{"id":"RLSA-2024:0608","summary":"Important: firefox security update","details":"Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nThis update upgrades Firefox to version 115.7.0 ESR.\n\nSecurity Fix(es):\n\n* Mozilla: Out of bounds write in ANGLE (CVE-2024-0741)\n\n* Mozilla: Failure to update user input timestamp (CVE-2024-0742)\n\n* Mozilla: Crash when listing printers on Linux (CVE-2024-0746)\n\n* Mozilla: Bypass of Content Security Policy when directive unsafe-inline was set (CVE-2024-0747)\n\n* Mozilla: Phishing site popup could show local origin in address bar (CVE-2024-0749)\n\n* Mozilla: Potential permissions request bypass via clickjacking (CVE-2024-0750)\n\n* Mozilla: Privilege escalation through devtools (CVE-2024-0751)\n\n* Mozilla: HSTS policy on subdomain could bypass policy of upper domain (CVE-2024-0753)\n\n* Mozilla: Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7 (CVE-2024-0755)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-02-04T19:15:12.361213Z","published":"2024-02-12T20:17:26.918627Z","upstream":["CVE-2024-0741","CVE-2024-0742","CVE-2024-0746","CVE-2024-0747","CVE-2024-0749","CVE-2024-0750","CVE-2024-0751","CVE-2024-0753","CVE-2024-0755"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2024:0608"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259926"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259927"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259928"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259929"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259930"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259931"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259932"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259933"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259934"}],"affected":[{"package":{"name":"firefox","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/firefox?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:115.7.0-1.el8_9"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:0608.json"}}],"schema_version":"1.7.3","credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}