gpp_maybe Security update for mozillafirefox
SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-1350


This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.10.0 ESR (MSFA 2024-19) (bsc#1222535): - CVE-2024-3852: GetBoundName in the JIT returned the wrong object - CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement - CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection - CVE-2024-2609: Permission prompt input delay could expire when not in focus - CVE-2024-3859: Integer-overflow led to out-of-bounds-read in the OpenType sanitizer - CVE-2024-3861: Potential use-after-free due to AlignedBuffer self-move - CVE-2024-3863: Download Protections were bypassed by .xrm-ms files on Windows - CVE-2024-3302: Denial of Service using HTTP/2 CONTINUATION frames - CVE-2024-3864: Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10


cloud_download Downloads

Desktop Applications Module 15.5 s390x
Desktop Applications Module 15.5 x86_64
Desktop Applications Module 15.5 ppc64le
Desktop Applications Module 15.5 aarch64