Headline
RHSA-2021:0992: Red Hat Security Advisory: firefox security update
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 78.9.0 ESR. Security Fix(es):
- Mozilla: Texture upload into an unbound backing buffer resulted in an out-of-bound read (CVE-2021-23981)
- Mozilla: Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9 (CVE-2021-23987)
- Mozilla: Internal network hosts could have been probed by a malicious webpage (CVE-2021-23982)
- Mozilla: Malicious extensions could have spoofed popup information (CVE-2021-23984) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Related CVEs:
- CVE-2021-23981: Mozilla: Texture upload into an unbound backing buffer resulted in an out-of-bound read
- CVE-2021-23982: Mozilla: Internal network hosts could have been probed by a malicious webpage
- CVE-2021-23984: Mozilla: Malicious extensions could have spoofed popup information
- CVE-2021-23987: Mozilla: Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9