ALT-PU-2024-8114-1

Обновление пакета firefox-esr в ветке sisyphus_loongarch64

Версия115.11.0-alt1
Задание#0
Опубликовано2024-05-21
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (6)

CVE-2024-4769
MEDIUM5.9

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Опубликовано: 2024-05-14Изменено: 2025-04-01
CVSS 3.xСРЕДНЯЯ 5.9
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2024-4777
HIGH8.8

Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Опубликовано: 2024-05-14Изменено: 2025-03-13
CVSS 3.xВЫСОКАЯ 8.8
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H