Skip to navigation Skip to main content

ユーティリティー

  • サブスクリプション
  • ダウンロード
  • Red Hat Console
  • サポートの利用
Red Hat Customer Portal
  • サブスクリプション
  • ダウンロード
  • Red Hat Console
  • サポートの利用
  • 製品

    主な製品

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    すべての製品

    ダウンロードとコンテナー

    • ダウンロード
    • パッケージ
    • コンテナー

    主なリソース

    • 製品ドキュメント
    • 製品ライフサイクル
    • 製品コンプライアンス
    • エラータ
  • ナレッジ

    Red Hat Knowledge Center

    • ナレッジベースソリューション
    • ナレッジベース記事
    • カスタマーポータルラボ
    • エラータ

    主な製品ドキュメント

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    すべての製品ドキュメント

    トレーニングと認定

    • 概要
    • コースインデックス
    • 認定インデックス
    • スキル評価
  • セキュリティ

    Red Hat Product Security Center

    • セキュリティー更新
    • セキュリティーアドバイザリー
    • Red Hat CVE データベース
    • エラータ

    リファレンス

    • セキュリティー情報
    • セキュリティー評価
    • セキュリティーデータ

    主なリソース

    • セキュリティーラボ
    • バックポートに関するポリシー
    • セキュリティブログ
  • Support

    Red Hat Support

    • サポートケース
    • トラブルシューティング
    • サポートの利用
    • Red Hat サポートへのお問い合わせ

    Red Hat Community Support

    • カスタマーポータルコミュニティー
    • コミュニティーディスカッション
    • コントリビューション

    Top Resources

    • 製品ライフサイクル
    • カスタマーポータルラボ
    • Red Hat Jboss でサポートされる構成
    • Red Hat Lightspeed
または、問題のトラブルシューティングを行う.

言語の選択

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

インフラストラクチャーと管理

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

クラウドコンピューティング

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

ストレージ

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

ランタイム

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

統合および自動化

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
全製品
Red Hat 製品エラータ RHSA-2024:3958 - Security Advisory
発行日:
2024-06-17
更新日:
2024-06-17

RHSA-2024:3958 - Security Advisory

  • 概要
  • 更新パッケージ

概要

Important: firefox security update

タイプ/重大度

Security Advisory: Important

Red Hat Lightspeed パッチ分析

このアドバイザリーの影響を受けるシステムを特定し、修正します。

影響を受けるシステムの表示

トピック

An update for Firefox is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

説明

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

This update upgrades Firefox to version 115.12.0 ESR.

Security Fix(es):

  • firefox: Use-after-free in networking (CVE-2024-5702)
  • firefox: Use-after-free in JavaScript object transplant (CVE-2024-5688)
  • firefox: External protocol handlers leaked by timing attack (CVE-2024-5690)
  • firefox: Sandboxed iframes were able to bypass sandbox restrictions to open a new window (CVE-2024-5691)
  • firefox: Cross-Origin Image leak via Offscreen Canvas (CVE-2024-5693)
  • firefox: Memory Corruption in Text Fragments (CVE-2024-5696)
  • firefox: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12 (CVE-2024-5700)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解決策

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

After installing the update, Firefox must be restarted for the changes to take
effect.

影響を受ける製品

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

修正

  • BZ - 2291394 - CVE-2024-5702 Mozilla: Use-after-free in networking
  • BZ - 2291395 - CVE-2024-5688 Mozilla: Use-after-free in JavaScript object transplant
  • BZ - 2291396 - CVE-2024-5690 Mozilla: External protocol handlers leaked by timing attack
  • BZ - 2291397 - CVE-2024-5691 Mozilla: Sandboxed iframes were able to bypass sandbox restrictions to open a new window
  • BZ - 2291399 - CVE-2024-5693 Mozilla: Cross-Origin Image leak via Offscreen Canvas
  • BZ - 2291400 - CVE-2024-5696 Mozilla: Memory Corruption in Text Fragments
  • BZ - 2291401 - CVE-2024-5700 Mozilla: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12

CVE

  • CVE-2024-5688
  • CVE-2024-5690
  • CVE-2024-5691
  • CVE-2024-5693
  • CVE-2024-5696
  • CVE-2024-5700
  • CVE-2024-5702

参考資料

  • https://access.redhat.com/security/updates/classification/#important
注記: これらのパッケージのより新しいバージョンを利用できる場合があります。 詳細はパッケージ名をクリックしてください。

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
firefox-115.12.0-1.el9_0.src.rpm SHA-256: 57e0031ca4b19ac59a6d028f2ac5e53dea158b3456296991a419a7c96e5821e0
ppc64le
firefox-115.12.0-1.el9_0.ppc64le.rpm SHA-256: 3ba06dd7c1194c33603d98e6506cd95ff780693dff7d81edb6c5649bf6f7f03f
firefox-debuginfo-115.12.0-1.el9_0.ppc64le.rpm SHA-256: 65e4c192baf6d2ba20ef88f470a73a972a7809c3c29ca6883c8bbcc07137d733
firefox-debugsource-115.12.0-1.el9_0.ppc64le.rpm SHA-256: 292ee79d8a628d6bb1b338a846ebc3e9091661e7d0d3e9a7c67f2985d4a55d83

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
firefox-115.12.0-1.el9_0.src.rpm SHA-256: 57e0031ca4b19ac59a6d028f2ac5e53dea158b3456296991a419a7c96e5821e0
x86_64
firefox-115.12.0-1.el9_0.x86_64.rpm SHA-256: 270d2be4934caf35e27c564d0ae21dd7c340993569ec7c144a6c495ed198d472
firefox-debuginfo-115.12.0-1.el9_0.x86_64.rpm SHA-256: a434d98f59f3606241aee136486a9ff7c8352d5b9293847214442a61e9f67f32
firefox-debugsource-115.12.0-1.el9_0.x86_64.rpm SHA-256: d16905a90791c6841290920b39dd2d86b1ed802c765e98591bc59c90476df08d

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
firefox-115.12.0-1.el9_0.src.rpm SHA-256: 57e0031ca4b19ac59a6d028f2ac5e53dea158b3456296991a419a7c96e5821e0
aarch64
firefox-115.12.0-1.el9_0.aarch64.rpm SHA-256: 0011bc6f7a84983963041a5dd791c94ff8574fe443acb3c038f0c4a4c1b1d111
firefox-debuginfo-115.12.0-1.el9_0.aarch64.rpm SHA-256: 4188c4e626f4b43e7347e5cfcca38d515f595fe535837cc328cba30e1dcf9b55
firefox-debugsource-115.12.0-1.el9_0.aarch64.rpm SHA-256: 99ac99b8b2ee318aee3a44338dce16b661545157689d401d1b6fe9772f231081

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
firefox-115.12.0-1.el9_0.src.rpm SHA-256: 57e0031ca4b19ac59a6d028f2ac5e53dea158b3456296991a419a7c96e5821e0
s390x
firefox-115.12.0-1.el9_0.s390x.rpm SHA-256: fd7717ed5b396de9ed9dd2a79d88f64092b4c570e14565e893d00e2ca580d9df
firefox-debuginfo-115.12.0-1.el9_0.s390x.rpm SHA-256: f65a8b3613c2dff758507629d08d93978ddbac9f74237e58ede4235c1a45d642
firefox-debugsource-115.12.0-1.el9_0.s390x.rpm SHA-256: 81609dba55e44a4ac3bbaa91f738bf02dd5335efaa234bba34612a8a1aced471

Red Hat のセキュリティーに関する連絡先は secalert@redhat.com です。 連絡先の詳細は https://access.redhat.com/security/team/contact/ をご覧ください。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

クイックリンク

  • ダウンロード
  • サブスクリプション
  • サポートケース
  • カスタマーサービス
  • 製品ドキュメント

ヘルプ

  • お問い合わせ
  • カスタマーポータルについてよくある質問 (FAQ)
  • ログインに関するヘルプ

サイト情報

  • 信頼の Red Hat
  • WEB ブラウザのサポートポリシー
  • アクセシビリティ
  • 受賞と評価
  • 奥付

他の Red Hat サイト

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • Red Hat について
  • 採用情報
  • イベント
  • 各国のオフィス
  • Red Hat への問い合わせ
  • Red Hat ブログ
  • Inclusion at Red Hat
  • Red Hat グッズストア
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • プライバシーポリシー
  • 利用規約
  • すべてのポリシーとガイドライン
  • デジタルアクセシビリティー