Alpine: multiple firefox-esr packages: security update to 91.3.0-r0

critical Tenable Cloud Security Plugin ID 404457

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass
restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects
Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. (CVE-2021-38503)

- When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-
free could have resulted, leading to memory corruption and a potentially exploitable crash. This
vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. (CVE-2021-38504)

- Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record
data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios.
Applications that wish to prevent copied data from being recorded in Cloud History must use specific
clipboard formats; and Firefox before versions 94 and ESR 91.3 did not implement them. This could have
caused sensitive data to be recorded to a user's Microsoft account. *This bug only affects Firefox for
Windows 10+ with Cloud Clipboard enabled. Other operating systems are unaffected.*. This vulnerability
affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. (CVE-2021-38505)

- Through a series of navigations, Firefox could have entered fullscreen mode without notification or
warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This
vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. (CVE-2021-38506)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-38503

https://security.alpinelinux.org/vuln/CVE-2021-38504

https://security.alpinelinux.org/vuln/CVE-2021-38505

https://security.alpinelinux.org/vuln/CVE-2021-38506

https://security.alpinelinux.org/vuln/CVE-2021-38507

https://security.alpinelinux.org/vuln/CVE-2021-38508

https://security.alpinelinux.org/vuln/CVE-2021-38509

https://security.alpinelinux.org/vuln/CVE-2021-38510

Plugin Details

Severity: Critical

ID: 404457

Version: Revision 1.28

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 95.11

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-38503

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 11/2/2021

Reference Information

CVE: CVE-2021-38503, CVE-2021-38504, CVE-2021-38505, CVE-2021-38506, CVE-2021-38507, CVE-2021-38508, CVE-2021-38509, CVE-2021-38510