An update for firefox is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2023:5426-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5426 Issue date: 2023-10-04 CVE Names: CVE-2023-3600 CVE-2023-5169 CVE-2023-5171 CVE-2023-5176 CVE-2023-5217 ===================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream AUS (v. 8.2) - x86_64 Red Hat Enterprise Linux AppStream E4S (v. 8.2) - ppc64le, x86_64 Red Hat Enterprise Linux AppStream TUS (v. 8.2) - x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.3.1 ESR. Security Fix(es): * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heapbuffer overflow in vp8 encoding in libvpx (CVE-2023-5217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2222652 - CVE-2023-3600 firefox: use-after-free in workers 2240893 - CVE-2023-5169 Mozilla: Out-of-bounds write in PathOps 2240894 - CVE-2023-5171 Mozilla: Use-after-free in Ion Compiler 2240896 - CVE-2023-5176 Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 2241191 - CVE-2023-5217 libvpx: Heap buffer overflow in vp8 encoding in libvpx 6. Package List: Red Hat Enterprise Linux AppStream AUS (v. 8.2): Source: firefox-115.3.1-1.el8_2.src.rpm x86_64: firefox-115.3.1-1.el8_2.x86_64.rpm firefox-debuginfo-115.3.1-1.el8_2.x86_64.rpm firefox-debugsource-115.3.1-1.el8_2.x86_64.rpm Red Hat Enterprise Linux AppStream E4S (v. 8.2): Source: firefox-115.3.1-1.el8_2.src.rpm ppc64le: firefox-115.3.1-1.el8_2.ppc64le.rpm firefox-debuginfo-115.3.1-1.el8_2.ppc64le.rpm firefox-debugsource-115.3.1-1.el8_2.ppc64le.rpm x86_64: firefox-115.3.1-1.el8_2.x86_64.rpm firefox-debuginfo-115.3.1-1.el8_2.x86_64.rpm firefox-debugsource-115.3.1-1.el8_2.x86_64.rpm Red Hat Enterprise Linux AppStream TUS (v. 8.2): Source: firefox-115.3.1-1.el8_2.src.rpm x86_64: firefox-115.3.1-1.el8_2.x86_64.rpm firefox-debuginfo-115.3.1-1.el8_2.x86_64.rpm firefox-debugsource-115.3.1-1.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2023-3600 https://access.redhat.com/security/cve/CVE-2023-5169 https://access.redhat.com/security/cve/CVE-2023-5171 https://access.redhat.com/security/cve/CVE-2023-5176 https://access.redhat.com/security/cve/CVE-2023-5217 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlHYRXAAoJENzjgjWX9erEZb4QAIQn9IATFkj2n1jMRiXa/UKe 3cwDMBx1zLUDRXvzseSwLciklkhBN0Mehawio1F4a7ucZ+dBgb/jvHYWvTm0XZH0 4tiO/QpM5YLdEDP2Ee+JHV8tqR8RKbyKJBhl0fCYvEg6UTrb26PtUK64Fp3wZHYz 64N76TEu1KVn6VE0idPoNlhpAx/sFrlfWUH0KM7If7oxe4T8KF+XLdunuQkEYyf+ DFtxp9phgwSmrVU4zDVgRCfw6eGqH9cJNH1Z+FNaIzj8if6qwH149WcIG3E/arD7 rOT0wgcU87xvShEoXs7EioOs/34F3NqxzuJfbWuzB9ACfQMbHjQAGIflfug2rsUG tZf9b1zIPqgjvmc92OM8Ae6enxRNRmRgA4OZNcnGDfTgU6QTK9DiHTezwgaCwNoo P77fKXy0Km6SVMuOrKcnsof6bA2ZwGT/fcBJ0fY0VrqWK1CldAWAIJypM1sF+eNt tI2sFwRX8B+z5VcKCyTfusGt4Cr/cPIT1MrWpUxoraOfapdohjQ8jWWcWfcS/aNJ EM23uA4pjfwrXFH395PRk3b7F6rNpfOQYqNSE4dCQGsaP7gS8mA26/i6M0kDrG9z ujhX3OboSrqgJ3FD6mYf0V6DYWGt1r6UtlTd2mZ1ZC1YptWRM8/ibFWuYVngcOA7 evDJGsiE/hTpPCMTzN9U =zD5z -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for pcs is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: pcs security update Advisory ID: RHSA-2023:0393-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0393 Issue date: 2023-01-24 CVE Names: CVE-2022-45442 ==================================================================== 1. Summary: An update for pcs is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux High Availability E4S (v. 8.2) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux High Availability TUS (v. 8.2) - aarch64, ppc64le, s390x, x86_64 3. Description: The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Security Fix(es): * sinatra: Reflected File Download attack (CVE-2022-45442) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 2153363 - CVE-2022-45442 sinatra: Reflected File Download attack 6. Package List: Red Hat Enterprise Linux High Availability E4S (v. 8.2): Source: pcs-0.10.4-6.el8_2.4.src.rpm aarch64: pcs-0.10.4-6.el8_2.4.aarch64.rpm pcs-snmp-0.10.4-6.el8_2.4.aarch64.rpm ppc64le: pcs-0.10.4-6.el8_2.4.ppc64le.rpm pcs-snmp-0.10.4-6.el8_2.4.ppc64le.rpm s390x: pcs-0.10.4-6.el8_2.4.s390x.rpm pcs-snmp-0.10.4-6.el8_2.4.s390x.rpm x86_64: pcs-0.10.4-6.el8_2.4.x86_64.rpm pcs-snmp-0.10.4-6.el8_2.4.x86_64.rpm Red Hat Enterprise Linux High Availability TUS (v. 8.2): Source: pcs-0.10.4-6.el8_2.4.src.rpm aarch64: pcs-0.10.4-6.el8_2.4.aarch64.rpm pcs-snmp-0.10.4-6.el8_2.4.aarch64.rpm ppc64le: pcs-0.10.4-6.el8_2.4.ppc64le.rpm pcs-snmp-0.10.4-6.el8_2.4.ppc64le.rpm s390x: pcs-0.10.4-6.el8_2.4.s390x.rpm pcs-snmp-0.10.4-6.el8_2.4.s390x.rpm x86_64: pcs-0.10.4-6.el8_2.4.x86_64.rpm pcs-snmp-0.10.4-6.el8_2.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-45442 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY8+0PNzjgjWX9erEAQgNkA//edHjahjCaKOYb3cR/ahSnNXjhhl/x4nM lX18WSd2PpJ1KvUbVBXo2BL0jlfDBwTpFvdJmzTcxjrEM10i0B84c4DJDJfmcdI0 CWnh85UpwUpTGvqhxUpf8EWDNh6yrLrdDh1RjBc765/Ldy4ai67cqoCv2FzkCBRo sPtPQBLt6eVME/39tarbX3mwN6JUGPEiXmSkKv2KqN+Jf4kLzLjrs4Cj0/V0WXrW MZwMnVnfKqL+XerOCincbCvwfNByfN0seVj9wIkOaAu+Zz4YASXzZl8wtbkN3Gr5 UV0vZ68MegZPTLsvre+inn2DIQfBOH1xxN352Vz1q3lBu2TnyC/mC0Leun2lK7bY rbG7pz3piN4xOZNvOcPl0id0d6DMauDdZnNv9kF/A7K9EbqooMaR/H1I3CgsqIuo p3Mvrfx7GuLFUyGNkUMV5Gkm9Gdc64JLXFVA3kqTitp36dr2APx//D5KDbAZfWG3 fnTJgIRovcE0+/dt6RfFkFDufBh7vKYJLIf/2+GBKnDjTEXzjus627VSBXx3Z2wM 4fWCZe7YfYvQY0lxQMOKIXC1l5T+9LFgOnl7FcsgU/krR17pwU0zRBKOdKC8SsPa R1Lz0b/NKPh6ABykjKyoI/irdnp8Xy8M++98UsQHkI4oMvebl/nsx5BAjlzanBSZ FhiArI4ug2Y=YPWO -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.