firefox-102.11.0-2.el9.ML.1
エラータID: AXSA:2023-6024:19
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.
This update upgrades Firefox to version 102.11.0 ESR.
Security Fix(es):
* Mozilla: Browser prompts could have been obscured by popups (CVE-2023-32205)
* Mozilla: Crash in RLBox Expat driver (CVE-2023-32206)
* Mozilla: Potential permissions request bypass via clickjacking
(CVE-2023-32207)
* Mozilla: Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
(CVE-2023-32215)
* Mozilla: Content process crash due to invalid wasm code (CVE-2023-32211)
* Mozilla: Potential spoof due to obscured address bar (CVE-2023-32212)
* Mozilla: Potential memory corruption in FileReader::DoReadData()
(CVE-2023-32213)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE-2023-32205
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2023-32206
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2023-32207
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2023-32211
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2023-32212
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2023-32213
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
CVE-2023-32215
** RESERVED ** This candidate has been reserved by an organization or individual
that will use it when announcing a new security problem. When the candidate has
been publicized, the details for this candidate will be provided.
Update packages.
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
An attacker could have positioned a
datalist
element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
Memory safety bugs present in Firefox 112 and Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
N/A
SRPMS
- firefox-102.11.0-2.el9.ML.1.src.rpm
MD5: f816c10f55e20a50c8089665b8718bf2
SHA-256: 9633aa4492df5aeb6611dcafebc1f6ec9f11e1dac56d88c11fa0f9512f502119
Size: 594.97 MB
Asianux Server 9 for x86_64
- firefox-102.11.0-2.el9.ML.1.x86_64.rpm
MD5: 2b38e834b123ecb85dd74320fab7f6d3
SHA-256: fd047ec34afaf1260e2a2225abc83e2f62084b15e77bcb4b8b17df2446ab1962
Size: 107.03 MB - firefox-x11-102.11.0-2.el9.ML.1.x86_64.rpm
MD5: 7ea24b6ded75e6d33907fe78449f0464
SHA-256: 112cc43b9df1b081bad5d7f4ffd5b99910cabf7470209391bbb5751fa704ce51
Size: 14.08 kB