MGASA-2024-0349

Source
https://advisories.mageia.org/MGASA-2024-0349.html
Import Source
https://advisories.mageia.org/MGASA-2024-0349.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0349
Related
Published
2024-11-09T05:17:41Z
Modified
2024-11-09T04:24:36Z
Summary
Updated nspr, nss, firefox & rust packages fix security vulnerabilities
Details

Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response. (CVE-2024-10461) Origin of permission prompt could be spoofed by long URL. (CVE-2024-10462) Cross origin video frame leak. (CVE-2024-10463) History interface could have been used to cause a Denial of Service condition in the browser. (CVE-2024-10464) Clipboard "paste" button persisted across tabs. (CVE-2024-10465) DOM push subscription message could hang Firefox. (CVE-2024-10466) Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4. (CVE-2024-10467)

References
Credits

Affected packages

Mageia:9 / nspr

Package

Name
nspr
Purl
pkg:rpm/mageia/nspr?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.36-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / nss

Package

Name
nss
Purl
pkg:rpm/mageia/nss?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.106.0-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
128.4.0-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
128.4.0-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / rust

Package

Name
rust
Purl
pkg:rpm/mageia/rust?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.76.0-3.mga9

Ecosystem specific

{
    "section": "core"
}