Hi,

You are receiving an AlmaLinux Security update email because you subscribed to 
receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2025-01-10

Summary:

Mozilla Firefox is an open-source web browser, designed for standards 
compliance, performance, and portability.  

Security Fix(es):  

  * firefox: Use-after-free when breaking lines in text (CVE-2025-0238)
  * firefox: Memory corruption when using JavaScript Text Segmentation 
(CVE-2025-0241)
  * firefox: Alt-Svc ALPN validation failure when redirected (CVE-2025-0239)
  * firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 
134, Firefox ESR 128.6, and Thunderbird 128.6 (CVE-2025-0243)
  * firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 
134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 
128.6 (CVE-2025-0242)
  * firefox: WebChannel APIs susceptible to confused deputy attack 
(CVE-2025-0237)
  * firefox: Compartment mismatch when parsing JavaScript JSON module 
(CVE-2025-0240)


For more details about the security issue(s), including the impact, a CVSS 
score, acknowledgments, and other related information, refer to the CVE page(s) 
listed in the References section.


Full details, updated packages, references, and other related information: 
https://errata.almalinux.org/9/ALSA-2025-0080.html

This message is automatically generated, please don’t reply. For further 
questions, please, contact us via the AlmaLinux community chat: 
https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on 
https://lists.almalinux.org.

Kind regards,
AlmaLinux Team

Reply via email to