{"schema_version":"1.7.3","id":"SUSE-SU-2023:3163-1","published":"2023-08-02T10:44:54Z","modified":"2026-02-04T03:34:43.694596Z","related":["CVE-2023-4045","CVE-2023-4046","CVE-2023-4047","CVE-2023-4048","CVE-2023-4049","CVE-2023-4050","CVE-2023-4052","CVE-2023-4054","CVE-2023-4055","CVE-2023-4056","CVE-2023-4057"],"upstream":["CVE-2023-4045","CVE-2023-4046","CVE-2023-4047","CVE-2023-4048","CVE-2023-4049","CVE-2023-4050","CVE-2023-4052","CVE-2023-4054","CVE-2023-4055","CVE-2023-4056","CVE-2023-4057"],"summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following security issues:\n\n  Firefox was updated to Extended Support Release 115.1.0 ESR (bsc#1213746).\n\n  - CVE-2023-4045: Fixed cross-origin restrictions bypass with Offscreen Canvas (bmo#1833876).\n  - CVE-2023-4046: Fixed incorrect value used during WASM compilation (bmo#1837686).\n  - CVE-2023-4047: Fixed potential permissions request bypass via clickjacking (bmo#1839073).\n  - CVE-2023-4048: Fixed crash in DOMParser due to out-of-memory conditions (bmo#1841368).\n  - CVE-2023-4049: Fixed potential race conditions when releasing platform objects (bmo#1842658).\n  - CVE-2023-4050: Fixed stack buffer overflow in StorageManager (bmo#1843038).\n  - CVE-2023-4052: Fixed file deletion and privilege escalation through Firefox uninstaller (bmo#1824420).\n  - CVE-2023-4054: Fixed lack of warning when opening appref-ms files (bmo#1840777).\n  - CVE-2023-4055: Fixed cookie jar overflow caused unexpected cookie jar state (bmo#1782561).\n  - CVE-2023-4056: Fixed memory safety bugs (bmo#1820587, bmo#1824634, bmo#1839235, bmo#1842325, bmo#1843847).\n  - CVE-2023-4057: Fixed memory safety bugs (bmo#1841682).\n    \n  Bugfixes:\n\n  - Remove bashisms from startup-script (bsc#1213657).\n","affected":[{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.1.0-150000.150.97.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.1.0-150000.150.97.1","MozillaFirefox-devel":"115.1.0-150000.150.97.1","MozillaFirefox-translations-common":"115.1.0-150000.150.97.1","MozillaFirefox-translations-other":"115.1.0-150000.150.97.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3163-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP1-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.1.0-150000.150.97.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.1.0-150000.150.97.1","MozillaFirefox-devel":"115.1.0-150000.150.97.1","MozillaFirefox-translations-common":"115.1.0-150000.150.97.1","MozillaFirefox-translations-other":"115.1.0-150000.150.97.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3163-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP1","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.1.0-150000.150.97.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.1.0-150000.150.97.1","MozillaFirefox-devel":"115.1.0-150000.150.97.1","MozillaFirefox-translations-common":"115.1.0-150000.150.97.1","MozillaFirefox-translations-other":"115.1.0-150000.150.97.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3163-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233163-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213657"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4054"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4056"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4057"}]}