SUSE-SU-2023:4551-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4551-1
SUSE-SU-2023:4551-1
Summary: Security update for MozillaFirefox
Details: This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 115.5.0 ESR Placeholder changelog-entry (bsc#1217230) * Fixed: Various security fixes and other quality improvements. MFSA 2023-46 (bsc#1216338) * CVE-2023-5721: Queued up rendering could have allowed websites to clickjack * CVE-2023-5732: Address bar spoofing via bidirectional characters * CVE-2023-5724: Large WebGL draw could have led to a crash * CVE-2023-5725: WebExtensions could open arbitrary URLs * CVE-2023-5726: Full screen notification obscured by file open dialog on macOS * CVE-2023-5727: Download Protections were bypassed by .msix, .msixbundle, .appx, and .appxbundle files on Windows * CVE-2023-5728: Improper object tracking during GC in the JavaScript engine could have led to a crash. * CVE-2023-5730: Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4.1
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234551-1/, https://bugzilla.suse.com/1216338, https://bugzilla.suse.com/1217230, https://www.suse.com/security/cve/CVE-2023-5721, https://www.suse.com/security/cve/CVE-2023-5724, https://www.suse.com/security/cve/CVE-2023-5725, https://www.suse.com/security/cve/CVE-2023-5726, https://www.suse.com/security/cve/CVE-2023-5727, https://www.suse.com/security/cve/CVE-2023-5728, https://www.suse.com/security/cve/CVE-2023-5730, https://www.suse.com/security/cve/CVE-2023-5732
Affected packages
Package
Name: MozillaFirefox
Purl: pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
