RHSA-2024:1910: Important: firefox security update
Important: firefox security update
Other sources
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.<br>This update upgrades Firefox to version 115.10.0 ESR.<br>Security Fix(es):<br><li> GetBoundName in the JIT returned the wrong object (CVE-2024-3852)</li> <li> Out-of-bounds-read after mis-optimized switch statement (CVE-2024-3854)</li> <li> Incorrect JITting of arguments led to use-after-free during garbage collection (CVE-2024-3857)</li> <li> Permission prompt input delay could expire when not in focus (CVE-2024-2609)</li> <li> Integer-overflow led to out-of-bounds-read in the OpenType sanitizer (CVE-2024-3859)</li> <li> Potential use-after-free due to AlignedBuffer self-move (CVE-2024-3861)</li> <li> Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10 (CVE-2024-3864)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1910?
The severity of RHSA-2024:1910 is classified as important.
How do I fix RHSA-2024:1910?
To fix RHSA-2024:1910, you need to upgrade Firefox to version 115.10.0-1.el7_9.
Which versions of Firefox are affected in RHSA-2024:1910?
RHSA-2024:1910 affects Firefox versions prior to 115.10.0-1.el7_9.
What products are impacted by RHSA-2024:1910?
RHSA-2024:1910 impacts various Red Hat Enterprise Linux products including Desktop, Server, and Workstation.
What security issues are addressed in RHSA-2024:1910?
RHSA-2024:1910 addresses a security issue related to GetBoundName in the JIT returning the wrong object.