Security update for MozillaFirefox
This update for MozillaFirefox fixes the following issues: - Updated to version 115.4.0 ESR (bsc#1216338): - CVE-2023-5721: Fixed a potential clickjack via queued up rendering. - CVE-2023-5722: Fixed a cross-Origin size and header leakage. - CVE-2023-5723: Fixed unexpected errors when handling invalid cookie characters. - CVE-2023-5724: Fixed a crash due to a large WebGL draw. - CVE-2023-5725: Fixed an issue where WebExtensions could open arbitrary URLs. - CVE-2023-5726: Fixed an issue where fullscreen notifications would be obscured by file the open dialog on macOS. - CVE-2023-5727: Fixed a download protection bypass on on Windows. - CVE-2023-5728: Fixed a crash caused by improper object tracking during GC in the JavaScript engine. - CVE-2023-5729: Fixed an issue where fullscreen notifications would be obscured by WebAuthn prompts. - CVE-2023-5730: Fixed multiple memory safety issues. - CVE-2023-5731: Fixed multiple memory safety issues.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for MozillaFirefox fixes the following issues: - Updated to version 115.4.0 ESR (bsc#1216338): - CVE-2023-5721: Fixed a potential clickjack via queued up rendering. - CVE-2023-5722: Fixed a cross-Origin size and header leakage. - CVE-2023-5723: Fixed unexpected errors when handling invalid cookie characters. - CVE-2023-5724: Fixed a crash due to a large WebGL draw. - CVE-2023-5725: Fixed an issue where WebExtensions could open arbitrary URLs. - CVE-2023-5726: Fixed an issue where fullscreen notifications would be obscured by file the open dialog on macOS. - CVE-2023-5727: Fixed a download protection bypass on on Windows. - CVE-2023-5728: Fixed a crash caused by improper object tracking during GC in the JavaScript engine. - CVE-2023-5729: Fixed an issue where fullscreen notifications would be obscured by WebAuthn prompts. - CVE-2023-5730: Fixed multiple memory safety issues. - CVE-2023-5731: Fixed multiple memory safety issues.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1216338
- https://www.suse.com/security/cve/CVE-2023-5721
- https://www.suse.com/security/cve/CVE-2023-5722
- https://www.suse.com/security/cve/CVE-2023-5723
- https://www.suse.com/security/cve/CVE-2023-5724
- https://www.suse.com/security/cve/CVE-2023-5725
- https://www.suse.com/security/cve/CVE-2023-5726
- https://www.suse.com/security/cve/CVE-2023-5727
- https://www.suse.com/security/cve/CVE-2023-5728
- https://www.suse.com/security/cve/CVE-2023-5729
- https://www.suse.com/security/cve/CVE-2023-5730
- https://www.suse.com/security/cve/CVE-2023-5731
- https://www.suse.com/support/update/announcement/2023/suse-su-20234214-1/