ALSA-2024:1912
Dashboard / Vulnerabilities / ALSA-2024:1912
ALSA-2024:1912
Summary: Important: firefox security update
Details: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.10.0 ESR. Security Fix(es): * GetBoundName in the JIT returned the wrong object (CVE-2024-3852) * Out-of-bounds-read after mis-optimized switch statement (CVE-2024-3854) * Incorrect JITting of arguments led to use-after-free during garbage collection (CVE-2024-3857) * Permission prompt input delay could expire when not in focus (CVE-2024-2609) * Integer-overflow led to out-of-bounds-read in the OpenType sanitizer (CVE-2024-3859) * Potential use-after-free due to AlignedBuffer self-move (CVE-2024-3861) * Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10 (CVE-2024-3864) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2024:1912, https://access.redhat.com/security/cve/CVE-2024-2609, https://access.redhat.com/security/cve/CVE-2024-3852, https://access.redhat.com/security/cve/CVE-2024-3854, https://access.redhat.com/security/cve/CVE-2024-3857, https://access.redhat.com/security/cve/CVE-2024-3859, https://access.redhat.com/security/cve/CVE-2024-3861, https://access.redhat.com/security/cve/CVE-2024-3864, https://bugzilla.redhat.com/2275547, https://bugzilla.redhat.com/2275549, https://bugzilla.redhat.com/2275550, https://bugzilla.redhat.com/2275551, https://bugzilla.redhat.com/2275552, https://bugzilla.redhat.com/2275553, https://bugzilla.redhat.com/2275555, https://errata.almalinux.org/8/ALSA-2024-1912.html
Affected packages
Package
Name: firefox
Purl: pkg:rpm/almalinux/firefox
Affected ranges
Type: ECOSYSTEM
Events:
