Synopsis
The remote Amazon Linux 2 host is missing a security update.
Description
The version of firefox installed on the remote host is prior to 128.7.0-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2FIREFOX-2025-034 advisory.
    The origin of an external protocol handler prompt could have been obscured using a data: URL within an     `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and     Thunderbird < 132. (CVE-2024-10460)
    In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not     respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox     < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. (CVE-2024-10461)
    Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability     affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. (CVE-2024-10462)
    Repeated writes to history interface attributes could have been used to cause a Denial of Service     condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability     affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. (CVE-2024-10464)
    A clipboard paste button could persist across tabs which allowed a spoofing attack. This vulnerability     affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. (CVE-2024-10465)
    By sending a specially crafted push message, a remote server could have hung the parent process, causing     the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4,     Thunderbird < 128.4, and Thunderbird < 132. (CVE-2024-10466)
    Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs     showed evidence of memory corruption and we presume that with enough effort some of these could have been     exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4,     Thunderbird < 128.4, and Thunderbird < 132. (CVE-2024-10467)
    Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially     exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132. (CVE-2024-10468)
    A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable     browser crash. This vulnerability affects Firefox < 126. (CVE-2024-10941)
    An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence     of navigational events. This vulnerability affects Firefox < 129. (CVE-2024-8900)
    It is currently unknown if this issue is exploitable but a condition may arise where the structured clone     of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR     < 128.3, Thunderbird < 128.3, and Thunderbird < 131. (CVE-2024-9396)
    A missing delay in directory upload UI could have made it possible for an attacker to trick a user into     granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3,     Thunderbird < 128.3, and Thunderbird < 131. (CVE-2024-9397)
    A website configured to initiate a specially crafted WebTransport session could crash the Firefox process     leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3,     Thunderbird < 128.3, and Thunderbird < 131. (CVE-2024-9399)
    A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger     an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR     < 128.3, Thunderbird < 128.3, and Thunderbird < 131. (CVE-2024-9400)
    Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to     a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox     ESR < 115.19, Thunderbird < 134, and Thunderbird ESR < 128.6. (CVE-2025-0238)
    Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5,     Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we     presume that with enough effort some of these could have been exploited to run arbitrary code. This     vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firefox ESR < 115.19, Thunderbird < 134, and     Thunderbird ESR < 128.6. (CVE-2025-0242)
    An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable     crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird <     128.7, and Thunderbird < 135. (CVE-2025-1009)
    An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially     exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7,     Thunderbird < 128.7, and Thunderbird < 135. (CVE-2025-1010)
    A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker     to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7,     Thunderbird < 128.7, and Thunderbird < 135. (CVE-2025-1011)
    A race during concurrent delazification could have led to a use-after-free. This vulnerability affects     Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
    (CVE-2025-1012)
    A race condition could have led to private browsing tabs being opened in normal browsing windows. This     could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR <     128.7, Thunderbird < 128.7, and Thunderbird < 135. (CVE-2025-1013)
    Certificate length was not properly checked when added to a certificate store. In practice only trusted     data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7,     and Thunderbird < 135. (CVE-2025-1014)
    Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6,     Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we     presume that with enough effort some of these could have been exploited to run arbitrary code. This     vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and     Thunderbird < 135. (CVE-2025-1016)
    Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some     of these bugs showed evidence of memory corruption and we presume that with enough effort some of these     could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR <     128.7, Thunderbird < 128.7, and Thunderbird < 135. (CVE-2025-1017)
Tenable has extracted the preceding description block directly from the tested product security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Run 'yum update firefox' to update your system.
Plugin Details
File Name: al2_ALASFIREFOX-2025-034.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:firefox, p-cpe:/a:amazon:linux:firefox-debuginfo
Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 2/12/2025
Vulnerability Publication Date: 5/14/2024
Reference Information
CVE: CVE-2024-10460, CVE-2024-10461, CVE-2024-10462, CVE-2024-10464, CVE-2024-10465, CVE-2024-10466, CVE-2024-10467, CVE-2024-10468, CVE-2024-10941, CVE-2024-8900, CVE-2024-9396, CVE-2024-9397, CVE-2024-9399, CVE-2024-9400, CVE-2025-0238, CVE-2025-0242, CVE-2025-1009, CVE-2025-1010, CVE-2025-1011, CVE-2025-1012, CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017
IAVA: 2024-A-0279-S, 2024-A-0607-S, 2024-A-0695-S, 2024-A-0769-S, 2025-A-0009-S, 2025-A-0079-S