Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE Leap 15.4/15.5 Important: MozillaFirefox Security Update Details

opensuse
Calendar Grey September 5, 2023
Dist Opensuse Esm H88
A significant security patch has been released for Chrome addressing 15 vulnerabilities, including potential information leaks and stability concerns. Update immediately!
This update for MozillaFirefox fixes the following issues: Firefox was updated to Extended Support Release 115.2.0 ESR (MFSA 2023-36) (bsc#1214606).

Description

This update for MozillaFirefox fixes the following issues:

Firefox was updated to Extended Support Release 115.2.0 ESR (MFSA 2023-36)

(bsc#1214606).

* CVE-2023-4574: Fixed memory corruption in IPC ColorPickerShownCallback

(bmo#1846688)

* CVE-2023-4575: Fixed memory corruption in IPC FilePickerShownCallback

(bmo#1846689)

* CVE-2023-4576: Fixed integer Overflow in RecordedSourceSurfaceCreation

(bmo#1846694)

* CVE-2023-4577: Fixed memory corruption in JIT UpdateRegExpStatics

(bmo#1847397)

* CVE-2023-4051: Fixed full screen notification obscured by file open dialog

(bmo#1821884)

* CVE-2023-4578: Fixed Out of Memory Exception in SpiderMonkey could have

triggered an (bmo#1839007)

* CVE-2023-4053: Fixed full screen notification obscured by external program

(bmo#1839079)

* CVE-2023-4580: Fixed push notifications saved to disk unencrypted

(bmo#1843046)

* CVE-2023-4581: Fixed XLL file extensions downloadable without warnings

(bmo#1843758)

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-3519=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-3519=1

* Desktop Applications Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-3519=1

* Desktop Applications Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-3519=1

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2

zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-3519=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-3519=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-3519=1

* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2

zypper in...

Read the Full Advisory

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* MozillaFirefox-translations-other-115.2.0-150200.152.102.1

* MozillaFirefox-branding-upstream-115.2.0-150200.152.102.1

* MozillaFirefox-115.2.0-150200.152.102.1

* MozillaFirefox-debugsource-115.2.0-150200.152.102.1

* MozillaFirefox-translations-common-115.2.0-150200.152.102.1

* MozillaFirefox-debuginfo-115.2.0-150200.152.102.1

* openSUSE Leap 15.4 (noarch)

* MozillaFirefox-devel-115.2.0-150200.152.102.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* MozillaFirefox-translations-other-115.2.0-150200.152.102.1

* MozillaFirefox-branding-upstream-115.2.0-150200.152.102.1

* MozillaFirefox-115.2.0-150200.152.102.1

* MozillaFirefox-debugsource-115.2.0-150200.152.102.1

* MozillaFirefox-translations-common-115.2.0-150200.152.102.1

* MozillaFirefox-debuginfo-115.2.0-150200.152.102.1

* openSUSE Leap 15.5 (noarch)

* MozillaFirefox-devel-115.2.0-150200.152.102.1

* Desktop Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64)

*...

Read the Full Advisory

References

* #1214606

## References:

* https://www.suse.com/security/cve/CVE-2023-4051.html

* https://www.suse.com/security/cve/CVE-2023-4053.html

* https://www.suse.com/security/cve/CVE-2023-4574.html

* https://www.suse.com/security/cve/CVE-2023-4575.html

* https://www.suse.com/security/cve/CVE-2023-4576.html

* https://www.suse.com/security/cve/CVE-2023-4577.html

* https://www.suse.com/security/cve/CVE-2023-4578.html

* https://www.suse.com/security/cve/CVE-2023-4580.html

* https://www.suse.com/security/cve/CVE-2023-4581.html

* https://www.suse.com/security/cve/CVE-2023-4582.html

* https://www.suse.com/security/cve/CVE-2023-4583.html

* https://www.suse.com/security/cve/CVE-2023-4584.html

* https://www.suse.com/security/cve/CVE-2023-4585.html

* https://bugzilla.suse.com/show_bug.cgi?id=1214606

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:3519-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here