE6bkiFmQVCi8EXC5wnhF/M=
=6YnI
-----END PGP SIGNATURE-----