Opened 3 weeks ago

Closed 3 weeks ago

Last modified 3 weeks ago

#19934 closed enhancement (fixed)

firefox-115.12.0

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New minor version.

Change History (5)

comment:1 by Douglas R. Reno, 3 weeks ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:2 by Douglas R. Reno, 3 weeks ago

Priority: normalelevated

comment:3 by Douglas R. Reno, 3 weeks ago

Resolution: fixed
Status: assignedclosed

Fixed at 40e69c7b4d2bf64d3dc2c8c3b1969fbe533487ba

I'll put release notes and an SA in tomorrow.

comment:4 by Douglas R. Reno, 3 weeks ago

Release notes:

Various security fixes and other quality improvements.

Security Vulnerabilities:

  • CVE-2024-5702: Use-after-free in networking (High) - Memory corruption in the networking stack could have led to a potentially exploitable crash.
  • CVE-2024-5688: Use-after-free in JavaScript object transplant (High) - If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant.
  • CVE-2024-5690: External protocol handlers leaked by timing attack (Moderate) - By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system.
  • CVE-2024-5691: Sandboxed iframes were able to bypass sandbox restrictions to open a new window (Moderate) - By tricking the browser with a X-Frame-Options header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window.
  • CVE-2024-5693: Cross-Origin Image leak via Offscreen Canvas (Moderate) - Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy.
  • CVE-2024-5696: Memory Corruption in Text Fragments (Moderate) - By manipulating the text in an <input> tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash.
  • CVE-2024-5700: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12 (High) - Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

comment:5 by Douglas R. Reno, 3 weeks ago

SA-12.1-063 issued

Note: See TracTickets for help on using tickets.