Opened 10 months ago

Closed 10 months ago

Last modified 8 months ago

#22498 closed enhancement (fixed)

firefox-140.6.0esr and spidermonkey (js)

Reported by: Joe Locash Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Release notes not available yet.

Change History (8)

comment:1 by zeckma, 10 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by Xi Ruoyao, 10 months ago

Summary: firefox-140.6.0esr → firefox-140.6.0esr (and spidermonkey)

comment:3 by Bruce Dubbs, 10 months ago

Summary: firefox-140.6.0esr (and spidermonkey) → firefox-140.6.0esr and spidermonkey (js)

comment:4 by zeckma, 10 months ago

Priority: normal → high

Security fixes (High)

Total (10); High (5); Moderate (5)

  • CVE-2025-14321 (High): Use-after-free in the WebRTC: Signaling component
  • CVE-2025-14322 (High): Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
  • CVE-2025-14323 (High): Privilege escalation in the DOM: Notifications component
  • CVE-2025-14324 (High): JIT miscompilation in the JavaScript Engine: JIT component
  • CVE-2025-14325 (High): JIT miscompilation in the JavaScript Engine: JIT component
  • CVE-2025-14328 (Moderate): Privilege escalation in the Netmonitor component
  • CVE-2025-14329 (Moderate): Privilege escalation in the Netmonitor component
  • CVE-2025-14330 (Moderate): JIT miscompilation in the JavaScript Engine: JIT component
  • CVE-2025-14331 (Moderate): Same-origin policy bypass in the Request Handling component
  • CVE-2025-14333 (Moderate): Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146

comment:5 by zeckma, 10 months ago

Spidermonkey should be subject to: CVE-2025-14322, CVE-2025-14324, CVE-2025-14325, and CVE-2025-14330.

comment:6 by zeckma, 10 months ago

Fixed at 52a308e3166b3fbacf5b709bf1e421c72ad2aa75. Leaving open for SA filing.

comment:7 by zeckma, 10 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-058 and SA-12.4-059 issued.

comment:8 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.