RHSA-2024:1487: Critical: firefox security update
Critical: firefox security update
Other sources
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.<br>This update upgrades Firefox to version 115.9.1 ESR.<br>Security Fix(es):<br><li> nss: timing attack against RSA decryption (CVE-2023-5388)</li> <li> Mozilla: Crash in NSS TLS method (CVE-2024-0743)</li> <li> Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)</li> <li> Mozilla: Integer overflow could have led to out of bounds write (CVE-2024-2608)</li> <li> Mozilla: Improve handling of out-of-memory conditions in ICU (CVE-2024-2616)</li> <li> Mozilla: Improper handling of html and body tags enabled CSP nonce leakage (CVE-2024-2610)</li> <li> Mozilla: Clickjacking vulnerability could have led to a user accidentally granting permissions (CVE-2024-2611)</li> <li> Mozilla: Self referencing object could have potentially led to a use-after-free (CVE-2024-2612)</li> <li> Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9 (CVE-2024-2614)</li> <li> Mozilla: Privileged JavaScript Execution via Event Handlers (CVE-2024-29944)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1487?
RHSA-2024:1487 has been classified as critical due to the potential impact of a timing attack against RSA decryption.
How do I fix RHSA-2024:1487?
To address RHSA-2024:1487, you should upgrade Firefox to version 115.9.1-1.el9_0 or later.
What products are affected by RHSA-2024:1487?
RHSA-2024:1487 affects multiple Red Hat Enterprise Linux products including those for Power, ARM 64, and x86_64 architectures.
Is there a workaround for RHSA-2024:1487?
There are no specific workarounds recommended for RHSA-2024:1487; upgrading to the patched version is the preferred solution.
When was RHSA-2024:1487 released?
RHSA-2024:1487 was released as part of a security update aimed at addressing vulnerabilities in Mozilla Firefox.