Mozilla Firefox is a standalone web browser, designed for standards compliance and performance. Its functionality can be enhanced via a plethora of extensions.
Security Fix(es):
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as .url
by including an invalid character in the extension. Note: This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.(CVE-2024-5692)
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.(CVE-2024-6603)
{ "severity": "High" }
{ "x86_64": [ "firefox-128.7.0-1.oe2403.x86_64.rpm", "firefox-debuginfo-128.7.0-1.oe2403.x86_64.rpm", "firefox-debugsource-128.7.0-1.oe2403.x86_64.rpm" ], "src": [ "firefox-128.7.0-1.oe2403.src.rpm" ], "aarch64": [ "firefox-128.7.0-1.oe2403.aarch64.rpm", "firefox-debuginfo-128.7.0-1.oe2403.aarch64.rpm", "firefox-debugsource-128.7.0-1.oe2403.aarch64.rpm" ] }