Alert GCSA-22051 - Aggiornamenti di sicurezza per prodotti Mozilla

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

******************************************************************

Alert ID: GCSA-22051
Data: 04 Maggio 2022
Titolo: Aggiornamenti di sicurezza per prodotti Mozilla

******************************************************************


:: Descrizione

Mozilla ha rilasciato nuove versioni di alcuni prodotti, nelle quali
vengono risolte alcune vulnerabilita' critiche sfruttabili per
condurre attacchi.

Maggiori informazioni sono disponibili nelle segnalazioni
ufficiali alla sezione "Riferimenti".


:: Software interessato

Firefox versioni precedenti alla 100
Firefox ESR versioni precedenti alla 91.9


:: Impatto

Remote Code Execution
Security Restriction Bypass
Information Disclosure
Spoofing


:: Soluzione

Aggiornare i software all'ultima versione

Firefox 100
Firefox ESR 91.9

https://www.mozilla.org/it/firefox/new/
https://www.mozilla.org/en-US/firefox/organizations/


:: Riferimenti

Mozilla Security Advisory
https://www.mozilla.org/en-US/security/advisories/mfsa2022-16/
https://www.mozilla.org/en-US/security/advisories/mfsa2022-17/

Mitre CVE
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29909
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29910
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29911
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29912
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29914
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29915
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29916
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29917
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29918



GARR CERT Security Alert - subscribe/unsubscribe:
http://www.cert.garr.it/alert/ricevi-gli-alert-di-cert
-----BEGIN PGP SIGNATURE-----

iD8DBQFicmXKwZxMk2USYEIRAu58AJ9cG8M4l/StVq4pdN9vUPBfCciKMgCg0XSk
+oeTn4+cFZSwbE5bnffB2BY=
=SMZ3
-----END PGP SIGNATURE-----