firefox-102.14.0-1.el8.ML.1

エラータID: AXSA:2023-6318:29

Release date: 
Thursday, August 10, 2023 - 00:39
Subject: 
firefox-102.14.0-1.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.

This update upgrades Firefox to version 102.14.0 ESR.

Security Fix(es):

Mozilla: Offscreen Canvas could have bypassed cross-origin restrictions
(CVE-2023-4045)
Mozilla: Incorrect value used during WASM compilation (CVE-2023-4046)
Mozilla: Potential permissions request bypass via clickjacking
(CVE-2023-4047)
Mozilla: Crash in DOMParser due to out-of-memory conditions (CVE-2023-4048)
Mozilla: Fix potential race conditions when releasing platform objects
(CVE-2023-4049)
Mozilla: Stack buffer overflow in StorageManager (CVE-2023-4050)
Mozilla: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox
ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 (CVE-2023-4056)
Mozilla: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, and
Thunderbird 115.1 (CVE-2023-4057)
Mozilla: Cookie jar overflow caused unexpected cookie jar state
(CVE-2023-4055)

CVE(s):
CVE-2023-4045
CVE-2023-4046
CVE-2023-4047
CVE-2023-4048
CVE-2023-4049
CVE-2023-4050
CVE-2023-4055
CVE-2023-4056
CVE-2023-4057

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-102.14.0-1.el8.ML.1.src.rpm
    MD5: 3326f566b7cee873cfe3d77aa41cd5a1
    SHA-256: b9750a1656fba9db5ed6e6a031ff5c0f88993f478f5ccfe263ad12c8ff2dddf6
    Size: 594.94 MB

Asianux Server 8 for x86_64
  1. firefox-102.14.0-1.el8.ML.1.x86_64.rpm
    MD5: a9f1523af874b666c06f360daa971a69
    SHA-256: a1ae00a079ca393206163d786de62a0c9de2250a737606777f2331bbe7281b19
    Size: 109.45 MB