[RHSA-2021:0992] firefox security update
Severity
Important
Affected Packages
5
CVEs
5
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 78.9.0 ESR.
Security Fix(es):
Mozilla: Texture upload into an unbound backing buffer resulted in an out-of-bound read (CVE-2021-23981)
Mozilla: Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9 (CVE-2021-23987)
Mozilla: Internal network hosts could have been probed by a malicious webpage (CVE-2021-23982)
Mozilla: Malicious extensions could have spoofed popup information (CVE-2021-23984)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-7.9 | < 78.9.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-7.9 | < 78.9.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-7.9 | < 78.9.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-7.9 | < 78.9.0-1.el7_9 |
pkg:rpm/redhat/firefox?arch=i686&distro=redhat-7.9 | < 78.9.0-1.el7_9 |
- ID
- RHSA-2021:0992
- Severity
- important
- URL
- https://access.redhat.com/errata/RHSA-2021:0992
- Published
-
2021-03-25T00:00:00
(3 years ago) - Modified
-
2021-03-25T00:00:00
(3 years ago) - Rights
- Copyright 2021 Red Hat, Inc.
- Other Advisories
-
- ALAS2-2021-1632
- ALAS2-2023-1951
- ALPINE:CVE-2021-23981
- ALPINE:CVE-2021-23982
- ALPINE:CVE-2021-23984
- ALPINE:CVE-2021-23987
- ALSA-2021:0990
- ALSA-2021:0993
- DSA-4874-1
- DSA-4876-1
- ELSA-2021-0990
- ELSA-2021-0992
- ELSA-2021-0993
- ELSA-2021-0996
- GLSA-202104-09
- GLSA-202104-10
- MFSA-2021-10
- MFSA-2021-11
- MFSA-2021-12
- openSUSE-SU-2021:0487-1
- openSUSE-SU-2021:0580-1
- RHSA-2021:0990
- RHSA-2021:0993
- RHSA-2021:0996
- SUSE-SU-2021:0966-1
- SUSE-SU-2021:0999-1
- SUSE-SU-2021:1007-1
- SUSE-SU-2021:1167-1
- USN-4893-1
- USN-4995-1
- USN-4995-2
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1942783 | https://bugzilla.redhat.com/1942783 | |
Bugzilla | 1942784 | https://bugzilla.redhat.com/1942784 | |
Bugzilla | 1942785 | https://bugzilla.redhat.com/1942785 | |
Bugzilla | 1942786 | https://bugzilla.redhat.com/1942786 | |
Bugzilla | 1942787 | https://bugzilla.redhat.com/1942787 | |
RHSA | RHSA-2021:0992 | https://access.redhat.com/errata/RHSA-2021:0992 | |
CVE | CVE-2021-23981 | https://access.redhat.com/security/cve/CVE-2021-23981 | |
CVE | CVE-2021-23982 | https://access.redhat.com/security/cve/CVE-2021-23982 | |
CVE | CVE-2021-23984 | https://access.redhat.com/security/cve/CVE-2021-23984 | |
CVE | CVE-2021-23987 | https://access.redhat.com/security/cve/CVE-2021-23987 | |
CVE | CVE-2021-4127 | https://access.redhat.com/security/cve/CVE-2021-4127 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-7.9 | redhat | firefox | < 78.9.0-1.el7_9 | redhat-7.9 | x86_64 | |
Affected | pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-7.9 | redhat | firefox | < 78.9.0-1.el7_9 | redhat-7.9 | s390x | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-7.9 | redhat | firefox | < 78.9.0-1.el7_9 | redhat-7.9 | ppc64le | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64&distro=redhat-7.9 | redhat | firefox | < 78.9.0-1.el7_9 | redhat-7.9 | ppc64 | |
Affected | pkg:rpm/redhat/firefox?arch=i686&distro=redhat-7.9 | redhat | firefox | < 78.9.0-1.el7_9 | redhat-7.9 | i686 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |