[ALSA-2021:0655] firefox security update
An update for firefox is now available for AlmaLinux AlmaLinux Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 78.8.0 ESR.
Security Fix(es):
Mozilla: Content Security Policy violation report could have contained the destination of a redirect (CVE-2021-23968)
Mozilla: Content Security Policy violation report could have contained the destination of a redirect (CVE-2021-23969)
Mozilla: Memory safety bugs fixed in Firefox 86 and Firefox ESR 78.8 (CVE-2021-23978)
Mozilla: MediaError message property could have leaked information about cross-origin resources (CVE-2021-23973)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/almalinux/firefox?arch=x86_64&distro=almalinux-8.3 | < 78.8.0-1.el8_3.alma |
- ID
- ALSA-2021:0655
- Severity
- critical
- URL
- https://errata.almalinux.org/ALSA-2021:0655.html
- Published
-
2021-02-24T14:17:36
(3 years ago) - Modified
-
2021-05-04T09:10:37
(3 years ago) - Rights
- Copyright 2021 AlmaLinux OS
- Other Advisories
-
- ALAS2-2021-1618
- ALPINE:CVE-2021-23968
- ALPINE:CVE-2021-23969
- ALPINE:CVE-2021-23973
- ALPINE:CVE-2021-23978
- ALSA-2021:0657
- DSA-4862-1
- DSA-4866-1
- ELSA-2021-0655
- ELSA-2021-0656
- ELSA-2021-0657
- ELSA-2021-0661
- GLSA-202104-09
- GLSA-202104-10
- MFSA-2021-07
- MFSA-2021-08
- MFSA-2021-09
- openSUSE-SU-2021:0373-1
- openSUSE-SU-2021:0387-1
- RHSA-2021:0655
- RHSA-2021:0656
- RHSA-2021:0657
- RHSA-2021:0661
- SUSE-SU-2021:0659-1
- SUSE-SU-2021:0661-1
- SUSE-SU-2021:0667-1
- SUSE-SU-2021:0676-1
- USN-4756-1
- USN-4936-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2021-23968 | https://vulners.com/cve/CVE-2021-23968 | |
CVE | CVE-2021-23969 | https://vulners.com/cve/CVE-2021-23969 | |
CVE | CVE-2021-23973 | https://vulners.com/cve/CVE-2021-23973 | |
CVE | CVE-2021-23978 | https://vulners.com/cve/CVE-2021-23978 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/almalinux/firefox?arch=x86_64&distro=almalinux-8.3 | almalinux | firefox | < 78.8.0-1.el8_3.alma | almalinux-8.3 | x86_64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |