[RHSA-2024:1484] firefox security update
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.
This update upgrades Firefox to version 115.9.1 ESR.
Security Fix(es):
nss: timing attack against RSA decryption (CVE-2023-5388)
Mozilla: Crash in NSS TLS method (CVE-2024-0743)
Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)
Mozilla: Integer overflow could have led to out of bounds write (CVE-2024-2608)
Mozilla: Improve handling of out-of-memory conditions in ICU (CVE-2024-2616)
Mozilla: Improper handling of html and body tags enabled CSP nonce leakage (CVE-2024-2610)
Mozilla: Clickjacking vulnerability could have led to a user accidentally granting permissions (CVE-2024-2611)
Mozilla: Self referencing object could have potentially led to a use-after-free (CVE-2024-2612)
Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9 (CVE-2024-2614)
Mozilla: Privileged JavaScript Execution via Event Handlers (CVE-2024-29944)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-8.9 | < 115.9.1-1.el8_9 |
pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-8.9 | < 115.9.1-1.el8_9 |
pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-8.9 | < 115.9.1-1.el8_9 |
pkg:rpm/redhat/firefox?arch=aarch64&distro=redhat-8.9 | < 115.9.1-1.el8_9 |
- ID
- RHSA-2024:1484
- Severity
- critical
- URL
- https://access.redhat.com/errata/RHSA-2024:1484
- Published
-
2024-03-25T00:00:00
(5 months ago) - Modified
-
2024-03-25T00:00:00
(5 months ago) - Rights
- Copyright 2024 Red Hat, Inc.
- Other Advisories
-
- ALAS-2024-1907
- ALAS2-2024-2419
- ALAS2-2024-2505
- ALPINE:CVE-2023-5388
- ALPINE:CVE-2024-0743
- ALPINE:CVE-2024-2607
- ALPINE:CVE-2024-2608
- ALPINE:CVE-2024-2610
- ALPINE:CVE-2024-2611
- ALPINE:CVE-2024-2612
- ALPINE:CVE-2024-2614
- ALPINE:CVE-2024-2616
- ALPINE:CVE-2024-29944
- ALSA-2024:0105
- ALSA-2024:0108
- ALSA-2024:1484
- ALSA-2024:1485
- ALSA-2024:1493
- ALSA-2024:1494
- DSA-5643-1
- DSA-5644-1
- DSA-5645-1
- ELSA-2024-0105
- ELSA-2024-0108
- ELSA-2024-1484
- ELSA-2024-1485
- ELSA-2024-1486
- ELSA-2024-1493
- ELSA-2024-1494
- ELSA-2024-1498
- GLSA-202402-26
- GLSA-202407-22
- MFSA-2024-01
- MFSA-2024-12
- MFSA-2024-13
- MFSA-2024-14
- MFSA-2024-15
- MFSA-2024-16
- RHSA-2024:0105
- RHSA-2024:0108
- RHSA-2024:1485
- RHSA-2024:1486
- RHSA-2024:1493
- RHSA-2024:1494
- RHSA-2024:1498
- RLSA-2024:0105
- RLSA-2024:1484
- RLSA-2024:1494
- SSA:2024-079-02
- SSA:2024-079-03
- SSA:2024-083-01
- SUSE-SU-2024:0578-1
- SUSE-SU-2024:0579-1
- SUSE-SU-2024:0597-1
- SUSE-SU-2024:0971-1
- SUSE-SU-2024:1000-1
- SUSE-SU-2024:1002-1
- SUSE-SU-2024:1147-1
- SUSE-SU-2024:2600-1
- USN-6610-1
- USN-6703-1
- USN-6710-1
- USN-6717-1
- USN-6727-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/firefox?arch=x86_64&distro=redhat-8.9 | redhat | firefox | < 115.9.1-1.el8_9 | redhat-8.9 | x86_64 | |
Affected | pkg:rpm/redhat/firefox?arch=s390x&distro=redhat-8.9 | redhat | firefox | < 115.9.1-1.el8_9 | redhat-8.9 | s390x | |
Affected | pkg:rpm/redhat/firefox?arch=ppc64le&distro=redhat-8.9 | redhat | firefox | < 115.9.1-1.el8_9 | redhat-8.9 | ppc64le | |
Affected | pkg:rpm/redhat/firefox?arch=aarch64&distro=redhat-8.9 | redhat | firefox | < 115.9.1-1.el8_9 | redhat-8.9 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |