firefox-102.12.0-1.0.1.el7.AXS7

エラータID: AXSA:2023-6069:20

Release date: 
Monday, June 19, 2023 - 00:54
Subject: 
firefox-102.12.0-1.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 102.12.0 ESR.

Security Fix(es):

* Mozilla: Click-jacking certificate exceptions through rendering lag (CVE-2023-34414)
* Mozilla: Memory safety bugs fixed in Firefox 114 and Firefox ESR 102.12 (CVE-2023-34416)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-34414
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2023-34416
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-102.12.0-1.0.1.el7.AXS7.src.rpm
    MD5: d614bb04101dbc03936b177544f27b80
    SHA-256: 45dd29e9f95e2ca8c15ee4944047f7d2cb1e1e3d6e83fb6a675fe6a9f82e2962
    Size: 594.91 MB

Asianux Server 7 for x86_64
  1. firefox-102.12.0-1.0.1.el7.AXS7.i686.rpm
    MD5: 455501468e15f7517a37516319149f89
    SHA-256: 6be413662027c0b21b13547153f9590c88dbbae6c8a9475b8d8b4a9ce4c7b1be
    Size: 113.10 MB
  2. firefox-102.12.0-1.0.1.el7.AXS7.x86_64.rpm
    MD5: aed9159f61975b8ee9a39820abfd7c6a
    SHA-256: 865f5ba97a2eb066cc54e688e87699ec5fe3bc99d357a15702c72495ec9441e2
    Size: 109.73 MB