Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
Security Fix(es):
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.(CVE-2020-26971)
Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.(CVE-2021-29946)
{ "severity": "High" }
{ "x86_64": [ "firefox-debugsource-79.0-21.oe2003sp4.x86_64.rpm", "firefox-debuginfo-79.0-21.oe2003sp4.x86_64.rpm", "firefox-79.0-21.oe2003sp4.x86_64.rpm", "mozilla-crashreporter-firefox-debuginfo-79.0-21.oe2003sp4.x86_64.rpm" ], "aarch64": [ "firefox-79.0-21.oe2003sp4.aarch64.rpm", "firefox-debuginfo-79.0-21.oe2003sp4.aarch64.rpm", "firefox-debugsource-79.0-21.oe2003sp4.aarch64.rpm" ], "src": [ "firefox-79.0-21.oe2003sp4.src.rpm" ] }