Synopsis
The remote SUSE host is missing one or more security updates.
Description
The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:1748-1 advisory.
  - Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the     top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This     vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. (CVE-2022-29909)
  - An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-     activation</code> could lead to script execution without <code>allow-scripts</code> being present. This     vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. (CVE-2022-29911)
  - Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This     vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. (CVE-2022-29912)
  - When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI,     which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox     ESR < 91.9, and Firefox < 100. (CVE-2022-29914)
  - Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS     variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird     < 91.9, Firefox ESR < 91.9, and Firefox < 100. (CVE-2022-29916)
  - Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported     memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of     memory corruption and we presume that with enough effort some of these could have been exploited to run     arbitrary code. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
    (CVE-2022-29917)
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected MozillaFirefox, MozillaFirefox-devel, MozillaFirefox-translations-common and / or MozillaFirefox- translations-other packages.
Plugin Details
File Name: suse_SU-2022-1748-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Vulnerability Information
CPE: p-cpe:/a:novell:suse_linux:mozillafirefox-translations-common, cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:mozillafirefox, p-cpe:/a:novell:suse_linux:mozillafirefox-devel, p-cpe:/a:novell:suse_linux:mozillafirefox-translations-other
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 5/19/2022
Vulnerability Publication Date: 5/3/2022