firefox-115.13.0-3.0.1.el7.AXS7
エラータID: AXSA:2024-8625:26
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.
Security Fix(es):
* Mozilla: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and
Thunderbird 115.13 (CVE-2024-6604)
* Mozilla: Race condition in permission assignment (CVE-2024-6601)
* Mozilla: Memory corruption in thread creation (CVE-2024-6603)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE-2024-6601
A race condition could lead to a cross-origin container obtaining permissions of
the top-level origin. This vulnerability affects Firefox < 128 and Firefox ESR <
115.13.
CVE-2024-6603
In an out-of-memory scenario an allocation could fail but free would have been
called on the pointer afterwards leading to memory corruption. This
vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
CVE-2024-6604
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird
115.12. Some of these bugs showed evidence of memory corruption and we presume
that with enough effort some of these could have been exploited to run arbitrary
code. This vulnerability affects Firefox < 128 and Firefox ESR < 115.13.
Update packages.
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
N/A
Asianux Server 7 for x86_64
- firefox-115.13.0-3.0.1.el7.AXS7.i686.rpm
MD5: 9cfc316d548056f7750de7a6b0214ba6
SHA-256: 3be753ac9f6d850bdc43b199728cf4694766d28518eba49aa2c3151394f41590
Size: 120.03 MB - firefox-115.13.0-3.0.1.el7.AXS7.x86_64.rpm
MD5: 4bc6280ba295f06ba2cf2199f73900aa
SHA-256: 25c3a201fe0bdd9e3e85eead25878221450676f9539b7a873445aaf9d719a083
Size: 116.31 MB