USN-5494-1: SpiderMonkey JavaScript Library vulnerabilities
27 June 2022
Several security issues were fixed in SpiderMonkey JavaScript Library.
Releases
Packages
- mozjs91 - SpiderMonkey JavaScript library
Details
It was discovered that SpiderMonkey JavaScript Library incorrectly
generated certain assembly code. An remote attacker could
possibly use this issue to cause a crash or expose sensitive
information. (CVE-2022-28285)
It was discovered that SpiderMonkey JavaScript Library incorrectly
generated certain assembly code. An remote attacker could
possibly use this issue to cause a crash. (CVE-2022-31740)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
After a standard system update you need to restart any application that use
SpiderMonkey JavaScript Library to make all the necessary changes.