USN-6074-1 fixed vulnerabilities and USN-6074-2 fixed minor regressions in
Firefox. The update introduced several minor regressions. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-32205,
CVE-2023-32207, CVE-2023-32210, CVE-2023-32211, CVE-2023-32212,
CVE-2023-32213, CVE-2023-32215, CVE-2023-32216)
Irvan Kurniawan discovered that Firefox did not properly manage memory
when using RLBox Expat driver. An attacker could potentially exploits this
issue to cause a denial of service. (CVE-2023-32206)
Anne van Kesteren discovered that Firefox did not properly validate the
import() call in service workers. An attacker could potentially exploits
this to obtain sensitive information. (CVE-2023-32208)
Sam Ezeh discovered that Firefox did not properly handle certain favicon
image files. If a user were tricked into opening a malicicous favicon file,
an attacker could cause a denial of service. (CVE-2023-32209)
More Stories
ntpd-rs-1.5.0-1.fc41
FEDORA-2025-e9be11b9ba Packages in this update: ntpd-rs-1.5.0-1.fc41 Update description: Update to version 1.5.0 (for now, without PPS feature enabled due to...
ntpd-rs-1.5.0-1.fc40
FEDORA-2025-66b73d6c72 Packages in this update: ntpd-rs-1.5.0-1.fc40 Update description: Update to version 1.5.0 (for now, without PPS feature enabled due to...
ntpd-rs-1.5.0-1.fc42
FEDORA-2025-c480cf7e5e Packages in this update: ntpd-rs-1.5.0-1.fc42 Update description: Update to version 1.5.0 (for now, without PPS feature enabled due to...
USN-7455-2: Linux kernel (FIPS) vulnerabilities
Jann Horn discovered that the watch_queue event notification subsystem in the Linux kernel contained an out-of-bounds write vulnerability. A local...
USN-7455-1: Linux kernel vulnerabilities
Jann Horn discovered that the watch_queue event notification subsystem in the Linux kernel contained an out-of-bounds write vulnerability. A local...
nodejs-bash-language-server-5.6.0-1.fc40 nodejs-pnpm-10.9.0-1.fc40
FEDORA-2025-f68a9b835d Packages in this update: nodejs-bash-language-server-5.6.0-1.fc40 nodejs-pnpm-10.9.0-1.fc40 Update description: Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language-server to...