From ede025dc4375f6a140f5df1c193e66e6c8e23c7f Mon Sep 17 00:00:00 2001 From: Matt Reagan Date: Tue, 2 Apr 2024 11:57:00 -0700 Subject: [PATCH 1/4] Advisories for iOS v124 release --- announce/2024/mfsa2024-09.yml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 announce/2024/mfsa2024-09.yml diff --git a/announce/2024/mfsa2024-09.yml b/announce/2024/mfsa2024-09.yml new file mode 100644 index 0000000..33793ee --- /dev/null +++ b/announce/2024/mfsa2024-09.yml @@ -0,0 +1,23 @@ +## mfsa2024-09.yml +announced: April 2, 2024 +impact: moderate +fixed_in: +- Firefox for iOS 124 +title: Security Vulnerabilities fixed in Firefox for iOS 124 +advisories: + CVE-2024-31393: + title: Javascript URLs would load when dragged to address bar + impact: moderate + reporter: Muneaki Nishimura + description: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections + + bugs: + - url: 1879739 + CVE-2024-31392: + title: Firefox on iOS would show pages with mixed content secure + impact: low + reporter: Chaykin Artem + description: Firefox could potentially show pages with a secure icon even if content had mixed security status + + bugs: + - url: 1875925 \ No newline at end of file From 169033981036e592b4dcbbb06d323f88f35c096c Mon Sep 17 00:00:00 2001 From: Matt Reagan Date: Tue, 2 Apr 2024 11:59:55 -0700 Subject: [PATCH 2/4] Correct file number --- announce/2024/{mfsa2024-09.yml => mfsa2024-11.yml} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename announce/2024/{mfsa2024-09.yml => mfsa2024-11.yml} (100%) diff --git a/announce/2024/mfsa2024-09.yml b/announce/2024/mfsa2024-11.yml similarity index 100% rename from announce/2024/mfsa2024-09.yml rename to announce/2024/mfsa2024-11.yml From d05987f9936b4ab1385930264ba8ebdb0d1ad1c3 Mon Sep 17 00:00:00 2001 From: Matt Reagan Date: Tue, 2 Apr 2024 12:03:50 -0700 Subject: [PATCH 3/4] Correct file number in yml --- announce/2024/mfsa2024-11.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/announce/2024/mfsa2024-11.yml b/announce/2024/mfsa2024-11.yml index 33793ee..da5e014 100644 --- a/announce/2024/mfsa2024-11.yml +++ b/announce/2024/mfsa2024-11.yml @@ -1,4 +1,4 @@ -## mfsa2024-09.yml +## mfsa2024-11.yml announced: April 2, 2024 impact: moderate fixed_in: From 1cefaee8f150d23a8c3334f9eedbab6dc44f8183 Mon Sep 17 00:00:00 2001 From: Matt Reagan Date: Tue, 2 Apr 2024 14:13:14 -0700 Subject: [PATCH 4/4] Change wording for security advisory text --- announce/2024/mfsa2024-11.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/announce/2024/mfsa2024-11.yml b/announce/2024/mfsa2024-11.yml index da5e014..b43a9d2 100644 --- a/announce/2024/mfsa2024-11.yml +++ b/announce/2024/mfsa2024-11.yml @@ -17,7 +17,7 @@ advisories: title: Firefox on iOS would show pages with mixed content secure impact: low reporter: Chaykin Artem - description: Firefox could potentially show pages with a secure icon even if content had mixed security status + description: If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status bugs: - url: 1875925 \ No newline at end of file