Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in firefox
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in firefox
ID: RHSA-2025:2481
Distribution: Red Hat
Plattformen: Red Hat Enterprise Linux AppStream E4S (v.9.0)
Datum: Mo, 10. März 2025, 16:19
Referenzen: https://access.redhat.com/errata/RHSA-2025:2481
https://bugzilla.redhat.com/show_bug.cgi?id=2349792
https://bugzilla.redhat.com/show_bug.cgi?id=2349796
https://bugzilla.redhat.com/show_bug.cgi?id=2349786
https://bugzilla.redhat.com/show_bug.cgi?id=2349795
https://access.redhat.com/security/cve/CVE-2025-1933
https://access.redhat.com/security/cve/CVE-2025-1935
https://access.redhat.com/security/cve/CVE-2025-1932
https://bugzilla.redhat.com/show_bug.cgi?id=2349793
https://access.redhat.com/security/cve/CVE-2025-1936
https://access.redhat.com/security/cve/CVE-2025-1934
https://access.redhat.com/security/cve/CVE-2025-1938
https://access.redhat.com/security/cve/CVE-2025-1930
https://access.redhat.com/security/cve/CVE-2025-1931
https://bugzilla.redhat.com/show_bug.cgi?id=2349794
https://access.redhat.com/security/cve/CVE-2025-1937
https://bugzilla.redhat.com/show_bug.cgi?id=2349797
https://bugzilla.redhat.com/show_bug.cgi?id=2349787
https://bugzilla.redhat.com/show_bug.cgi?id=2349790
Applikationen: Mozilla Firefox

Originalnachricht

An update for firefox is now available for Red Hat Enterprise Linux 9.0 Update
Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance, and portability.

Security Fix(es):

* firefox: Use-after-free in WebTransportChild (CVE-2025-1931)

* firefox: AudioIPC StreamData could trigger a use-after-free in the Browser
process (CVE-2025-1930)

* firefox: Unexpected GC during RegExp bailout processing (CVE-2025-1934)

* firefox: Clickjacking the registerProtocolHandler info-bar Reporter
(CVE-2025-1935)

* firefox: thunderbird: Memory safety bugs fixed in Firefox 136, Thunderbird
136, Firefox ESR 128.8, and Thunderbird 128.8 (CVE-2025-1938)

* firefox: JIT corruption of WASM i32 return values on 64-bit CPUs
(CVE-2025-1933)

* firefox: thunderbird: Memory safety bugs fixed in Firefox 136, Thunderbird
136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8 (CVE-2025-1937)

* firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access
(CVE-2025-1932)

* firefox: Adding %00 and a fake extension to a jar: URL changed the
interpretation of the contents (CVE-2025-1936)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2025-1930: Use After Free (CWE-416)
CVE-2025-1931: Use After Free (CWE-416)
CVE-2025-1932: Out-of-bounds Read (CWE-125)
CVE-2025-1933: Access of Resource Using Incompatible Type ('Type
Confusion') (CWE-843)
CVE-2025-1934: Improper Cleanup on Thrown Exception (CWE-460)
CVE-2025-1935: Improper Restriction of Rendered UI Layers or Frames (CWE-1021)
CVE-2025-1936: Improper Check for Unusual or Exceptional Conditions (CWE-754)
CVE-2025-1937: Buffer Copy without Checking Size of Input ('Classic Buffer
Overflow') (CWE-120)
CVE-2025-1938: Buffer Copy without Checking Size of Input ('Classic Buffer
Overflow') (CWE-120)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung