An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2023:1479-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1479 Issue date: 2023-03-27 CVE Names: CVE-2023-0767 CVE-2023-25751 CVE-2023-25752 CVE-2023-28162 CVE-2023-28164 CVE-2023-28176 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - ppc64le, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.9.0 ESR. Security Fix(es): * nss: Arbitrary memory write via PKCS 12 (CVE-2023-0767) * Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751) * Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176) * Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752) * Mozilla: Invalid downcast in Worklets (CVE-2023-28162) * Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation (CVE-2023-28164) Formore details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2170377 - CVE-2023-0767 nss: Arbitrary memory write via PKCS 12 2178458 - CVE-2023-25751 Mozilla: Incorrect code generation during JIT compilation 2178460 - CVE-2023-25752 Mozilla: Potential out-of-bounds when accessing throttled streams 2178466 - CVE-2023-28162 Mozilla: Invalid downcast in Worklets 2178470 - CVE-2023-28164 Mozilla: URL being dragged from a removed cross-origin iframe into the same tab triggered navigation 2178472 - CVE-2023-28176 Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.1): Source: firefox-102.9.0-4.el8_1.src.rpm ppc64le: firefox-102.9.0-4.el8_1.ppc64le.rpm firefox-debuginfo-102.9.0-4.el8_1.ppc64le.rpm firefox-debugsource-102.9.0-4.el8_1.ppc64le.rpm x86_64: firefox-102.9.0-4.el8_1.x86_64.rpm firefox-debuginfo-102.9.0-4.el8_1.x86_64.rpm firefox-debugsource-102.9.0-4.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-0767 https://access.redhat.com/security/cve/CVE-2023-25751 https://access.redhat.com/security/cve/CVE-2023-25752 https://access.redhat.com/security/cve/CVE-2023-28162 https://access.redhat.com/security/cve/CVE-2023-28164 https://access.redhat.com/security/cve/CVE-2023-28176 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZCIHTtzjgjWX9erEAQg1LA//WydqHlnFtd0J2yjS8LfsRpICtcXwV8Ls ZyIxFkx1PsZI8EcZkOFp+sWv7xpAMbas0ojWUuW2Bbj0OIOE1b4G1Rq16TUrdSiG bkdNJdsWtaz2zMWfSwzWz2aBFKlrMJUyME5imnlyPivCoCOfHf52qpweqr/vh3s4 shE7IUypPY79bzOpt3H9jxnNWRyybOen5G1Q/ExEdMrB3RI7cNn1k6XvAUV60L/3 DQbVAV3z2j+lxfb8orj68C6PMM1b8fE+lMgHy5Rw/JGJUwMkZypF1GbE2e9UTtIV aMaOm+tjS83q2utk+g9n7xuDga6a9SmuQmaotjLtOsp158fJcKspCx5hmAO0eLeT PdvXdFhvfUaRMrBN+IMXIaCj6mtqRxpLl6cHO908KS9lJZQKWnmrggWmt12bnufk eWQFjjgyMaxgxTkajbPpKXt7Msp+T1EzSkWdban10GTfv+kd/mVihHMsdlLK8C+l ToIsKJCMeZkBVgL8Qus5CRq9NBrssbQtWMKXphost7USwkMdw7pKn/CHStdm+7oG UI+sERAJNoAuDLihgGTwYc7zpw3aDU/O6SECpuPEZd8AoY1L5gBbot2pIgRHXK7z 2IQG0fOYX/0AKlBgYP0RAj19NRVCXR89KP7rEdChyrBbF5i7mn0kqiuNJ+6VjWDO GH3c+X2WQwU=P4vx -----END PGP SIGNATURE----- -- RHSA-announce mailing list
gcc: GCC generates incorrect code for RDRAND/RDSEED intrinsics (CVE-2017-11671) Additional Changes: SL7 x86_64 cpp-4.8.5-28.el7.x86_64.rpm gcc-4.8.5-28.el7.x86_64.rpm gcc-base-debuginfo-4.8.5-28.el7.i686.rpm gcc-base-debuginfo-4.8.5-28.el7.x86_64.rpm gcc-debuginfo-4.8.5-28.el7.i686.rpm gcc-debuginfo-4.8.5-28.el7.x86_64.rpm libatomic-4.8.5-28.el7.i686.rpm lib [More...]. Synopsis: Low: gcc security, bug fix, and enhancement update Advisory ID: SLSA-2018:0849-1 Issue Date: 2018-04-10 CVE Numbers: CVE-2017-11671 -- Security Fix(es): * gcc: GCC generates incorrect code for RDRAND/RDSEED intrinsics (CVE-2017-11671) Additional Changes: -- SL7 x86_64 cpp-4.8.5-28.el7.x86_64.rpm gcc-4.8.5-28.el7.x86_64.rpm gcc-base-debuginfo-4.8.5-28.el7.i686.rpm gcc-base-debuginfo-4.8.5-28.el7.x86_64.rpm gcc-debuginfo-4.8.5-28.el7.i686.rpm gcc-debuginfo-4.8.5-28.el7.x86_64.rpm libatomic-4.8.5-28.el7.i686.rpm libatomic-4.8.5-28.el7.x86_64.rpm libgcc-4.8.5-28.el7.i686.rpm libgcc-4.8.5-28.el7.x86_64.rpm libgfortran-4.8.5-28.el7.i686.rpm libgfortran-4.8.5-28.el7.x86_64.rpm libgomp-4.8.5-28.el7.i686.rpm libgomp-4.8.5-28.el7.x86_64.rpm libitm-4.8.5-28.el7.i686.rpm libitm-4.8.5-28.el7.x86_64.rpm libquadmath-4.8.5-28.el7.i686.rpm libquadmath-4.8.5-28.el7.x86_64.rpm libstdc++-4.8.5-28.el7.i686.rpm libstdc++-4.8.5-28.el7.x86_64.rpm gcc-c++-4.8.5-28.el7.x86_64.rpm gcc-gfortran-4.8.5-28.el7.x86_64.rpm gcc-gnat-4.8.5-28.el7.x86_64.rpm gcc-go-4.8.5-28.el7.x86_64.rpm gcc-objc++-4.8.5-28.el7.x86_64.rpm gcc-objc-4.8.5-28.el7.x86_64.rpm gcc-plugin-devel-4.8.5-28.el7.x86_64.rpm libasan-4.8.5-28.el7.i686.rpm libasan-4.8.5-28.el7.x86_64.rpm libasan-static-4.8.5-28.el7.i686.rpm libasan-static-4.8.5-28.el7.x86_64.rpm libatomic-static-4.8.5-28.el7.i686.rpm libatomic-static-4.8.5-28.el7.x86_64.rpm libgfortran-static-4.8.5-28.el7.i686.rpm libgfortran-static-4.8.5-28.el7.x86_64.rpm libgnat-4.8.5-28.el7.i686.rpm libgnat-4.8.5-28.el7.x86_64.rpm libgnat-devel-4.8.5-28.el7.i686.rpm libgnat-devel-4.8.5-28.el7.x86_64.rpm libgnat-static-4.8.5-28.el7.i686.rpm libgnat-static-4.8.5-28.el7.x86_64.rpm libgo-4.8.5-28.el7.i686.rpm libgo-4.8.5-28.el7.x86_64.rpm libgo-devel-4.8.5-28.el7.i686.rpm libgo-devel-4.8.5-28.el7.x86_64.rpm libgo-static-4.8.5-28.el7.i686.rpm libgo-static-4.8.5-28.el7.x86_64.rpm libitm-devel-4.8.5-28.el7.i686.rpm libitm-devel-4.8.5-28.el7.x86_64.rpm libitm-static-4.8.5-28.el7.i686.rpm libitm-static-4.8.5-28.el7.x86_64.rpm libmudflap-4.8.5-28.el7.i686.rpm libmudflap-4.8.5-28.el7.x86_64.rpm libmudflap-devel-4.8.5-28.el7.i686.rpm libmudflap-devel-4.8.5-28.el7.x86_64.rpm libmudflap-static-4.8.5-28.el7.i686.rpm libmudflap-static-4.8.5-28.el7.x86_64.rpm libobjc-4.8.5-28.el7.i686.rpm libobjc-4.8.5-28.el7.x86_64.rpm libquadmath-devel-4.8.5-28.el7.i686.rpm libquadmath-devel-4.8.5-28.el7.x86_64.rpm libquadmath-static-4.8.5-28.el7.i686.rpm libquadmath-static-4.8.5-28.el7.x86_64.rpm libstdc++-devel-4.8.5-28.el7.i686.rpm libstdc++-devel-4.8.5-28.el7.x86_64.rpm libstdc++-docs-4.8.5-28.el7.x86_64.rpm libstdc++-static-4.8.5-28.el7.i686.rpm libstdc++-static-4.8.5-28.el7.x86_64.rpm libtsan-4.8.5-28.el7.x86_64.rpm libtsan-static-4.8.5-28.el7.x86_64.rpm - Scientific Linux Development Team . GCC miscompiles RDRAND/RDSEED intrinsics, causing issues. Examine the security patch notes and bug resolutions for SL7.. gcc Bug Fix, Security Advisory, Scientific Linux. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.