Lucene search

K
redhatRedHatRHSA-2023:0295
HistoryJan 23, 2023 - 8:26 a.m.

(RHSA-2023:0295) Important: firefox security update

2023-01-2308:26:13
access.redhat.com
10
mozilla firefox
security update
version 102.7.0 esr
libusrsctp library
arbitrary file read
memory safety bugs
malicious command
url navigation
content security policy
fullscreen notification
console.log bypass

0.004 Low

EPSS

Percentile

72.2%

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 102.7.0 ESR.

Security Fix(es):

  • Mozilla: libusrsctp library out of date (CVE-2022-46871)

  • Mozilla: Arbitrary file read from GTK drag and drop on Linux (CVE-2023-23598)

  • Mozilla: Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7 (CVE-2023-23605)

  • Mozilla: Malicious command could be hidden in devtools output (CVE-2023-23599)

  • Mozilla: URL being dragged from cross-origin iframe into same tab triggers navigation (CVE-2023-23601)

  • Mozilla: Content Security Policy wasn’t being correctly applied to WebSockets in WebWorkers (CVE-2023-23602)

  • Mozilla: Fullscreen notification bypass (CVE-2022-46877)

  • Mozilla: Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive (CVE-2023-23603)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.