RHSA-2024:6838: Important: firefox update
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Security Fix(es): mozilla: Type confusion when looking up a property name in a "with" block (CVE-2024-8381) mozilla: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran (CVE-2024-8382) mozilla: Firefox did not ask before openings news: links in an external application (CVE-2024-8383) mozilla: Garbage collection could mis-color cross-compartment objects in OOM conditions (CVE-2024-8384) mozilla: WASM type confusion involving ArrayTypes (CVE-2024-8385) mozilla: SelectElements could be shown over another site if popups are allowed (CVE-2024-8386) mozilla: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2 (CVE-2024-8387) mozilla: Type Confusion in Async Generators in Javascript Engine (CVE-2024-7652)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:6838?
RHSA-2024:6838 has been classified with an important severity level.
How do I fix RHSA-2024:6838?
To address RHSA-2024:6838, update the affected Firefox package to version 128.2.0-1.el7_9.
Which products are affected by RHSA-2024:6838?
RHSA-2024:6838 affects Red Hat Enterprise Linux Server with Extended Life Cycle Support for IBM Power and IBM z Systems.
What packages are updated in RHSA-2024:6838?
RHSA-2024:6838 includes updates for the firefox and firefox-debuginfo packages.
Is RHSA-2024:6838 applicable to all system architectures?
RHSA-2024:6838 applies to both big endian and little endian versions of the affected products.