Lucene search

K
slackwareSlackware Linux ProjectSSA-2023-297-01
HistoryOct 24, 2023 - 10:27 p.m.

[slackware-security] mozilla-firefox

2023-10-2422:27:04
Slackware Linux Project
www.slackware.com
20
slackware 15.0
mozilla firefox
security fix
cve-2023-5721
cve-2023-5732
cve-2023-5724
cve-2023-5725
cve-2023-5726
cve-2023-5727
cve-2023-5728
cve-2023-5730
osu open source lab
rsync hosting
ftp
upgradepkg

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

46.9%

New mozilla-firefox packages are available for Slackware 15.0 and -current to
fix security issues.

Here are the details from the Slackware 15.0 ChangeLog:

patches/packages/mozilla-firefox-115.4.0esr-i686-1_slack15.0.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/115.4.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2023-46/
https://vulners.com/cve/CVE-2023-5721
https://vulners.com/cve/CVE-2023-5732
https://vulners.com/cve/CVE-2023-5724
https://vulners.com/cve/CVE-2023-5725
https://vulners.com/cve/CVE-2023-5726
https://vulners.com/cve/CVE-2023-5727
https://vulners.com/cve/CVE-2023-5728
https://vulners.com/cve/CVE-2023-5730
(* Security fix *)

Where to find the new packages:

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-firefox-115.4.0esr-i686-1_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-firefox-115.4.0esr-x86_64-1_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-firefox-115.4.0esr-i686-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-firefox-115.4.0esr-x86_64-1.txz

MD5 signatures:

Slackware 15.0 package:
fa708962e0039b54a5054f54e224fb86 mozilla-firefox-115.4.0esr-i686-1_slack15.0.txz

Slackware x86_64 15.0 package:
9823b28526eeab639ac9f7eae0c2d2cc mozilla-firefox-115.4.0esr-x86_64-1_slack15.0.txz

Slackware -current package:
e1ab19c0513a4ce7c520e7a0bc843519 xap/mozilla-firefox-115.4.0esr-i686-1.txz

Slackware x86_64 -current package:
dccda0f1f3841d9e2913d887d7b6e120 xap/mozilla-firefox-115.4.0esr-x86_64-1.txz

Installation instructions:

Upgrade the package as root:
> upgradepkg mozilla-firefox-115.4.0esr-i686-1_slack15.0.txz

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

46.9%