Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:01710-1

Опубликовано: 26 мая 2025
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Update to Firefox Extended Support Release 128.10.1 ESR.

  • MFSA 2025-37 (bsc#1243303)
    • CVE-2025-4918: Out-of-bounds access when resolving Promise objects
    • CVE-2025-4919: Out-of-bounds access when optimizing linear sums

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
MozillaFirefox-128.10.1-112.259.1
MozillaFirefox-devel-128.10.1-112.259.1
MozillaFirefox-translations-common-128.10.1-112.259.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
MozillaFirefox-128.10.1-112.259.1
MozillaFirefox-devel-128.10.1-112.259.1
MozillaFirefox-translations-common-128.10.1-112.259.1

Описание

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:MozillaFirefox-128.10.1-112.259.1
SUSE Linux Enterprise Server 12 SP5-LTSS:MozillaFirefox-devel-128.10.1-112.259.1
SUSE Linux Enterprise Server 12 SP5-LTSS:MozillaFirefox-translations-common-128.10.1-112.259.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:MozillaFirefox-128.10.1-112.259.1

Ссылки

Описание

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:MozillaFirefox-128.10.1-112.259.1
SUSE Linux Enterprise Server 12 SP5-LTSS:MozillaFirefox-devel-128.10.1-112.259.1
SUSE Linux Enterprise Server 12 SP5-LTSS:MozillaFirefox-translations-common-128.10.1-112.259.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:MozillaFirefox-128.10.1-112.259.1

Ссылки