firefox-115.13.0-3.el9_4.ML.1
エラータID: AXSA:2024-8564:24
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
* Mozilla: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (CVE-2024-6604)
* Mozilla: Race condition in permission assignment (CVE-2024-6601)
* Mozilla: Memory corruption in thread creation (CVE-2024-6603)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2024-6601
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
CVE-2024-6603
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
CVE-2024-6604
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
Update packages.
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
N/A
SRPMS
- firefox-115.13.0-3.el9_4.ML.1.src.rpm
MD5: 9e0a81fc5f1fef6404549f62a5f5bc7c
SHA-256: 3ef8a2e387a984bcc357966484584903040f05af41b7a631fd74526637d0c17d
Size: 706.84 MB
Asianux Server 9 for x86_64
- firefox-115.13.0-3.el9_4.ML.1.x86_64.rpm
MD5: f9d8208df2169bb574b379ae0ae5062c
SHA-256: 0c119e93918b2056525202194063d736ec8b40e18651592b0815edf6b1fde391
Size: 113.60 MB - firefox-x11-115.13.0-3.el9_4.ML.1.x86_64.rpm
MD5: 6573894002dcab5edff31e41174a9e0e
SHA-256: 20080cfe211e54319c25d3d05e1be70abdc49473b6f11293b6075363c2bf10d8
Size: 13.85 kB