{"schema_version":"1.7.3","id":"SUSE-SU-2023:4214-1","published":"2023-10-26T08:38:07Z","modified":"2026-02-04T04:06:20.731727Z","related":["CVE-2023-5721","CVE-2023-5722","CVE-2023-5723","CVE-2023-5724","CVE-2023-5725","CVE-2023-5726","CVE-2023-5727","CVE-2023-5728","CVE-2023-5729","CVE-2023-5730","CVE-2023-5731"],"upstream":["CVE-2023-5721","CVE-2023-5722","CVE-2023-5723","CVE-2023-5724","CVE-2023-5725","CVE-2023-5726","CVE-2023-5727","CVE-2023-5728","CVE-2023-5729","CVE-2023-5730","CVE-2023-5731"],"summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following issues:\n\n- Updated to version 115.4.0 ESR (bsc#1216338):\n\n  - CVE-2023-5721: Fixed a potential clickjack via queued up\n    rendering.\n  - CVE-2023-5722: Fixed a cross-Origin size and header leakage.\n  - CVE-2023-5723: Fixed unexpected errors when handling invalid\n    cookie characters.\n  - CVE-2023-5724: Fixed a crash due to a large WebGL draw.\n  - CVE-2023-5725: Fixed an issue where WebExtensions could open\n    arbitrary URLs.\n  - CVE-2023-5726: Fixed an issue where fullscreen notifications would\n    be obscured by file the open dialog on macOS.\n  - CVE-2023-5727: Fixed a download protection bypass on on Windows.\n  - CVE-2023-5728: Fixed a crash caused by improper object tracking\n    during GC in the JavaScript engine.\n  - CVE-2023-5729: Fixed an issue where fullscreen notifications would\n    be obscured by WebAuthn prompts.\n  - CVE-2023-5730: Fixed multiple memory safety issues.\n  - CVE-2023-5731: Fixed multiple memory safety issues.\n","affected":[{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP4","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP5","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP2-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP3-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP2","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP3","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Enterprise Storage 7.1","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%207.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-branding-upstream":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.0-150200.152.114.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"115.4.0-150200.152.114.1","MozillaFirefox-branding-upstream":"115.4.0-150200.152.114.1","MozillaFirefox-devel":"115.4.0-150200.152.114.1","MozillaFirefox-translations-common":"115.4.0-150200.152.114.1","MozillaFirefox-translations-other":"115.4.0-150200.152.114.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4214-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234214-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216338"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5721"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5722"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5723"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5724"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5728"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5729"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5730"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5731"}]}