firefox-115.3.1-1.0.1.el7.AXS7

エラータID: AXSA:2023-6514:39

Release date: 
Friday, October 20, 2023 - 00:26
Subject: 
firefox-115.3.1-1.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 115.3.1 ESR.

Security Fix(es):

* firefox: use-after-free in workers (CVE-2023-3600)
* Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169)
* Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171)
* Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176)
* libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-3600
During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
CVE-2023-5169
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
CVE-2023-5171
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
CVE-2023-5176
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-115.3.1-1.0.1.el7.AXS7.src.rpm
    MD5: cf12ec35e74e469cc5cfb29e56df3060
    SHA-256: d6c9c3a7be91e75c7a5f608628c2a9a98b7438efe2268cd4ed250fa09754dbba
    Size: 703.58 MB

Asianux Server 7 for x86_64
  1. firefox-115.3.1-1.0.1.el7.AXS7.i686.rpm
    MD5: 30a1ca602488bb548dcd817bc63f6119
    SHA-256: 8e1febc1b1141a475dcc33310159f1a5d2c35fb638085111b7d9b6191997b412
    Size: 116.49 MB
  2. firefox-115.3.1-1.0.1.el7.AXS7.x86_64.rpm
    MD5: 8bf33d4cd3e0addfee4360ca54a706b7
    SHA-256: 35b4e0b81c445154359361b28f67e4445f0206365839681468d6ec3f40c7da21
    Size: 112.81 MB