|
|
Log in / Subscribe / Register

Scientific Linux alert SLSA-2023:3137-1 (firefox)

From:  Farhan Ahmed <fahmed@fnal.gov>
To:  scientific-linux-errata@listserv.fnal.gov
Subject:  Security ERRATA Important: firefox on SL7.x x86_64
Date:  Wed, 17 May 2023 15:13:24 -0000
Message-ID:  <20230517151324.664.18222@50523906fb6c>

Synopsis: Important: firefox security update Advisory ID: SLSA-2023:3137-1 Issue Date: 2023-05-17 CVE Numbers: CVE-2023-32205 CVE-2023-32206 CVE-2023-32207 CVE-2023-32211 CVE-2023-32212 CVE-2023-32213 CVE-2023-32215 -- This update upgrades Firefox to version 102.11.0 ESR. Security Fix(es): * Mozilla: Browser prompts could have been obscured by popups (CVE-2023-32205) * Mozilla: Crash in RLBox Expat driver (CVE-2023-32206) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-32207) * Mozilla: Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11 (CVE-2023-32215) * Mozilla: Content process crash due to invalid wasm code (CVE-2023-32211) * Mozilla: Potential spoof due to obscured address bar (CVE-2023-32212) * Mozilla: Potential memory corruption in FileReader::DoReadData() (CVE-2023-32213) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 firefox-102.11.0-2.el7_9.x86_64.rpm firefox-debuginfo-102.11.0-2.el7_9.x86_64.rpm firefox-102.11.0-2.el7_9.i686.rpm firefox-debuginfo-102.11.0-2.el7_9.i686.rpm - Scientific Linux Development Team


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds