RHSA-2023:0805: Important: firefox security update
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.This update upgrades Firefox to version 102.8.0 ESR.Security Fix(es): Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728) Mozilla: Screen hijack via browser fullscreen mode (CVE-2023-25730) Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735) Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737) Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739) Mozilla: Fullscreen notification not shown in Firefox Focus (CVE-2023-25743) Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744) Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746) Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729) Mozilla: Out of bounds memory write from EncodeInputStream (CVE-2023-25732) Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4 - Upgrade
Upgrade
redhat/firefox-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4 - Upgrade
Upgrade
redhat/firefox-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4.aa - Upgrade
Upgrade
redhat/firefox-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4.aa - Upgrade
Upgrade
redhat/firefox-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_4.aa - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 102.8.0 ESR - Operational
After installing the Firefox security update to version 102.8.0 ESR, restart Firefox for the changes to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0805?
The severity of RHSA-2023:0805 is considered important due to the content security policy leak in violation reports using iframes.
How do I fix RHSA-2023:0805?
To fix RHSA-2023:0805, update Firefox to version 102.8.0 ESR by applying the latest packages from Red Hat.
Which versions of Firefox are affected by RHSA-2023:0805?
RHSA-2023:0805 affects Firefox versions prior to 102.8.0-2.el8_4.
What are the main vulnerabilities addressed in RHSA-2023:0805?
RHSA-2023:0805 primarily addresses a content security policy leak related to iframes.
Is there a specific package version I need to update for RHSA-2023:0805?
Yes, you need to update to Firefox version 102.8.0-2.el8_4 to mitigate the vulnerability described in RHSA-2023:0805.