MGASA-2023-0342
Dashboard / Vulnerabilities / MGASA-2023-0342
MGASA-2023-0342
Summary: Updated firefox packages fix security vulnerabilities
Details: The updated packages fix security vulnerabilities. Out-of-bound memory access in WebGL2 blitFramebuffer. (CVE-2023-6204) Use-after-free in MessagePort::Entangled. (CVE-2023-6205) Clickjacking permission prompts using the fullscreen transition. (CVE-2023-6206) Use-after-free in ReadableByteStreamQueueEntry::Buffer. (CVE-2023-6207) Using Selection API would copy contents into X11 primary selection. (CVE-2023-6208) Incorrect parsing of relative URLs starting with "///". (CVE-2023-6209) Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. (CVE-2023-6212)
References: https://advisories.mageia.org/MGASA-2023-0342.html, https://bugs.mageia.org/show_bug.cgi?id=32551, https://www.mozilla.org/en-US/firefox/115.5.0/releasenotes/, https://www.mozilla.org/en-US/security/advisories/mfsa2023-50/, https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_95.html
Affected packages
Package
Name: rootcerts
Purl: pkg:rpm/mageia/rootcerts?arch=source&distro=mageia-9
Affected ranges
Type: ECOSYSTEM
Events:
