File _patchinfo of Package patchinfo.31291
<patchinfo incident="31291">
<issue tracker="bnc" id="1216338">VUL-0: MozillaFirefox / MozillaThunderbird: update to 119 and 115.4esr</issue>
<issue tracker="cve" id="2023-5726"/>
<issue tracker="cve" id="2023-5727"/>
<issue tracker="cve" id="2023-5724"/>
<issue tracker="cve" id="2023-5730"/>
<issue tracker="cve" id="2023-5728"/>
<issue tracker="cve" id="2023-5732"/>
<issue tracker="cve" id="2023-5725"/>
<issue tracker="cve" id="2023-5721"/>
<packager>MSirringhaus</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for MozillaThunderbird</summary>
<description>This update for MozillaThunderbird fixes the following issues:
- Updated to version 115.4.1:
- CVE-2023-5721: Fixed a potential clickjack via queued up
rendering.
- CVE-2023-5732: Fixed an address bar spoofing via bidirectional
characters
- CVE-2023-5724: Fixed a crash due to a large WebGL draw.
- CVE-2023-5725: Fixed an issue where WebExtensions could open
arbitrary URLs.
- CVE-2023-5726: Fixed an issue where fullscreen notifications would
be obscured by file the open dialog on macOS.
- CVE-2023-5727: Fixed a download protection bypass on on Windows.
- CVE-2023-5728: Fixed a crash caused by improper object tracking
during GC in the JavaScript engine.
- CVE-2023-5730: Fixed multiple memory safety issues.
</description>
</patchinfo>