RHSA-2025:10073: Important: firefox security update
Important: firefox security update
Other sources
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.Security Fix(es): firefox: Content-Disposition header ignored when a file is included in an embed or object tag (CVE-2025-6430) firefox: Use-after-free in FontFaceSet (CVE-2025-6424) firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com (CVE-2025-6429) firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID (CVE-2025-6425) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:10073?
The severity of RHSA-2025:10073 is classified as Important.
How do I fix RHSA-2025:10073?
To fix RHSA-2025:10073, update the firefox package to version 128.12.0-1.el10_0 or later.
Which systems are affected by RHSA-2025:10073?
RHSA-2025:10073 affects various versions of Red Hat Enterprise Linux, including IBM z Systems, Power little endian, and ARM 64.
What are the main security issues addressed in RHSA-2025:10073?
RHSA-2025:10073 addresses a security vulnerability where the Content-Disposition header is ignored when a file is included in an embed or object tag.
What packages are involved in the RHSA-2025:10073 update?
The packages involved in the RHSA-2025:10073 update include firefox, firefox-debuginfo, and firefox-debugsource.