File _patchinfo of Package patchinfo.31237
<patchinfo incident="31237">
<issue tracker="bnc" id="1216338">VUL-0: MozillaFirefox / MozillaThunderbird: update to 119 and 115.4esr</issue>
<issue tracker="cve" id="2023-5721"/>
<issue tracker="cve" id="2023-5722"/>
<issue tracker="cve" id="2023-5723"/>
<issue tracker="cve" id="2023-5724"/>
<issue tracker="cve" id="2023-5725"/>
<issue tracker="cve" id="2023-5726"/>
<issue tracker="cve" id="2023-5727"/>
<issue tracker="cve" id="2023-5728"/>
<issue tracker="cve" id="2023-5729"/>
<issue tracker="cve" id="2023-5730"/>
<issue tracker="cve" id="2023-5731"/>
<packager>MSirringhaus</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for MozillaFirefox</summary>
<description>This update for MozillaFirefox fixes the following issues:
- Updated to version 115.4.0 ESR (bsc#1216338):
- CVE-2023-5721: Fixed a potential clickjack via queued up
rendering.
- CVE-2023-5722: Fixed a cross-Origin size and header leakage.
- CVE-2023-5723: Fixed unexpected errors when handling invalid
cookie characters.
- CVE-2023-5724: Fixed a crash due to a large WebGL draw.
- CVE-2023-5725: Fixed an issue where WebExtensions could open
arbitrary URLs.
- CVE-2023-5726: Fixed an issue where fullscreen notifications would
be obscured by file the open dialog on macOS.
- CVE-2023-5727: Fixed a download protection bypass on on Windows.
- CVE-2023-5728: Fixed a crash caused by improper object tracking
during GC in the JavaScript engine.
- CVE-2023-5729: Fixed an issue where fullscreen notifications would
be obscured by WebAuthn prompts.
- CVE-2023-5730: Fixed multiple memory safety issues.
- CVE-2023-5731: Fixed multiple memory safety issues.
</description>
</patchinfo>