[ALSA-2024:9554] Important: firefox security update
Type:
security
Severity:
important
Release date:
2024-11-18
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: Use-after-free in Animation timeline (128.3.1 ESR Chemspill) (CVE-2024-9680) * firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser (CVE-2024-10464) * firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response (CVE-2024-10461) * firefox: thunderbird: Permission leak via embed or object elements (CVE-2024-10458) * firefox: thunderbird: Use-after-free in layout with accessibility (CVE-2024-10459) * firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4 (CVE-2024-10467) * firefox: thunderbird: Clipboard "paste" button persisted across tabs (CVE-2024-10465) * firefox: DOM push subscription message could hang Firefox (CVE-2024-10466) * firefox: thunderbird: Cross origin video frame leak (CVE-2024-10463) * firefox: thunderbird: Origin of permission prompt could be spoofed by long URL (CVE-2024-10462) * firefox: thunderbird: Confusing display of origin for external protocol handler prompt (CVE-2024-10460) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-128.4.0-1.el9_5.aarch64.rpm 57c7968fbcaaf24842fda385891d6fc4aa04dc79f7bce2de90502f5d5084e6fc
aarch64 firefox-x11-128.4.0-1.el9_5.aarch64.rpm 721da67a8ad746a2c0dbaa5b2b3f6545d6b42c59a5548e538910df833b6f638f
ppc64le firefox-x11-128.4.0-1.el9_5.ppc64le.rpm 46eac41f5d7e2620950f459c5963430e9ff5c89b1f8915da7ea08f75f7c29bfa
ppc64le firefox-128.4.0-1.el9_5.ppc64le.rpm 9ebe3fcb87d7b51de4de794bd42b32edc55dfb0753334ffa7425c3529201cd98
s390x firefox-x11-128.4.0-1.el9_5.s390x.rpm 5b03eeed1127188e9f97015b57179a904460f0c9c8ebc10404f3ca290255f92d
s390x firefox-128.4.0-1.el9_5.s390x.rpm 63fb7cdedf0520fe9fe03a153d810a5c326364479db9aca4e30a3afd9b60d174
x86_64 firefox-128.4.0-1.el9_5.x86_64.rpm 46b39c733e6e88040a024a5b4100c59fcb46b8f3e681e3f20ef51b050ce150f4
x86_64 firefox-x11-128.4.0-1.el9_5.x86_64.rpm 600260d0772c9116202c135f93a5ec41847a8ed25e8efed985f94b026dd0adb3
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.