Bug 1207119 - VUL-0: MozillaFirefox / MozillaThunderbird: update to 109 and 102.7esr
Summary: VUL-0: MozillaFirefox / MozillaThunderbird: update to 109 and 102.7esr
Status: RESOLVED FIXED
: CVE-2023-0430 (view as bug list)
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/353691/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-23598:7.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-01-13 08:17 UTC by Martin Sirringhaus
Modified: 2024-01-24 15:29 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Martin Sirringhaus 2023-01-17 15:06:13 UTC
- Mozilla Firefox 109
  MFSA 2023-01
  * CVE-2023-23597 (bmo#1538028)
    Logic bug in process allocation allowed to read arbitrary
    files
  * CVE-2023-23598 (bmo#1800425)
    Arbitrary file read from GTK drag and drop on Linux
  * CVE-2023-23599 (bmo#1777800)
    Malicious command could be hidden in devtools output on
    Windows
  * CVE-2023-23600 (bmo#1787034)
    Notification permissions persisted between Normal and Private
    Browsing on Android
  * CVE-2023-23601 (bmo#1794268)
    URL being dragged from cross-origin iframe into same tab
    triggers navigation
  * CVE-2023-23602 (bmo#1800890)
    Content Security Policy wasn't being correctly applied to
    WebSockets in WebWorkers
  * CVE-2023-23603 (bmo#1800832)
    Calls to <code>console.log</code> allowed bypasing Content
    Security Policy via format directive
  * CVE-2023-23604 (bmo#1802346)
    Creation of duplicate <code>SystemPrincipal</code> from less
    secure contexts
  * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)
    Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
  * CVE-2023-23606 (bmo#1764974, bmo#1798591, bmo#1799201,
    bmo#1800446, bmo#1801248, bmo#1802100, bmo#1803393,
    bmo#1804626, bmo#1804971, bmo#1807004)
    Memory safety bugs fixed in Firefox 109

- Mozilla Firefox ESR 102.7
  MFSA 2023-02
  * CVE-2022-46871 (bmo#1795697)
    libusrsctp library out of date
  * CVE-2023-23598 (bmo#1800425)
    Arbitrary file read from GTK drag and drop on Linux
  * CVE-2023-23599 (bmo#1777800)
    Malicious command could be hidden in devtools output on
    Windows
  * CVE-2023-23601 (bmo#1794268)
    URL being dragged from cross-origin iframe into same tab
    triggers navigation
  * CVE-2023-23602 (bmo#1800890)
    Content Security Policy wasn't being correctly applied to
    WebSockets in WebWorkers
  * CVE-2022-46877 (bmo#1795139)
    Fullscreen notification bypass
  * CVE-2023-23603 (bmo#1800832)
    Calls to <code>console.log</code> allowed bypasing Content
    Security Policy via format directive
  * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)
    Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
Comment 3 Marcus Meissner 2023-01-17 15:10:59 UTC
public https://www.mozilla.org/en-US/security/advisories/mfsa2023-02/
Comment 4 OBSbugzilla Bot 2023-01-18 08:05:04 UTC
This is an autogenerated message for OBS integration:
This bug (1207119) was mentioned in
https://build.opensuse.org/request/show/1059273 Factory / MozillaFirefox
Comment 5 Swamp Workflow Management 2023-01-20 14:21:03 UTC
SUSE-SU-2023:0113-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1207119
CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-23598,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise Server for SAP 15-SP3 (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise Server 15-SP3-LTSS (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise Realtime Extension 15-SP3 (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise High Performance Computing 15-SP3-LTSS (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise High Performance Computing 15-SP3-ESPOS (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Enterprise Storage 7.1 (src):    MozillaFirefox-102.7.0-150200.152.73.1
SUSE Enterprise Storage 7 (src):    MozillaFirefox-102.7.0-150200.152.73.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2023-01-20 14:27:55 UTC
SUSE-SU-2023:0112-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1207119
CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-23598,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    MozillaFirefox-102.7.0-150000.150.71.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    MozillaFirefox-102.7.0-150000.150.71.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    MozillaFirefox-102.7.0-150000.150.71.1
SUSE Enterprise Storage 6 (src):    MozillaFirefox-102.7.0-150000.150.71.1
SUSE CaaS Platform 4.0 (src):    MozillaFirefox-102.7.0-150000.150.71.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2023-01-20 14:32:29 UTC
SUSE-SU-2023:0111-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1207119
CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-23598,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    MozillaFirefox-102.7.0-112.145.1
SUSE OpenStack Cloud 9 (src):    MozillaFirefox-102.7.0-112.145.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    MozillaFirefox-102.7.0-112.145.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    MozillaFirefox-102.7.0-112.145.1
SUSE Linux Enterprise Server 12-SP5 (src):    MozillaFirefox-102.7.0-112.145.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    MozillaFirefox-102.7.0-112.145.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    MozillaFirefox-102.7.0-112.145.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Martin Sirringhaus 2023-01-23 10:02:31 UTC
- Mozilla Thunderbird 102.7
  MFSA 2023-03
  * CVE-2022-46871 (bmo#1795697)
    libusrsctp library out of date
  * CVE-2023-23598 (bmo#1800425)
    Arbitrary file read from GTK drag and drop on Linux
  * CVE-2023-23599 (bmo#1777800)
    Malicious command could be hidden in devtools output on
    Windows
  * CVE-2023-23601 (bmo#1794268)
    URL being dragged from cross-origin iframe into same tab
    triggers navigation
  * CVE-2023-23602 (bmo#1800890)
    Content Security Policy wasn't being correctly applied to
    WebSockets in WebWorkers
  * CVE-2022-46877 (bmo#1795139)
    Fullscreen notification bypass
  * CVE-2023-23603 (bmo#1800832)
    Calls to <code>console.log</code> allowed bypasing Content
    Security Policy via format directive
  * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)
    Memory safety bugs fixed in Thunderbird 102.7
Comment 9 Wolfgang Rosenauer 2023-01-23 10:41:57 UTC
FWIW, there should be a 102.7.1 very soon now because 102.7 caused a regression.
For Tumbleweed I'm planning to wait for that before submission.
The releasenotes contain a note about it:
https://www.thunderbird.net/en-US/thunderbird/102.7.0/releasenotes/

Upstream only set it to manual update and holds back from automatic updates as well.
ETA for 102.7.1 is this week.
Comment 10 Martin Sirringhaus 2023-01-23 10:45:07 UTC
I'm doing the same.
Comment 11 OBSbugzilla Bot 2023-02-01 08:45:03 UTC
This is an autogenerated message for OBS integration:
This bug (1207119) was mentioned in
https://build.opensuse.org/request/show/1062396 Factory / MozillaThunderbird
Comment 12 Martin Sirringhaus 2023-02-01 09:49:10 UTC
- Mozilla Thunderbird 102.7.1
  MFSA 2023-04
  * CVE-2023-0430 (bmo#1769000)
    Revocation status of S/Mime signature certificates was not
    checked
Comment 14 Cathy Hu 2023-02-06 14:19:24 UTC
*** Bug 1207858 has been marked as a duplicate of this bug. ***
Comment 15 Swamp Workflow Management 2023-02-09 14:19:11 UTC
SUSE-SU-2023:0329-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1207119
CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-0430,CVE-2023-23598,CVE-2023-23599,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    MozillaThunderbird-102.7.1-150200.8.102.1
SUSE Linux Enterprise Workstation Extension 15-SP4 (src):    MozillaThunderbird-102.7.1-150200.8.102.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    MozillaThunderbird-102.7.1-150200.8.102.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Marcus Meissner 2024-01-24 15:29:52 UTC
done