RHSA-2024:2881: Important: firefox security update
Important: firefox security update
Other sources
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.<br>This update upgrades Firefox to version 115.11.0 ESR.<br>Security Fix(es):<br><li> firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)</li> <li> firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767)</li> <li> firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768)</li> <li> firefox: Cross-origin responses could be distinguished between script and</li> non-script content-types (CVE-2024-4769)<br><li> firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770)</li> <li> firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and</li> Thunderbird 115.11 (CVE-2024-4777)<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2881?
The severity of RHSA-2024:2881 is classified as important due to arbitrary JavaScript execution vulnerabilities in PDF.js.
How do I fix RHSA-2024:2881?
To fix RHSA-2024:2881, update Firefox to version 115.11.0-1.el7_9.
What vulnerabilities are addressed in RHSA-2024:2881?
RHSA-2024:2881 addresses vulnerabilities related to arbitrary JavaScript execution in PDF.js.
Which Red Hat products are affected by RHSA-2024:2881?
RHSA-2024:2881 affects various Red Hat Enterprise Linux Desktop and Server products, including their versions for Power and IBM z Systems.
Is a specific package required for the fix of RHSA-2024:2881?
Yes, the package required for the fix of RHSA-2024:2881 is the firefox package, specifically version 115.11.0-1.el7_9.