firefox-115.6.0-1.el8_9.ML.1

エラータID: AXSA:2024-7376:03

Release date: 
Friday, January 12, 2024 - 00:41
Subject: 
firefox-115.6.0-1.el8_9.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.

This update upgrades Firefox to version 115.6.0 ESR.

Security Fix(es):

Mozilla: Heap-buffer-overflow affecting WebGL
DrawElementsInstanced method with Mesa VM driver (CVE-2023-6856)
Mozilla: Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6, and
Thunderbird 115.6 (CVE-2023-6864)
Mozilla: Potential exposure of uninitialized data in
EncryptingOutputStream (CVE-2023-6865)
Mozilla: Symlinks may resolve to smaller than expected buffers
(CVE-2023-6857)
Mozilla: Heap buffer overflow in nsTextFragment (CVE-2023-6858)
Mozilla: Use-after-free in PR_GetIdentitiesLayer (CVE-2023-6859)
Mozilla: Potential sandbox escape due to VideoBridge lack of
texture validation (CVE-2023-6860)
Mozilla: Heap buffer overflow affected
nsWindow::PickerOpen(void) in headless mode (CVE-2023-6861)
Mozilla: Use-after-free in nsDNSService (CVE-2023-6862)
Mozilla: Clickjacking permission prompts using the popup transition
(CVE-2023-6867)
Mozilla: Undefined behavior in ShutdownObserver()
(CVE-2023-6863)

CVE(s):
CVE-2023-6856
CVE-2023-6857
CVE-2023-6858
CVE-2023-6859
CVE-2023-6860
CVE-2023-6861
CVE-2023-6862
CVE-2023-6863
CVE-2023-6864
CVE-2023-6865
CVE-2023-6867

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-115.6.0-1.el8_9.ML.1.src.rpm
    MD5: 08b68a125bff6a9f1b80e0277d766e51
    SHA-256: 3eef9f59bc281936eb89dfbe1c516bf0cee9346c14e59f963b9d7cc689d96c6e
    Size: 703.61 MB

Asianux Server 8 for x86_64
  1. firefox-115.6.0-1.el8_9.ML.1.x86_64.rpm
    MD5: 59e3f9895bfa824a01f470827cd86c15
    SHA-256: 4081d31e06ce4b4909aefc317ffeb55874560052e4eef0c2bb5d1977900b986a
    Size: 112.91 MB