SUSE-SU-2023:2173-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2173-1
SUSE-SU-2023:2173-1
Summary: Security update for MozillaFirefox
Details: This update for MozillaFirefox fixes the following issues: Extended Support Release 102.11.0 ESR (bsc#1211175): - CVE-2023-32205: Browser prompts could have been obscured by popups - CVE-2023-32206: Crash in RLBox Expat driver - CVE-2023-32207: Potential permissions request bypass via clickjacking - CVE-2023-32211: Content process crash due to invalid wasm code - CVE-2023-32212: Potential spoof due to obscured address bar - CVE-2023-32213: Potential memory corruption in FileReader::DoReadData() - CVE-2023-32214: Potential DoS via exposed protocol handlers - CVE-2023-32215: Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232173-1/, https://bugzilla.suse.com/1211175, https://www.suse.com/security/cve/CVE-2023-32205, https://www.suse.com/security/cve/CVE-2023-32206, https://www.suse.com/security/cve/CVE-2023-32207, https://www.suse.com/security/cve/CVE-2023-32211, https://www.suse.com/security/cve/CVE-2023-32212, https://www.suse.com/security/cve/CVE-2023-32213, https://www.suse.com/security/cve/CVE-2023-32214, https://www.suse.com/security/cve/CVE-2023-32215
Affected packages
Package
Name: MozillaFirefox
Purl: pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
