[ALSA-2024:0025] Important: firefox security update
Type:
security
Severity:
important
Release date:
2024-01-03
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.6.0 ESR. Security Fix(es): * Mozilla: Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with Mesa VM driver (CVE-2023-6856) * Mozilla: Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6 (CVE-2023-6864) * Mozilla: Potential exposure of uninitialized data in EncryptingOutputStream (CVE-2023-6865) * Mozilla: Symlinks may resolve to smaller than expected buffers (CVE-2023-6857) * Mozilla: Heap buffer overflow in nsTextFragment (CVE-2023-6858) * Mozilla: Use-after-free in PR_GetIdentitiesLayer (CVE-2023-6859) * Mozilla: Potential sandbox escape due to VideoBridge lack of texture validation (CVE-2023-6860) * Mozilla: Heap buffer overflow affected nsWindow::PickerOpen(void) in headless mode (CVE-2023-6861) * Mozilla: Use-after-free in nsDNSService (CVE-2023-6862) * Mozilla: Clickjacking permission prompts using the popup transition (CVE-2023-6867) * Mozilla: Undefined behavior in ShutdownObserver() (CVE-2023-6863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-x11-115.6.0-1.el9_3.alma.aarch64.rpm acfe81643e43f736ea87a4427167ce0239c2f1ea9f77065307424c507ded0fd9
aarch64 firefox-115.6.0-1.el9_3.alma.aarch64.rpm b435afd895aeaa90a6ebf88861f2ad05f04dd6a2b017df77ee9335cd25ba2599
ppc64le firefox-x11-115.6.0-1.el9_3.alma.ppc64le.rpm 70b26c4982f41ff934183e618b33b0527cf6fa8bd064b3b37eb05c96039c0010
ppc64le firefox-115.6.0-1.el9_3.alma.ppc64le.rpm cbf9e97cfc478924bd9733b1b764b9e47cc7974e0a88b87732174ef443d54e67
s390x firefox-115.6.0-1.el9_3.alma.s390x.rpm a84e655a1f8277d5728c7123dd8e6e68f1f341a5879043d8efb430de6f2bd60a
s390x firefox-x11-115.6.0-1.el9_3.alma.s390x.rpm bf21182d18c786589b2db6c94ae979ddc6f1d0a4041cd1bb0228324c25e104de
x86_64 firefox-115.6.0-1.el9_3.alma.x86_64.rpm 48a6e6e4048864be1a27cdc564b2bfeb2f0f9cbfb2aec1162574ed5e8a4091b7
x86_64 firefox-x11-115.6.0-1.el9_3.alma.x86_64.rpm 6c5ed6ae4f6a1ca9cad39c660904cc191adbdd366e68c667ff90fbbd4eb2a5e7
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.