Security Fix(es):
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal /../ part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.(CVE-2023-6209)
{
"severity": "Medium"
}{
"aarch64": [
"firefox-79.0-34.oe2003sp4.aarch64.rpm",
"firefox-debuginfo-79.0-34.oe2003sp4.aarch64.rpm",
"firefox-debugsource-79.0-34.oe2003sp4.aarch64.rpm"
],
"x86_64": [
"firefox-79.0-34.oe2003sp4.x86_64.rpm",
"firefox-debuginfo-79.0-34.oe2003sp4.x86_64.rpm",
"firefox-debugsource-79.0-34.oe2003sp4.x86_64.rpm",
"mozilla-crashreporter-firefox-debuginfo-79.0-34.oe2003sp4.x86_64.rpm"
],
"src": [
"firefox-79.0-34.oe2003sp4.src.rpm"
]
}