GLSA 202401-10: Mozilla Firefox: Multiple Vulnerabilities
Severity: | high |
Title: | Mozilla Firefox: Multiple Vulnerabilities |
Date: | 01/07/2024 |
Bugs: |
|
ID: | 202401-10 |
Synopsis
Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could lead to remote code execution.Background
Mozilla Firefox is a popular open-source web browser from the Mozilla project.
Affected packages
Package | Vulnerable | Unaffected | Architecture(s) |
---|---|---|---|
www-client/firefox-bin | < 121.0 | >= 121.0 | All supported architectures |
www-client/firefox | < 121.0 | >= 121.0 | All supported architectures |
Description
Multiple vulnerabilities have been discovered in Mozilla Firefox. Please review the CVE identifiers referenced below for details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All Mozilla Firefox ESR binary users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=www-client/firefox-bin-115.6.0:esr"
All Mozilla Firefox ESR users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-115.6.0:esr"
All Mozilla Firefox binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-bin-121.0:rapid"
All Mozilla Firefox users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-121.0:rapid"
References
MFSA-TMP-2023-0002 MFSA-2023-40 CVE-2023-37212 CVE-2023-37210 CVE-2023-37209 CVE-2023-37206 CVE-2023-37205 CVE-2023-37204 CVE-2023-37203 CVE-2023-34417 CVE-2023-34416 CVE-2023-34415 CVE-2023-34414 CVE-2023-32216 CVE-2023-32215 CVE-2023-32214 CVE-2023-32213 CVE-2023-32212 CVE-2023-32211 CVE-2023-32210 CVE-2023-32209 CVE-2023-32208 CVE-2023-32207 CVE-2023-32206 CVE-2023-32205 CVE-2023-6873 CVE-2023-6872 CVE-2023-6871 CVE-2023-6870 CVE-2023-6869 CVE-2023-6868 CVE-2023-6867 CVE-2023-6866 CVE-2023-6865 CVE-2023-6864 CVE-2023-6863 CVE-2023-6862 CVE-2023-6861 CVE-2023-6860 CVE-2023-6859 CVE-2023-6858 CVE-2023-6857 CVE-2023-6856 CVE-2023-6213 CVE-2023-6211 CVE-2023-6210 CVE-2023-6135 CVE-2023-5758 CVE-2023-5731 CVE-2023-5729 CVE-2023-5723 CVE-2023-5722 CVE-2023-5175 CVE-2023-5173 CVE-2023-5172 CVE-2023-5170 CVE-2023-5129 CVE-2023-4863 CVE-2023-4579 CVE-2023-4058 CVE-2023-3482
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.