Rocky Linux 9 [CIQ] Security Update: firefox / firefox-debuginfo / firefox-debugsource / firefox-x11 Multiple Vulnerabilities (crlsa-2023_0810)

high Nessus Plugin ID 355048

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ crlsa-2023_0810 advisory.

* Mozilla: Arbitrary memory write via PKCS 12 in NSS (CVE-2023-0767)

* Mozilla: Content security policy leak in violation reports using iframes (CVE-2023-25728)

* Mozilla: Screen hijack via browser fullscreen mode (CVE-2023-25730)

* Mozilla: Potential use-after-free from compartment mismatch in SpiderMonkey (CVE-2023-25735)

* Mozilla: Invalid downcast in SVGUtils::SetupStrokeGeometry (CVE-2023-25737)

* Mozilla: Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739)

* Mozilla: Fullscreen notification not shown in Firefox Focus (CVE-2023-25743)

* Mozilla: Memory safety bugs fixed in Firefox 110 and Firefox ESR 102.8 (CVE-2023-25744)

* Mozilla: Memory safety bugs fixed in Firefox ESR 102.8 (CVE-2023-25746)

* Mozilla: Extensions could have opened external schemes without user knowledge (CVE-2023-25729)

* Mozilla: Out of bounds memory write from EncodeInputStream (CVE-2023-25732)

* Mozilla: Web Crypto ImportKey crashes tab (CVE-2023-25742)

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory crlsa-2023_0810.

See Also

https://access.redhat.com/errata/RHSA-2023:0810

https://bugzilla.redhat.com/show_bug.cgi?id=2170374

https://bugzilla.redhat.com/show_bug.cgi?id=2170375

https://bugzilla.redhat.com/show_bug.cgi?id=2170376

https://bugzilla.redhat.com/show_bug.cgi?id=2170377

https://bugzilla.redhat.com/show_bug.cgi?id=2170378

https://bugzilla.redhat.com/show_bug.cgi?id=2170379

https://bugzilla.redhat.com/show_bug.cgi?id=2170381

https://bugzilla.redhat.com/show_bug.cgi?id=2170382

https://bugzilla.redhat.com/show_bug.cgi?id=2170383

https://bugzilla.redhat.com/show_bug.cgi?id=2170390

https://bugzilla.redhat.com/show_bug.cgi?id=2170391

https://bugzilla.redhat.com/show_bug.cgi?id=2170402

https://errata.build.resf.org/RLSA-2023:0810

http://www.nessus.org/u?13586881

http://www.nessus.org/u?a3df08a9

Plugin Details

Severity: High

ID: 355048

File Name: ciq_rocky_linux_9_crlsa-2023_0810.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Unknown

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-25746

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Ease: No known exploits are available

Patch Publication Date: 2/22/2023

Vulnerability Publication Date: 2/14/2023

Reference Information

CVE: CVE-2023-0767, CVE-2023-25728, CVE-2023-25729, CVE-2023-25730, CVE-2023-25732, CVE-2023-25735, CVE-2023-25737, CVE-2023-25739, CVE-2023-25742, CVE-2023-25743, CVE-2023-25744, CVE-2023-25746