firefox-102.13.0-2.el9.ML.1

エラータID: AXSA:2023-6244:26

Release date: 
Wednesday, July 19, 2023 - 08:39
Subject: 
firefox-102.13.0-2.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 102.13.0 ESR.

Security Fix(es):

* Mozilla: Use-after-free in WebRTC certificate generation (CVE-2023-37201)
* Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-37202)
* Mozilla: Memory safety bugs fixed in Firefox 115, Firefox ESR 102.13, and Thunderbird 102.13 (CVE-2023-37211)
* Mozilla: Fullscreen notification obscured (CVE-2023-37207)
* Mozilla: Lack of warning when opening Diagcab files (CVE-2023-37208)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-37201
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37202
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37207
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37208
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37211
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-102.13.0-2.el9.ML.1.src.rpm
    MD5: bebb6fe10d2b429e9a93732ba3036baf
    SHA-256: 8f1cb31c11b7336f2eeec4558b280913c2d4df1054a38b30dd51631ae294c4dd
    Size: 594.96 MB

Asianux Server 9 for x86_64
  1. firefox-102.13.0-2.el9.ML.1.x86_64.rpm
    MD5: 06466a41fef0c0062261c5e6280d27a8
    SHA-256: b2ed3d02763abc9149e56bcb26eab50e65895f0e1bac3f86daf6d75280161c2b
    Size: 107.06 MB
  2. firefox-x11-102.13.0-2.el9.ML.1.x86_64.rpm
    MD5: bb8f0580b6c41c75b64a3fe253f3054a
    SHA-256: 41357e6a6505eebb28c3fde45c1557261792f4940a3e6cfffce98510fb92c160
    Size: 14.39 kB