Bug 1217230 - VUL-0: MozillaFirefox / MozillaThunderbird: update to 120 and 115.5esr
Summary: VUL-0: MozillaFirefox / MozillaThunderbird: update to 120 and 115.5esr
Status: RESOLVED FIXED
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-16 12:38 UTC by Martin Sirringhaus
Modified: 2024-01-24 15:29 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Martin Sirringhaus 2023-11-22 08:35:07 UTC
- Mozilla Firefox 120
  MFSA 2023-49
  * CVE-2023-6204 (bmo#1841050)
    Out-of-bound memory access in WebGL2 blitFramebuffer
  * CVE-2023-6205 (bmo#1854076)
    Use-after-free in MessagePort::Entangled
  * CVE-2023-6206 (bmo#1857430)
    Clickjacking permission prompts using the fullscreen
    transition
  * CVE-2023-6207 (bmo#1861344)
    Use-after-free in ReadableByteStreamQueueEntry::Buffer
  * CVE-2023-6208 (bmo#1855345)
    Using Selection API would copy contents into X11 primary
    selection.
  * CVE-2023-6209 (bmo#1858570)
    Incorrect parsing of relative URLs starting with "///"
  * CVE-2023-6210 (bmo#1801501)
    Mixed-content resources not blocked in a javascript: pop-up
  * CVE-2023-6211 (bmo#1850200)
    Clickjacking to load insecure pages in HTTPS-only mode
  * CVE-2023-6212 (bmo#1658432, bmo#1820983, bmo#1829252,
    bmo#1856072, bmo#1856091, bmo#1859030, bmo#1860943,
    bmo#1862782)
    Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5,
    and Thunderbird 115.5
  * CVE-2023-6213 (bmo#1849265, bmo#1851118, bmo#1854911)
    Memory safety bugs fixed in Firefox 120

- Mozilla Firefox 115.5
  MFSA 2023-50
  * CVE-2023-6204 (bmo#1841050)
    Out-of-bound memory access in WebGL2 blitFramebuffer
  * CVE-2023-6205 (bmo#1854076)
    Use-after-free in MessagePort::Entangled
  * CVE-2023-6206 (bmo#1857430)
    Clickjacking permission prompts using the fullscreen
    transition
  * CVE-2023-6207 (bmo#1861344)
    Use-after-free in ReadableByteStreamQueueEntry::Buffer
  * CVE-2023-6208 (bmo#1855345)
    Using Selection API would copy contents into X11 primary
    selection.
  * CVE-2023-6209 (bmo#1858570)
    Incorrect parsing of relative URLs starting with "///"
  * CVE-2023-6212 (bmo#1658432, bmo#1820983, bmo#1829252,
    bmo#1856072, bmo#1856091, bmo#1859030, bmo#1860943,
    bmo#1862782)
    Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5,
    and Thunderbird 115.5

- Mozilla Thunderbird 115.5.0
  MFSA 2023-52
  * CVE-2023-6204 (bmo#1841050)
    Out-of-bound memory access in WebGL2 blitFramebuffer
  * CVE-2023-6205 (bmo#1854076)
    Use-after-free in MessagePort::Entangled
  * CVE-2023-6206 (bmo#1857430)
    Clickjacking permission prompts using the fullscreen
    transition
  * CVE-2023-6207 (bmo#1861344)
    Use-after-free in ReadableByteStreamQueueEntry::Buffer
  * CVE-2023-6208 (bmo#1855345)
    Using Selection API would copy contents into X11 primary
    selection.
  * CVE-2023-6209 (bmo#1858570)
    Incorrect parsing of relative URLs starting with "///"
  * CVE-2023-6212 (bmo#1658432, bmo#1820983, bmo#1829252,
    bmo#1856072, bmo#1856091, bmo#1859030, bmo#1860943,
    bmo#1862782)
    Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5,
    and Thunderbird 115.5.0
Comment 4 Maintenance Automation 2023-11-22 20:30:01 UTC
SUSE-SU-2023:4533-1: An update that solves eight vulnerabilities can now be installed.

Category: security (important)
Bug References: 1216338, 1217230
CVE References: CVE-2023-5721, CVE-2023-5724, CVE-2023-5725, CVE-2023-5726, CVE-2023-5727, CVE-2023-5728, CVE-2023-5730, CVE-2023-5732
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): MozillaFirefox-115.5.0-150000.150.116.1
SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (src): MozillaFirefox-115.5.0-150000.150.116.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1 (src): MozillaFirefox-115.5.0-150000.150.116.1
SUSE CaaS Platform 4.0 (src): MozillaFirefox-115.5.0-150000.150.116.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Maintenance Automation 2023-11-22 20:30:03 UTC
SUSE-SU-2023:4532-1: An update that solves eight vulnerabilities can now be installed.

Category: security (important)
Bug References: 1216338, 1217230
CVE References: CVE-2023-5721, CVE-2023-5724, CVE-2023-5725, CVE-2023-5726, CVE-2023-5727, CVE-2023-5728, CVE-2023-5730, CVE-2023-5732
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src): MozillaFirefox-115.5.0-112.191.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): MozillaFirefox-115.5.0-112.191.1
SUSE Linux Enterprise Server 12 SP5 (src): MozillaFirefox-115.5.0-112.191.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): MozillaFirefox-115.5.0-112.191.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 OBSbugzilla Bot 2023-11-23 09:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1217230) was mentioned in
https://build.opensuse.org/request/show/1128271 Factory / MozillaThunderbird
Comment 7 Maintenance Automation 2023-11-24 12:30:07 UTC
SUSE-SU-2023:4551-1: An update that solves eight vulnerabilities can now be installed.

Category: security (important)
Bug References: 1216338, 1217230
CVE References: CVE-2023-5721, CVE-2023-5724, CVE-2023-5725, CVE-2023-5726, CVE-2023-5727, CVE-2023-5728, CVE-2023-5730, CVE-2023-5732
Sources used:
openSUSE Leap 15.4 (src): MozillaFirefox-115.5.0-150200.152.117.1
openSUSE Leap 15.5 (src): MozillaFirefox-115.5.0-150200.152.117.1
Desktop Applications Module 15-SP4 (src): MozillaFirefox-115.5.0-150200.152.117.1
Desktop Applications Module 15-SP5 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): MozillaFirefox-115.5.0-150200.152.117.1
SUSE Enterprise Storage 7.1 (src): MozillaFirefox-115.5.0-150200.152.117.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Frank Krüger 2023-11-24 17:44:14 UTC
If I am not mistaken, Firefox 120 isn't available in openSUSE yet.
Comment 9 Wolfgang Rosenauer 2023-11-25 08:06:40 UTC
It's WIP.
Comment 10 OBSbugzilla Bot 2023-11-27 15:25:02 UTC
This is an autogenerated message for OBS integration:
This bug (1217230) was mentioned in
https://build.opensuse.org/request/show/1129161 Factory / MozillaFirefox
Comment 11 Maintenance Automation 2023-11-27 16:30:09 UTC
SUSE-SU-2023:4588-1: An update that solves seven vulnerabilities can now be installed.

Category: security (important)
Bug References: 1217230
CVE References: CVE-2023-6204, CVE-2023-6205, CVE-2023-6206, CVE-2023-6207, CVE-2023-6208, CVE-2023-6209, CVE-2023-6212
Sources used:
openSUSE Leap 15.4 (src): MozillaThunderbird-115.5.0-150200.8.139.1
openSUSE Leap 15.5 (src): MozillaThunderbird-115.5.0-150200.8.139.1
SUSE Package Hub 15 15-SP4 (src): MozillaThunderbird-115.5.0-150200.8.139.1
SUSE Package Hub 15 15-SP5 (src): MozillaThunderbird-115.5.0-150200.8.139.1
SUSE Linux Enterprise Workstation Extension 15 SP4 (src): MozillaThunderbird-115.5.0-150200.8.139.1
SUSE Linux Enterprise Workstation Extension 15 SP5 (src): MozillaThunderbird-115.5.0-150200.8.139.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Maintenance Automation 2023-12-19 16:31:29 UTC
SUSE-SU-2023:4912-1: An update that solves 18 vulnerabilities can now be installed.

Category: security (important)
Bug References: 1217230, 1217974
CVE References: CVE-2023-6204, CVE-2023-6205, CVE-2023-6206, CVE-2023-6207, CVE-2023-6208, CVE-2023-6209, CVE-2023-6212, CVE-2023-6856, CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6860, CVE-2023-6861, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864, CVE-2023-6865, CVE-2023-6867
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src): MozillaFirefox-115.6.0-112.194.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): MozillaFirefox-115.6.0-112.194.1
SUSE Linux Enterprise Server 12 SP5 (src): MozillaFirefox-115.6.0-112.194.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): MozillaFirefox-115.6.0-112.194.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 OBSbugzilla Bot 2023-12-20 09:35:01 UTC
This is an autogenerated message for OBS integration:
This bug (1217230) was mentioned in
https://build.opensuse.org/request/show/1134147 Factory / MozillaThunderbird
Comment 14 Maintenance Automation 2023-12-20 16:30:13 UTC
SUSE-SU-2023:4929-1: An update that solves 18 vulnerabilities can now be installed.

Category: security (important)
Bug References: 1217230, 1217974
CVE References: CVE-2023-6204, CVE-2023-6205, CVE-2023-6206, CVE-2023-6207, CVE-2023-6208, CVE-2023-6209, CVE-2023-6212, CVE-2023-6856, CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6860, CVE-2023-6861, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864, CVE-2023-6865, CVE-2023-6867
Sources used:
SUSE CaaS Platform 4.0 (src): MozillaFirefox-115.6.0-150000.150.119.1
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): MozillaFirefox-115.6.0-150000.150.119.1
SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (src): MozillaFirefox-115.6.0-150000.150.119.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1 (src): MozillaFirefox-115.6.0-150000.150.119.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Maintenance Automation 2023-12-20 16:30:15 UTC
SUSE-SU-2023:4928-1: An update that solves 18 vulnerabilities can now be installed.

Category: security (important)
Bug References: 1217230, 1217974
CVE References: CVE-2023-6204, CVE-2023-6205, CVE-2023-6206, CVE-2023-6207, CVE-2023-6208, CVE-2023-6209, CVE-2023-6212, CVE-2023-6856, CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6860, CVE-2023-6861, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864, CVE-2023-6865, CVE-2023-6867
Sources used:
SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Enterprise Storage 7.1 (src): MozillaFirefox-115.6.0-150200.152.120.1
openSUSE Leap 15.4 (src): MozillaFirefox-115.6.0-150200.152.120.1
openSUSE Leap 15.5 (src): MozillaFirefox-115.6.0-150200.152.120.1
Desktop Applications Module 15-SP4 (src): MozillaFirefox-115.6.0-150200.152.120.1
Desktop Applications Module 15-SP5 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise Real Time 15 SP4 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): MozillaFirefox-115.6.0-150200.152.120.1
SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): MozillaFirefox-115.6.0-150200.152.120.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Marcus Meissner 2024-01-24 15:29:53 UTC
done