[ALSA-2024:3783] Moderate: firefox security update
Type:
security
Severity:
moderate
Release date:
2024-06-20
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.11.0 ESR. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-115.11.0-1.el8_10.alma.1.aarch64.rpm 8abdffe532133b803be8851150e0762752773f6458b25856847b0c1ca66e58d4
ppc64le firefox-115.11.0-1.el8_10.alma.1.ppc64le.rpm c5296687d65b9374a92e48a88a7d2274da3a611fb9ef5139b4e8e8fd62b64c86
s390x firefox-115.11.0-1.el8_10.alma.1.s390x.rpm 07cd7c86155696df14ef3f40033ea5de2d8a582cf6450d6b13425669f9e6767a
x86_64 firefox-115.11.0-1.el8_10.alma.1.x86_64.rpm 0eb678b67a56af9224ac7a48cb6a18822b12a2126a3d6fc6e82e67de0aae7b5f
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.