firefox-115.13.0-3.el8_10.ML.1

エラータID: AXSA:2024-8566:25

Release date: 
Wednesday, July 17, 2024 - 13:55
Subject: 
firefox-115.13.0-3.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* Mozilla: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (CVE-2024-6604)
* Mozilla: Race condition in permission assignment (CVE-2024-6601)
* Mozilla: Memory corruption in thread creation (CVE-2024-6603)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-6601
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
CVE-2024-6603
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
CVE-2024-6604
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. firefox-115.13.0-3.el8_10.ML.1.src.rpm
    MD5: 8338837903751a74db12cfc4f516227f
    SHA-256: dd832918abee96a75cc3a5911e552c90286525ebf22bd455dc48c5cef42d0282
    Size: 706.84 MB

Asianux Server 8 for x86_64
  1. firefox-115.13.0-3.el8_10.ML.1.x86_64.rpm
    MD5: 62115efaf80b689cf8feb2729992aaab
    SHA-256: 061d9355654e5a19fa2dd60ff2979bc6412859ceaa43bf8fb0839072cfcd3b97
    Size: 116.38 MB