Critical Mozilla Firefox Vulnerabilities Identified in Gentoo Advisory GLSA-202408-02
Summary
Multiple vulnerabilities have been discovered in Mozilla Firefox. Please
review the CVE identifiers referenced below for details.
Resolution
All Mozilla Firefox binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-bin-127.0:rapid"
All Mozilla Firefox users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-127.0:rapid"
All Mozilla Firefox ESR users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-115.12.0:esr"
All Mozilla Firefox ESR binary users should upgrade to the latest
version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/firefox-bin-115.12.0:esr"
References
[ 1 ] CVE-2024-2609 https://nvd.nist.gov/vuln/detail/CVE-2024-2609 [ 2 ] CVE-2024-3302 https://nvd.nist.gov/vuln/detail/CVE-2024-3302 [ 3 ] CVE-2024-3853 https://nvd.nist.gov/vuln/detail/CVE-2024-3853 [ 4 ] CVE-2024-3854 https://nvd.nist.gov/vuln/detail/CVE-2024-3854 [ 5 ] CVE-2024-3855 https://nvd.nist.gov/vuln/detail/CVE-2024-3855 [ 6 ] CVE-2024-3856 https://nvd.nist.gov/vuln/detail/CVE-2024-3856 [ 7 ] CVE-2024-3857 https://nvd.nist.gov/vuln/detail/CVE-2024-3857 [ 8 ] CVE-2024-3858 https://nvd.nist.gov/vuln/detail/CVE-2024-3858 [ 9 ] CVE-2024-3859 https://nvd.nist.gov/vuln/detail/CVE-2024-3859 [ 10 ] CVE-2024-3860 https://nvd.nist.gov/vuln/detail/CVE-2024-3860 [ 11 ] CVE-2024-3861 https://nvd.nist.gov/vuln/detail/CVE-2024-3861 [ 12 ] CVE-2024-3862 https://nvd.nist.gov/vuln/detail/CVE-2024-3862 [ 13 ] CVE-2024-3864 https://nvd.nist.gov/vuln/detail/CVE-2024-3864 [ 14 ] CVE-2024-3865 https://nvd.nist....
Availability
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202408-02
Concerns
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
Synopsis
Multiple vulnerabilities have been discovered in Mozilla Firefox, the
worst of which could lead to remote code execution.
Background
Mozilla Firefox is a popular open-source web browser from the Mozilla
project.
Affected Packages
Package Vulnerable Unaffected
---------------------- -------------- ---------------
www-client/firefox < 115.12.0:esr >= 115.12.0:esr
< 127.0:rapid >= 127.0:rapid
www-client/firefox-bin < 115.12.0:esr >= 115.12.0:esr
< 127.0:rapid >= 127.0:rapid
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.