RHSA-2023:0807: Important: Mozilla Firefox security update
Mozilla Firefox is an open source web browser designed for standards compliance, performance, and portability.This update upgrades Firefox to version 102.8.0 ESR.Security Fix(es): Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728) Mozilla: Screen hijack via browser full-screen mode (CVE-2023-25730) Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735) Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737) Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739) Mozilla: Full-screen notification not shown in Firefox Focus (CVE-2023-25743) Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744) Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746) Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729) Mozilla: Out-of-bounds memory write from EncodeInputStream (CVE-2023-25732) Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6 - Upgrade
Upgrade
redhat/firefox-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6 - Upgrade
Upgrade
redhat/firefox-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6.aa - Upgrade
Upgrade
redhat/firefox-debuginfoto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6.aa - Upgrade
Upgrade
redhat/firefox-debugsourceto a version that resolves this vulnerability.Fixed in 102.8.0-2.el8_6.aa - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 102.8.0 ESR - Operational
After installing the Firefox security update to version 102.8.0 ESR, restart Firefox so the changes take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0807?
The severity of RHSA-2023:0807 is classified as moderate due to the potential for content security policy leaks.
How do I fix RHSA-2023:0807?
To fix RHSA-2023:0807, update Firefox to version 102.8.0-2.el8_6.
What vulnerabilities are addressed in RHSA-2023:0807?
RHSA-2023:0807 addresses vulnerabilities related to content security policy leaks in iframes.
Which versions of Firefox are affected by RHSA-2023:0807?
Versions of Firefox prior to 102.8.0-2.el8_6 are affected by RHSA-2023:0807.
Is there a workaround for RHSA-2023:0807 if I cannot update Firefox?
Currently, there are no recommended workarounds for RHSA-2023:0807 other than applying the security update.