{"schema_version":"1.7.3","id":"SUSE-SU-2023:3161-1","published":"2023-08-02T10:39:25Z","modified":"2026-02-04T02:25:51.716675Z","related":["CVE-2023-4045","CVE-2023-4046","CVE-2023-4047","CVE-2023-4048","CVE-2023-4049","CVE-2023-4050","CVE-2023-4052","CVE-2023-4054","CVE-2023-4055","CVE-2023-4056","CVE-2023-4057"],"upstream":["CVE-2023-4045","CVE-2023-4046","CVE-2023-4047","CVE-2023-4048","CVE-2023-4049","CVE-2023-4050","CVE-2023-4052","CVE-2023-4054","CVE-2023-4055","CVE-2023-4056","CVE-2023-4057"],"summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following security issues:\n\n  Firefox was updated to Extended Support Release 115.1.0 ESR (bsc#1213746).\n  \n  - CVE-2023-4045: Fixed cross-origin restrictions bypass with Offscreen Canvas (bmo#1833876).\n  - CVE-2023-4046: Fixed incorrect value used during WASM compilation (bmo#1837686).\n  - CVE-2023-4047: Fixed potential permissions request bypass via clickjacking (bmo#1839073).\n  - CVE-2023-4048: Fixed crash in DOMParser due to out-of-memory conditions (bmo#1841368).\n  - CVE-2023-4049: Fixed potential race conditions when releasing platform objects (bmo#1842658).\n  - CVE-2023-4050: Fixed stack buffer overflow in StorageManager (bmo#1843038).\n  - CVE-2023-4052: Fixed file deletion and privilege escalation through Firefox uninstaller (bmo#1824420).\n  - CVE-2023-4054: Fixed lack of warning when opening appref-ms files (bmo#1840777).\n  - CVE-2023-4055: Fixed cookie jar overflow caused unexpected cookie jar state (bmo#1782561).\n  - CVE-2023-4056: Fixed memory safety bugs (bmo#1820587, bmo#1824634, bmo#1839235, bmo#1842325, bmo#1843847).\n  - CVE-2023-4057: Fixed memory safety bugs (bmo#1841682).\n\n  Bugfixes:\n\n  - Remove bashisms from startup-script (bsc#1213657).\n","affected":[{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.1.0-112.173.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-devel":"115.1.0-112.173.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3161-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.1.0-112.173.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.1.0-112.173.1","MozillaFirefox-devel":"115.1.0-112.173.1","MozillaFirefox-translations-common":"115.1.0-112.173.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3161-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.1.0-112.173.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.1.0-112.173.1","MozillaFirefox-devel":"115.1.0-112.173.1","MozillaFirefox-translations-common":"115.1.0-112.173.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3161-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.1.0-112.173.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.1.0-112.173.1","MozillaFirefox-devel":"115.1.0-112.173.1","MozillaFirefox-translations-common":"115.1.0-112.173.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3161-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233161-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213657"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4054"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4056"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4057"}]}