Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 849044 (CVE-2022-1919, CVE-2022-31743, CVE-2022-31744, CVE-2022-31745, CVE-2022-31748) - <www-client/firefox{-bin,}-{91.10.0,101.0}: multiple vulnerabilities
Summary: <www-client/firefox{-bin,}-{91.10.0,101.0}: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2022-1919, CVE-2022-31743, CVE-2022-31744, CVE-2022-31745, CVE-2022-31748
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa+]
Keywords:
Depends on: 846884
Blocks: CVE-2022-31736, CVE-2022-31737, CVE-2022-31738, CVE-2022-31740, CVE-2022-31741, CVE-2022-31742, CVE-2022-31747
  Show dependency tree
 
Reported: 2022-06-01 17:48 UTC by John Helmert III
Modified: 2022-08-10 04:22 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-06-01 17:48:22 UTC
See tracker for details. Please stabilize 101.0
Comment 1 Joonas Niilola gentoo-dev 2022-06-01 18:28:08 UTC
(In reply to John Helmert III from comment #0)
> See tracker for details. Please stabilize 101.0

* 91.10.0 ;) tomorrow!
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-06-02 04:09:49 UTC
(In reply to Joonas Niilola from comment #1)
> (In reply to John Helmert III from comment #0)
> > See tracker for details. Please stabilize 101.0
> 
> * 91.10.0 ;) tomorrow!

Indeed, sorry! Thanks for handling!
Comment 3 Larry the Git Cow gentoo-dev 2022-06-03 07:28:29 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=895cb41b0e9491fb4ab505091d56d5c0b9dc123e

commit 895cb41b0e9491fb4ab505091d56d5c0b9dc123e
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2022-06-03 07:24:54 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2022-06-03 07:28:26 +0000

    www-client/firefox: security cleanup
    
    Bug: https://bugs.gentoo.org/849044
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox/Manifest               |  296 -------
 www-client/firefox/firefox-100.0.2.ebuild | 1267 -----------------------------
 www-client/firefox/firefox-91.9.0.ebuild  | 1244 ----------------------------
 www-client/firefox/firefox-91.9.1.ebuild  | 1244 ----------------------------
 4 files changed, 4051 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=295284fe3dd7ced2e56ab8b0f95098110606f2f6

commit 295284fe3dd7ced2e56ab8b0f95098110606f2f6
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2022-06-03 07:24:16 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2022-06-03 07:28:26 +0000

    www-client/firefox-bin: security cleanup
    
    Bug: https://bugs.gentoo.org/849044
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox-bin/Manifest                   |  98 ------
 www-client/firefox-bin/firefox-bin-100.0.2.ebuild | 385 ----------------------
 2 files changed, 483 deletions(-)
Comment 4 Larry the Git Cow gentoo-dev 2022-08-10 04:18:13 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=28683764d95cb78c056bdf67f3245ad0eb5c6bbe

commit 28683764d95cb78c056bdf67f3245ad0eb5c6bbe
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2022-08-10 04:06:48 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-08-10 04:17:28 +0000

    [ GLSA 202208-08 ] Mozilla Firefox: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/834631
    Bug: https://bugs.gentoo.org/834804
    Bug: https://bugs.gentoo.org/836866
    Bug: https://bugs.gentoo.org/842438
    Bug: https://bugs.gentoo.org/846593
    Bug: https://bugs.gentoo.org/849044
    Bug: https://bugs.gentoo.org/857045
    Bug: https://bugs.gentoo.org/861515
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202208-08.xml | 147 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 147 insertions(+)
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-10 04:22:17 UTC
GLSA released, all done!