Bug 1181414 (CVE-2021-23953) - VUL-0: CVE-2021-23953,CVE-2021-23954,CVE-2020-26976,CVE-2021-23960,CVE-2021-23964: MozillaFirefox,MozillaThunderbird: Update to 78.7 ESR /85 (MFSA 2021-3, MFSA 2021-4)
Summary: VUL-0: CVE-2021-23953,CVE-2021-23954,CVE-2020-26976,CVE-2021-23960,CVE-2021-2...
Status: RESOLVED FIXED
Alias: CVE-2021-23953
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Charles Robertson
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/276248/
Whiteboard: CVSSv3.1:SUSE:CVE-2020-15685:6.1:(AV:...
Keywords:
Depends on:
Blocks: NOSTARTTLS
  Show dependency treegraph
 
Reported: 2021-01-26 14:35 UTC by Alexandros Toptsoglou
Modified: 2022-09-06 16:44 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2021-01-26 14:35:09 UTC
Firefox ESR 78.7

CVE-2021-23953: Cross-origin information leakage via redirected PDF requests

Description

If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data.
References

CVE-2021-23954: Type confusion when using logical assignment operators in JavaScript switch statements

Description

Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash.

CVE-2020-26976: HTTPS pages could have been intercepted by a registered service worker when they should not have been

Description

When a HTTPS page was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing.

CVE-2021-23960: Use-after-poison for incorrectly redeclared JavaScript variables during GC

Description

Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash.

CVE-2021-23964: Memory safety bugs fixed in Firefox 85 and Firefox ESR 78.7

Description

Mozilla developers Alexis Beingessner, Christian Holler, Andrew McCreight, Tyson Smith, Jon Coppeard, André Bargull, Jason Kratzer, Jesse Schwartzentruber, Steve Fink, Byron Campen reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Comment 1 Wolfgang Frisch 2021-01-26 17:23:04 UTC
Thunderbird 78.7.0
https://ftp.mozilla.org/pub/thunderbird/releases/78.7.0/
Comment 2 OBSbugzilla Bot 2021-01-26 22:20:06 UTC
This is an autogenerated message for OBS integration:
This bug (1181414) was mentioned in
https://build.opensuse.org/request/show/867008 Factory / MozillaFirefox
https://build.opensuse.org/request/show/867009 Factory / MozillaThunderbird
Comment 4 Wolfgang Frisch 2021-01-27 09:31:19 UTC
------------------------------------------------------------------------------
Mozilla Foundation Security Advisory 2021-05
Security Vulnerabilities fixed in Thunderbird 78.7
https://www.mozilla.org/en-US/security/advisories/mfsa2021-05/

CVE-2021-23953: Cross-origin information leakage via redirected PDF requests
CVE-2021-23954: Type confusion when using logical assignment operators in JavaScript switch
 statements
CVE-2020-15685: IMAP Response Injection when using STARTTLS
CVE-2020-26976: HTTPS pages could have been intercepted by a registered service worker when
 they should not have been
CVE-2021-23960: Use-after-poison for incorrectly redeclared JavaScript variables during GC
CVE-2021-23964: Memory safety bugs fixed in Thunderbird 78.7
------------------------------------------------------------------------------
CVE-2021-23953,CVE-2021-23954,CVE-2020-15685,CVE-2020-26976,CVE-2021-23960,CVE-2021-23964
Comment 6 Swamp Workflow Management 2021-01-29 14:18:42 UTC
SUSE-SU-2021:0245-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-15685,CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 15-SP1 (src):    MozillaThunderbird-78.7.0-3.119.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2021-01-29 14:21:05 UTC
SUSE-SU-2021:0241-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE OpenStack Cloud Crowbar 8 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE OpenStack Cloud 9 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE OpenStack Cloud 8 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE OpenStack Cloud 7 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server 12-SP5 (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    MozillaFirefox-78.7.0-112.45.1
SUSE Enterprise Storage 5 (src):    MozillaFirefox-78.7.0-112.45.1
HPE Helion Openstack 8 (src):    MozillaFirefox-78.7.0-112.45.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2021-01-29 14:22:01 UTC
SUSE-SU-2021:14609-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    MozillaFirefox-78.7.0-78.114.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    MozillaFirefox-78.7.0-78.114.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2021-01-29 17:16:29 UTC
SUSE-SU-2021:0246-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
SUSE Manager Server 4.0 (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Manager Retail Branch Server 4.0 (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Manager Proxy 4.0 (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Linux Enterprise Server 15-SP1-BCL (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    MozillaFirefox-78.7.0-3.128.2
SUSE Enterprise Storage 6 (src):    MozillaFirefox-78.7.0-3.128.2
SUSE CaaS Platform 4.0 (src):    MozillaFirefox-78.7.0-3.128.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2021-01-30 23:16:14 UTC
openSUSE-SU-2021:0209-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-15685,CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    MozillaThunderbird-78.7.0-lp152.2.29.1
Comment 11 Swamp Workflow Management 2021-01-30 23:18:15 UTC
openSUSE-SU-2021:0208-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-15685,CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    MozillaThunderbird-78.7.0-lp151.2.69.1
Comment 12 Swamp Workflow Management 2021-02-01 17:19:02 UTC
SUSE-SU-2021:0259-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src):    MozillaFirefox-78.7.0-8.26.2
SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src):    MozillaFirefox-78.7.0-8.26.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2021-02-01 17:27:52 UTC
SUSE-SU-2021:0257-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-15685,CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 15-SP2 (src):    MozillaThunderbird-78.7.0-8.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Swamp Workflow Management 2021-02-01 23:22:08 UTC
openSUSE-SU-2021:0222-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
openSUSE Leap 15.1 (src):    MozillaFirefox-78.7.0-lp151.2.88.2
Comment 15 Swamp Workflow Management 2021-02-01 23:23:07 UTC
openSUSE-SU-2021:0223-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1181414
CVE References: CVE-2020-26976,CVE-2021-23953,CVE-2021-23954,CVE-2021-23960,CVE-2021-23964
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    MozillaFirefox-78.7.0-lp152.2.43.1
Comment 16 Marcus Meissner 2021-08-09 12:13:46 UTC
done