[SUSE-SU-2023:3898-1] Security update for MozillaFirefox
Severity
Important
Affected Packages
60
CVEs
5
Security update for MozillaFirefox
This update for MozillaFirefox fixes the following issues:
Update to Firefox Extended Support Release 115.3.0 ESR (MFSA 2023-42, bsc#1215575):
Security fixes:
- CVE-2023-5168: Out-of-bounds write in FilterNodeD2D1 (bmo#1846683).
- CVE-2023-5169: Out-of-bounds write in PathOps (bmo#1846685).
- CVE-2023-5171: Use-after-free in Ion Compiler (bmo#1851599).
- CVE-2023-5174: Double-free in process spawning on Windows (bmo#1848454).
- CVE-2023-5176: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (bmo#1836353, bmo#1842674, bmo#1843824, bmo#1843962, bmo#1848890, bmo#1850180, bmo#1850983, bmo#1851195).
Other fixes:
- Fix broken build with newer binutils (bsc#1215309)
- ID
- SUSE-SU-2023:3898-1
- Severity
- important
- URL
- https://www.suse.com/support/update/announcement/2023/suse-su-20233898-1/
- Published
-
2023-09-29T09:26:45
(11 months ago) - Modified
-
2023-09-29T09:26:45
(11 months ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALPINE:CVE-2023-5168
- ALPINE:CVE-2023-5169
- ALPINE:CVE-2023-5171
- ALPINE:CVE-2023-5174
- ALPINE:CVE-2023-5176
- ALSA-2023:5434
- ALSA-2023:5435
- DSA-5506-1
- DSA-5513-1
- ELSA-2023-5428
- ELSA-2023-5433
- ELSA-2023-5434
- ELSA-2023-5435
- ELSA-2023-5475
- ELSA-2023-5477
- FEDORA-2023-bbb8d72c6f
- GLSA-202402-25
- MFSA-2023-41
- MFSA-2023-42
- MFSA-2023-43
- RHSA-2023:5428
- RHSA-2023:5433
- RHSA-2023:5434
- RHSA-2023:5435
- RHSA-2023:5475
- RHSA-2023:5477
- RLSA-2023:5428
- RLSA-2023:5435
- SSA:2023-269-01
- SUSE-SU-2023:3837-1
- SUSE-SU-2023:3899-1
- SUSE-SU-2023:4016-1
- USN-6404-1
- USN-6405-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/suse-su-2023_3898-1.json | |
Suse | URL for SUSE-SU-2023:3898-1 | https://www.suse.com/support/update/announcement/2023/suse-su-20233898-1/ | |
Suse | E-Mail link for SUSE-SU-2023:3898-1 | https://lists.suse.com/pipermail/sle-security-updates/2023-September/016461.html | |
Bugzilla | SUSE Bug 1215309 | https://bugzilla.suse.com/1215309 | |
Bugzilla | SUSE Bug 1215575 | https://bugzilla.suse.com/1215575 | |
CVE | SUSE CVE CVE-2023-5168 page | https://www.suse.com/security/cve/CVE-2023-5168/ | |
CVE | SUSE CVE CVE-2023-5169 page | https://www.suse.com/security/cve/CVE-2023-5169/ | |
CVE | SUSE CVE CVE-2023-5171 page | https://www.suse.com/security/cve/CVE-2023-5171/ | |
CVE | SUSE CVE CVE-2023-5174 page | https://www.suse.com/security/cve/CVE-2023-5174/ | |
CVE | SUSE CVE CVE-2023-5176 page | https://www.suse.com/security/cve/CVE-2023-5176/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15&sp=3 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=sles-15&sp=2 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=opensuse-leap-15.5 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=x86_64&distro=opensuse-leap-15.4 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15&sp=3 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=sles-15&sp=2 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=opensuse-leap-15.5 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=s390x&distro=opensuse-leap-15.4 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15&sp=3 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=sles-15&sp=2 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=opensuse-leap-15.5 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=ppc64le&distro=opensuse-leap-15.4 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15&sp=3 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=sles-15&sp=2 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=opensuse-leap-15.5 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox?arch=aarch64&distro=opensuse-leap-15.4 | suse | MozillaFirefox | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=x86_64&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=s390x&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=ppc64le&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-other?arch=aarch64&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-other | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=x86_64&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=s390x&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=ppc64le&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15&sp=3 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=sles-15&sp=2 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | sles-15 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=opensuse-leap-15.5 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-translations-common?arch=aarch64&distro=opensuse-leap-15.4 | suse | MozillaFirefox-translations-common | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=noarch&distro=sles-15&sp=3 | suse | MozillaFirefox-devel | < 115.3.0-150200.152.108.1 | sles-15 | noarch | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=noarch&distro=sles-15&sp=2 | suse | MozillaFirefox-devel | < 115.3.0-150200.152.108.1 | sles-15 | noarch | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=noarch&distro=opensuse-leap-15.5 | suse | MozillaFirefox-devel | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | noarch | |
Affected | pkg:rpm/suse/MozillaFirefox-devel?arch=noarch&distro=opensuse-leap-15.4 | suse | MozillaFirefox-devel | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | noarch | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=x86_64&distro=opensuse-leap-15.5 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=x86_64&distro=opensuse-leap-15.4 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | x86_64 | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=s390x&distro=opensuse-leap-15.5 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=s390x&distro=opensuse-leap-15.4 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | s390x | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=ppc64le&distro=opensuse-leap-15.5 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=ppc64le&distro=opensuse-leap-15.4 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | ppc64le | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=aarch64&distro=opensuse-leap-15.5 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.5 | aarch64 | |
Affected | pkg:rpm/suse/MozillaFirefox-branding-upstream?arch=aarch64&distro=opensuse-leap-15.4 | suse | MozillaFirefox-branding-upstream | < 115.3.0-150200.152.108.1 | opensuse-leap-15.4 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |