Advisories ยป MGASA-2023-0285

Updated Firefox and Thunderbird packages fix security vulnerabilities

Publication date: 10 Oct 2023
Modification date: 10 Oct 2023
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-5169 , CVE-2023-5171 , CVE-2023-5176 , CVE-2023-5217

Description

Updated Firefox and Thunderbird packages fix security vulnerabilities:

Out-of-bounds write in PathOps. (CVE-2023-5169)

Use-after-free in Ion Compiler. (CVE-2023-5171)

Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and
Thunderbird 115.3. (CVE-2023-5176)

Heap buffer overflow in libvpx. (CVE-2023-5217)
                

References

SRPMS

9/core