[ALSA-2023:4071] Important: firefox security update
Type:
security
Severity:
important
Release date:
2023-07-14
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.13.0 ESR. Security Fix(es): * Mozilla: Use-after-free in WebRTC certificate generation (CVE-2023-37201) * Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-37202) * Mozilla: Memory safety bugs fixed in Firefox 115, Firefox ESR 102.13, and Thunderbird 102.13 (CVE-2023-37211) * Mozilla: Fullscreen notification obscured (CVE-2023-37207) * Mozilla: Lack of warning when opening Diagcab files (CVE-2023-37208) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-x11-102.13.0-2.el9_2.alma.aarch64.rpm 0292e76d27ee8b86c4c5bb867ac9c8b700262094e35127cccf69a6f0e4c87481
aarch64 firefox-102.13.0-2.el9_2.alma.aarch64.rpm 51603c640710331d95651cb55a314c5ff4c36fa229e084762296fa84bc853fb4
ppc64le firefox-102.13.0-2.el9_2.alma.ppc64le.rpm 2e8adc0aaac6c3cabd66168c371eb94601c70544290fe671c616b808805cd688
ppc64le firefox-x11-102.13.0-2.el9_2.alma.ppc64le.rpm b74c0b0c555629f986e52e74676de2b5b18e464ebe96ccf711591d101ac5ecdf
s390x firefox-x11-102.13.0-2.el9_2.alma.s390x.rpm 3ca59fdf4dc4cf2505ba8990fa8d2796c7c60b22da8a2e20fc81a7d4a8f0619f
s390x firefox-102.13.0-2.el9_2.alma.s390x.rpm e9a863faaad3f99ff8325e9eedcfa4921bcc2ea4594b60fb7d793522f36020ec
x86_64 firefox-x11-102.13.0-2.el9_2.alma.x86_64.rpm d14892a7bce824d614762b4416ae558377a8faa677f914aa11d65739931ea32f
x86_64 firefox-102.13.0-2.el9_2.alma.x86_64.rpm feec975b8dada516ce73f778664a91332d74cdc967a216b244def9e7c7b35ff4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.