File _patchinfo of Package patchinfo.38115
<patchinfo incident="38115">
<issue tracker="cve" id="2025-3028"/>
<issue tracker="cve" id="2025-3029"/>
<issue tracker="cve" id="2025-3030"/>
<issue tracker="bnc" id="1240083">VUL-0: MozillaFirefox / MozillaThunderbird: update to 137 and 128.9esr</issue>
<packager>MSirringhaus</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for MozillaFirefox</summary>
<description>This update for MozillaFirefox fixes the following issues:
- Firefox Extended Support Release 128.9.0 ESR MFSA 2025-22 (bsc#1240083):
* CVE-2025-3028: Use-after-free triggered by XSLTProcessor
* CVE-2025-3029: URL Bar Spoofing via non-BMP Unicode characters
* CVE-2025-3030: Memory safety bugs fixed in Firefox 137, Thunderbird 137,
Firefox ESR 128.9, and Thunderbird 128.9
</description>
</patchinfo>