[RLSA-2023:1336] firefox security update
An update is available for firefox. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 102.9.0 ESR.
Security Fix(es):
Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751)
Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176)
Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752)
Mozilla: Invalid downcast in Worklets (CVE-2023-28162)
Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (CVE-2023-28164)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package | Affected Version |
---|---|
pkg:rpm/rockylinux/firefox?arch=x86_64&distro=rockylinux-8.7 | < 102.9.0-3.el8_7 |
pkg:rpm/rockylinux/firefox?arch=aarch64&distro=rockylinux-8.7 | < 102.9.0-3.el8_7 |
- ID
- RLSA-2023:1336
- Severity
- important
- URL
- https://errata.rockylinux.org/RLSA-2023:1336
- Published
-
2023-03-28T13:07:10
(18 months ago) - Modified
-
2023-03-28T13:08:46
(18 months ago) - Rights
- Copyright 2024 Rocky Enterprise Software Foundation
- Other Advisories
-
- ALAS2-2023-1988
- ALPINE:CVE-2023-25751
- ALPINE:CVE-2023-25752
- ALPINE:CVE-2023-28162
- ALPINE:CVE-2023-28164
- ALPINE:CVE-2023-28176
- ALSA-2023:1336
- ALSA-2023:1337
- ALSA-2023:1403
- ALSA-2023:1407
- DSA-5374-1
- DSA-5375-1
- ELSA-2023-1333
- ELSA-2023-1336
- ELSA-2023-1337
- ELSA-2023-1401
- ELSA-2023-1403
- ELSA-2023-1407
- GLSA-202305-35
- GLSA-202305-36
- MFSA-2023-09
- MFSA-2023-10
- MFSA-2023-11
- RHSA-2023:1333
- RHSA-2023:1336
- RHSA-2023:1337
- RHSA-2023:1401
- RHSA-2023:1403
- RHSA-2023:1407
- RLSA-2023:1337
- RLSA-2023:1403
- RLSA-2023:1407
- SSA:2023-073-01
- SSA:2023-075-01
- SUSE-SU-2023:0728-1
- SUSE-SU-2023:0763-1
- SUSE-SU-2023:0835-1
- SUSE-SU-2023:1736-1
- USN-5954-1
- USN-5972-1
- USN-6120-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2023-25751 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25751 | |
CVE | CVE-2023-25752 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25752 | |
CVE | CVE-2023-28162 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28162 | |
CVE | CVE-2023-28164 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28164 | |
CVE | CVE-2023-28176 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28176 | |
Bugzilla | 2178458 | https://bugzilla.redhat.com/show_bug.cgi?id=2178458 | |
Bugzilla | 2178460 | https://bugzilla.redhat.com/show_bug.cgi?id=2178460 | |
Bugzilla | 2178466 | https://bugzilla.redhat.com/show_bug.cgi?id=2178466 | |
Bugzilla | 2178470 | https://bugzilla.redhat.com/show_bug.cgi?id=2178470 | |
Bugzilla | 2178472 | https://bugzilla.redhat.com/show_bug.cgi?id=2178472 | |
Self | RLSA-2023:1336 | https://errata.rockylinux.org/RLSA-2023:1336 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/rockylinux/firefox?arch=x86_64&distro=rockylinux-8.7 | rockylinux | firefox | < 102.9.0-3.el8_7 | rockylinux-8.7 | x86_64 | |
Affected | pkg:rpm/rockylinux/firefox?arch=aarch64&distro=rockylinux-8.7 | rockylinux | firefox | < 102.9.0-3.el8_7 | rockylinux-8.7 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |