SUSE SLES15: MozillaFirefox / MozillaFirefox-branding-SLE / MozillaFirefox-devel / etc (SUSE-SU-2021:3331-1)

critical Nessus Plugin ID 154003

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2021:3331-1 advisory.

This update contains the Firefox Extended Support Release 91.2.0 ESR.

Firefox Extended Support Release 91.2.0 ESR

* Fixed: Various stability, functionality, and security fixes MFSA 2021-45 (bsc#1191332)
* CVE-2021-38496: Use-after-free in MessageTask
* CVE-2021-38497: Validation message could have been overlaid on another origin
* CVE-2021-38498: Use-after-free of nsLanguageAtomService object
* CVE-2021-32810: Data race in crossbeam-deque

https://github.com/crossbeam-rs/crossbeam/security/advisories/GHSA-pqqp-xmhj-wgcw)

* CVE-2021-38500 (bmo#1725854, bmo#1728321) Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2
* CVE-2021-38501 (bmo#1685354, bmo#1715755, bmo#1723176) Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2

- Fixed crash in FIPS mode (bsc#1190710)

* Fixed: Various stability, functionality, and security fixes

MFSA 2021-40 (bsc#1190269, bsc#1190274):

* CVE-2021-38492: Navigating to `mk:` URL scheme could load Internet Explorer
* CVE-2021-38495: Memory safety bugs fixed in Firefox 92 and Firefox ESR 91.1

Firefox Extended Support Release 91.0.1 ESR

* Fixed: Fixed an issue causing buttons on the tab bar to be resized when loading certain websites (bug 1704404)
* Fixed: Fixed an issue which caused tabs from private windows to be visible in non-private windows when viewing switch-to- tab results in the address bar panel (bug 1720369)
* Fixed: Various stability fixes
* Fixed: Security fix MFSA 2021-37 (bsc#1189547)
* CVE-2021-29991 (bmo#1724896) Header Splitting possible with HTTP/3 Responses

Firefox Extended Support Release 91.0 ESR

* New: Some of the highlights of the new Extended Support Release are:

- A number of user interface changes. For more information, see the Firefox 89 release notes.
- Firefox now supports logging into Microsoft, work, and school accounts using Windows single sign-on. Learn more
- On Windows, updates can now be applied in the background while Firefox is not running.
- Firefox for Windows now offers a new page about:third-party to help identify compatibility issues caused by third-party applications
- Version 2 of Firefox's SmartBlock feature further improves private browsing. Third party Facebook scripts are blocked to prevent you from being tracked, but are now automatically loaded 'just in time' if you decide to 'Log in with Facebook' on any website.
- Enhanced the privacy of the Firefox Browser's Private Browsing mode with Total Cookie Protection, which confines cookies to the site where they were created, preventing companis from using cookies to track your browsing across sites. This feature was originally launched in Firefox's ETP Strict mode.
- PDF forms now support JavaScript embedded in PDF files.
Some PDF forms use JavaScript for validation and other interactive features.
- You'll encounter less website breakage in Private Browsing and Strict Enhanced Tracking Protection with SmartBlock, which provides stand-in scripts so that websites load properly.
- Improved Print functionality with a cleaner design and better integration with your computer's printer settings.
- Firefox now protects you from supercookies, a type of tracker that can stay hidden in your browser and track you online, even after you clear cookies. By isolating supercookies, Firefox prevents them from tracking your web browsing from one site to the next.
- Firefox now remembers your preferred location for saved bookmarks, displays the bookmarks toolbar by default on new tabs, and gives you easy access to all of your bookmarks via a toolbar folder.
- Native support for macOS devices built with Apple Silicon CPUs brings dramatic performance improvements over the non- native build that was shipped in Firefox 83: Firefox launches over 2.5 times faster and web apps are now twice as responsive (per the SpeedoMeter 2.0 test). If you are on a new Apple device, follow these steps to upgrade to the latest Firefox.
- Pinch zooming will now be supported for our users with Windows touchscreen devices and touchpads on Mac devices.
Firefox users may now use pinch to zoom on touch-capable devices to zoom in and out of webpages.
- Weve improved functionality and design for a number of Firefox search features:
* Selecting a search engine at the bottom of the search panel now enters search mode for that engine, allowing you to see suggestions (if available) for your search terms. The old behavior (immediately performing a search) is available with a shift-click.
* When Firefox autocompletes the URL of one of your search engines, you can now search with that engine directly in the address bar by selecting the shortcut in the address bar results.
* Weve added buttons at the bottom of the search panel to allow you to search your bookmarks, open tabs, and history.
- Firefox supports AcroForm, which will allow you to fill in, print, and save supported PDF forms and the PDF viewer also has a new fresh look.
- For our users in the US and Canada, Firefox can now save, manage, and auto-fill credit card information for you, making shopping on Firefox ever more convenient.
- In addition to our default, dark and light themes, with this release, Firefox introduces the Alpenglow theme: a colorful appearance for buttons, menus, and windows. You can update your Firefox themes under settings or preferences.
* Changed: Firefox no longer supports Adobe Flash. There is no setting available to re-enable Flash support.
* Enterprise: Various bug fixes and new policies have been implemented in the latest version of Firefox. See more details in the Firefox for Enterprise 91 Release Notes.

MFSA 2021-33 (bsc#1188891):

* CVE-2021-29986: Race condition when resolving DNS names could have led to memory corruption
* CVE-2021-29981: Live range splitting could have led to conflicting assignments in the JIT
* CVE-2021-29988: Memory corruption as a result of incorrect style treatment
* CVE-2021-29983: Firefox for Android could get stuck in fullscreen mode
* CVE-2021-29984: Incorrect instruction reordering during JIT optimization
* CVE-2021-29980: Uninitialized memory in a canvas object could have led to memory corruption
* CVE-2021-29987: Users could have been tricked into accepting unwanted permissions on Linux
* CVE-2021-29985: Use-after-free media channels
* CVE-2021-29982: Single bit data leak due to incorrect JIT optimization and type confusion
* CVE-2021-29989: Memory safety bugs fixed in Firefox 91 and Firefox ESR 78.13
* CVE-2021-29990: Memory safety bugs fixed in Firefox 91

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1188891

https://bugzilla.suse.com/1189547

https://bugzilla.suse.com/1190269

https://bugzilla.suse.com/1190274

https://bugzilla.suse.com/1190710

https://bugzilla.suse.com/1191332

https://www.suse.com/security/cve/CVE-2021-29980

https://www.suse.com/security/cve/CVE-2021-29981

https://www.suse.com/security/cve/CVE-2021-29982

https://www.suse.com/security/cve/CVE-2021-29983

https://www.suse.com/security/cve/CVE-2021-29984

https://www.suse.com/security/cve/CVE-2021-29985

https://www.suse.com/security/cve/CVE-2021-29986

https://www.suse.com/security/cve/CVE-2021-29987

https://www.suse.com/security/cve/CVE-2021-29988

https://www.suse.com/security/cve/CVE-2021-29989

https://www.suse.com/security/cve/CVE-2021-29990

https://www.suse.com/security/cve/CVE-2021-29991

https://www.suse.com/security/cve/CVE-2021-32810

https://www.suse.com/security/cve/CVE-2021-38492

https://www.suse.com/security/cve/CVE-2021-38495

https://www.suse.com/security/cve/CVE-2021-38496

https://www.suse.com/security/cve/CVE-2021-38497

https://www.suse.com/security/cve/CVE-2021-38498

https://www.suse.com/security/cve/CVE-2021-38500

https://www.suse.com/security/cve/CVE-2021-38501

http://www.nessus.org/u?f0f1504a

Plugin Details

Severity: Critical

ID: 154003

File Name: suse_SU-2021-3331-1.nasl

Version: 1.13

Type: Local

Agent: unix

Published: 10/12/2021

Updated: 6/25/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-38501

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2021-32810

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:mozillafirefox-devel, p-cpe:/a:novell:suse_linux:mozillafirefox-translations-common, p-cpe:/a:novell:suse_linux:mozillafirefox-translations-other, p-cpe:/a:novell:suse_linux:mozillafirefox-branding-sle, cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:mozillafirefox

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/11/2021

Vulnerability Publication Date: 8/2/2021

Reference Information

CVE: CVE-2021-29980, CVE-2021-29981, CVE-2021-29982, CVE-2021-29983, CVE-2021-29984, CVE-2021-29985, CVE-2021-29986, CVE-2021-29987, CVE-2021-29988, CVE-2021-29989, CVE-2021-29990, CVE-2021-29991, CVE-2021-32810, CVE-2021-38492, CVE-2021-38495, CVE-2021-38496, CVE-2021-38497, CVE-2021-38498, CVE-2021-38500, CVE-2021-38501

IAVA: 2021-A-0366-S, 2021-A-0386-S, 2021-A-0405-S, 2021-A-0450-S, 2021-A-0461-S

SuSE: SUSE-SU-2021:3331-1