Alpine: multiple firefox packages: security update to 84.0.1-r0

critical Tenable Cloud Security Plugin ID 404376

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must
ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted
in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects
Firefox < 84. (CVE-2020-26972)

- Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain
potentially sensitive information from process memory via a crafted HTML page. (CVE-2020-16042)

- Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow
on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR <
78.6. (CVE-2020-26971)

- Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This
could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6,
and Firefox ESR < 78.6. (CVE-2020-26973)

See Also

https://security.alpinelinux.org/vuln/CVE-2020-16042

https://security.alpinelinux.org/vuln/CVE-2020-26971

https://security.alpinelinux.org/vuln/CVE-2020-26972

https://security.alpinelinux.org/vuln/CVE-2020-26973

https://security.alpinelinux.org/vuln/CVE-2020-26974

https://security.alpinelinux.org/vuln/CVE-2020-26975

https://security.alpinelinux.org/vuln/CVE-2020-26976

https://security.alpinelinux.org/vuln/CVE-2020-26977

https://security.alpinelinux.org/vuln/CVE-2020-26978

https://security.alpinelinux.org/vuln/CVE-2020-26979

https://security.alpinelinux.org/vuln/CVE-2020-35111

https://security.alpinelinux.org/vuln/CVE-2020-35112

https://security.alpinelinux.org/vuln/CVE-2020-35113

https://security.alpinelinux.org/vuln/CVE-2020-35114

Plugin Details

Severity: Critical

ID: 404376

Version: Revision 1.28

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-26972

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 12/2/2020

Reference Information

CVE: CVE-2020-16042, CVE-2020-26971, CVE-2020-26972, CVE-2020-26973, CVE-2020-26974, CVE-2020-26975, CVE-2020-26976, CVE-2020-26977, CVE-2020-26978, CVE-2020-26979, CVE-2020-35111, CVE-2020-35112, CVE-2020-35113, CVE-2020-35114

IAVA: 2020-A-0575-S, 2021-A-0051-S