Advisories ยป MGASA-2023-0308

Updated nss and firefox packages fix security vulnerabilities

Publication date: 06 Nov 2023
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-5721 , CVE-2023-5732 , CVE-2023-5724 , CVE-2023-5725 , CVE-2023-5728 , CVE-2023-5730

Description

The updated packages fix security vulnerabilities:

Queued up rendering could have allowed websites to clickjack.
(CVE-2023-5721)

Address bar spoofing via bidirectional characters. (CVE-2023-5732)

Large WebGL draw could have led to a crash. (CVE-2023-5724)

WebExtensions could open arbitrary URLs. (CVE-2023-5725)

Improper object tracking during GC in the JavaScript engine could have
led to a crash. (CVE-2023-5728)

Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and
Thunderbird 115.4.1. (CVE-2023-5730)
                

References

SRPMS

9/core