Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:0144

Опубликовано: 11 янв. 2025
Источник: rocky
Оценка: Important

Описание

Important: firefox security update

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

  • firefox: Use-after-free when breaking lines in text (CVE-2025-0238)

  • firefox: Memory corruption when using JavaScript Text Segmentation (CVE-2025-0241)

  • firefox: Alt-Svc ALPN validation failure when redirected (CVE-2025-0239)

  • firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6 (CVE-2025-0243)

  • firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6 (CVE-2025-0242)

  • firefox: WebChannel APIs susceptible to confused deputy attack (CVE-2025-0237)

  • firefox: Compartment mismatch when parsing JavaScript JSON module (CVE-2025-0240)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
firefoxx86_641.el8_10firefox-128.6.0-1.el8_10.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
5 месяцев назад

Security update for MozillaThunderbird

suse-cvrf
5 месяцев назад

Security update for MozillaFirefox

suse-cvrf
5 месяцев назад

Security update for MozillaFirefox

oracle-oval
5 месяцев назад

ELSA-2025-0144: firefox security update (IMPORTANT)

oracle-oval
5 месяцев назад

ELSA-2025-0132: firefox security update (IMPORTANT)