Bugzilla – Bug 1207119
VUL-0: MozillaFirefox / MozillaThunderbird: update to 109 and 102.7esr
Last modified: 2024-01-24 15:29:52 UTC
- Mozilla Firefox 109 MFSA 2023-01 * CVE-2023-23597 (bmo#1538028) Logic bug in process allocation allowed to read arbitrary files * CVE-2023-23598 (bmo#1800425) Arbitrary file read from GTK drag and drop on Linux * CVE-2023-23599 (bmo#1777800) Malicious command could be hidden in devtools output on Windows * CVE-2023-23600 (bmo#1787034) Notification permissions persisted between Normal and Private Browsing on Android * CVE-2023-23601 (bmo#1794268) URL being dragged from cross-origin iframe into same tab triggers navigation * CVE-2023-23602 (bmo#1800890) Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers * CVE-2023-23603 (bmo#1800832) Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive * CVE-2023-23604 (bmo#1802346) Creation of duplicate <code>SystemPrincipal</code> from less secure contexts * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974) Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7 * CVE-2023-23606 (bmo#1764974, bmo#1798591, bmo#1799201, bmo#1800446, bmo#1801248, bmo#1802100, bmo#1803393, bmo#1804626, bmo#1804971, bmo#1807004) Memory safety bugs fixed in Firefox 109 - Mozilla Firefox ESR 102.7 MFSA 2023-02 * CVE-2022-46871 (bmo#1795697) libusrsctp library out of date * CVE-2023-23598 (bmo#1800425) Arbitrary file read from GTK drag and drop on Linux * CVE-2023-23599 (bmo#1777800) Malicious command could be hidden in devtools output on Windows * CVE-2023-23601 (bmo#1794268) URL being dragged from cross-origin iframe into same tab triggers navigation * CVE-2023-23602 (bmo#1800890) Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers * CVE-2022-46877 (bmo#1795139) Fullscreen notification bypass * CVE-2023-23603 (bmo#1800832) Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974) Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7
public https://www.mozilla.org/en-US/security/advisories/mfsa2023-02/
This is an autogenerated message for OBS integration: This bug (1207119) was mentioned in https://build.opensuse.org/request/show/1059273 Factory / MozillaFirefox
SUSE-SU-2023:0113-1: An update that fixes 7 vulnerabilities is now available. Category: security (important) Bug References: 1207119 CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-23598,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605 JIRA References: Sources used: openSUSE Leap 15.4 (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise Server for SAP 15-SP3 (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise Server 15-SP3-LTSS (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise Realtime Extension 15-SP3 (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise High Performance Computing 15-SP3-LTSS (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise High Performance Computing 15-SP3-ESPOS (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Enterprise Storage 7.1 (src): MozillaFirefox-102.7.0-150200.152.73.1 SUSE Enterprise Storage 7 (src): MozillaFirefox-102.7.0-150200.152.73.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0112-1: An update that fixes 7 vulnerabilities is now available. Category: security (important) Bug References: 1207119 CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-23598,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15-SP1 (src): MozillaFirefox-102.7.0-150000.150.71.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): MozillaFirefox-102.7.0-150000.150.71.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): MozillaFirefox-102.7.0-150000.150.71.1 SUSE Enterprise Storage 6 (src): MozillaFirefox-102.7.0-150000.150.71.1 SUSE CaaS Platform 4.0 (src): MozillaFirefox-102.7.0-150000.150.71.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0111-1: An update that fixes 7 vulnerabilities is now available. Category: security (important) Bug References: 1207119 CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-23598,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): MozillaFirefox-102.7.0-112.145.1 SUSE OpenStack Cloud 9 (src): MozillaFirefox-102.7.0-112.145.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): MozillaFirefox-102.7.0-112.145.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): MozillaFirefox-102.7.0-112.145.1 SUSE Linux Enterprise Server 12-SP5 (src): MozillaFirefox-102.7.0-112.145.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): MozillaFirefox-102.7.0-112.145.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): MozillaFirefox-102.7.0-112.145.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
- Mozilla Thunderbird 102.7 MFSA 2023-03 * CVE-2022-46871 (bmo#1795697) libusrsctp library out of date * CVE-2023-23598 (bmo#1800425) Arbitrary file read from GTK drag and drop on Linux * CVE-2023-23599 (bmo#1777800) Malicious command could be hidden in devtools output on Windows * CVE-2023-23601 (bmo#1794268) URL being dragged from cross-origin iframe into same tab triggers navigation * CVE-2023-23602 (bmo#1800890) Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers * CVE-2022-46877 (bmo#1795139) Fullscreen notification bypass * CVE-2023-23603 (bmo#1800832) Calls to <code>console.log</code> allowed bypasing Content Security Policy via format directive * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974) Memory safety bugs fixed in Thunderbird 102.7
FWIW, there should be a 102.7.1 very soon now because 102.7 caused a regression. For Tumbleweed I'm planning to wait for that before submission. The releasenotes contain a note about it: https://www.thunderbird.net/en-US/thunderbird/102.7.0/releasenotes/ Upstream only set it to manual update and holds back from automatic updates as well. ETA for 102.7.1 is this week.
I'm doing the same.
This is an autogenerated message for OBS integration: This bug (1207119) was mentioned in https://build.opensuse.org/request/show/1062396 Factory / MozillaThunderbird
- Mozilla Thunderbird 102.7.1 MFSA 2023-04 * CVE-2023-0430 (bmo#1769000) Revocation status of S/Mime signature certificates was not checked
*** Bug 1207858 has been marked as a duplicate of this bug. ***
SUSE-SU-2023:0329-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1207119 CVE References: CVE-2022-46871,CVE-2022-46877,CVE-2023-0430,CVE-2023-23598,CVE-2023-23599,CVE-2023-23601,CVE-2023-23602,CVE-2023-23603,CVE-2023-23605 JIRA References: Sources used: openSUSE Leap 15.4 (src): MozillaThunderbird-102.7.1-150200.8.102.1 SUSE Linux Enterprise Workstation Extension 15-SP4 (src): MozillaThunderbird-102.7.1-150200.8.102.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src): MozillaThunderbird-102.7.1-150200.8.102.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done