File _patchinfo of Package patchinfo.31237

<patchinfo incident="31237">
  <issue tracker="bnc" id="1216338">VUL-0: MozillaFirefox / MozillaThunderbird: update to 119 and 115.4esr</issue>
  <issue tracker="cve" id="2023-5721"/>
  <issue tracker="cve" id="2023-5722"/>
  <issue tracker="cve" id="2023-5723"/>
  <issue tracker="cve" id="2023-5724"/>
  <issue tracker="cve" id="2023-5725"/>
  <issue tracker="cve" id="2023-5726"/>
  <issue tracker="cve" id="2023-5727"/>
  <issue tracker="cve" id="2023-5728"/>
  <issue tracker="cve" id="2023-5729"/>
  <issue tracker="cve" id="2023-5730"/>
  <issue tracker="cve" id="2023-5731"/>
  <packager>MSirringhaus</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for MozillaFirefox</summary>
  <description>This update for MozillaFirefox fixes the following issues:

- Updated to version 115.4.0 ESR (bsc#1216338):

  - CVE-2023-5721: Fixed a potential clickjack via queued up
    rendering.
  - CVE-2023-5722: Fixed a cross-Origin size and header leakage.
  - CVE-2023-5723: Fixed unexpected errors when handling invalid
    cookie characters.
  - CVE-2023-5724: Fixed a crash due to a large WebGL draw.
  - CVE-2023-5725: Fixed an issue where WebExtensions could open
    arbitrary URLs.
  - CVE-2023-5726: Fixed an issue where fullscreen notifications would
    be obscured by file the open dialog on macOS.
  - CVE-2023-5727: Fixed a download protection bypass on on Windows.
  - CVE-2023-5728: Fixed a crash caused by improper object tracking
    during GC in the JavaScript engine.
  - CVE-2023-5729: Fixed an issue where fullscreen notifications would
    be obscured by WebAuthn prompts.
  - CVE-2023-5730: Fixed multiple memory safety issues.
  - CVE-2023-5731: Fixed multiple memory safety issues.
</description>
</patchinfo>
openSUSE Build Service is sponsored by