Mageia alert MGASA-2023-0285 (firefox, thunderbird)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2023-0285: Updated Firefox and Thunderbird packages fix security vulnerabilities | |
Date: | Tue, 10 Oct 2023 19:23:10 +0200 | |
Message-ID: | <20231010172310.8700B9FBB3@duvel.mageia.org> | |
Archive-link: | Article |
MGASA-2023-0285 - Updated Firefox and Thunderbird packages fix security vulnerabilities Publication date: 10 Oct 2023 URL: https://advisories.mageia.org/MGASA-2023-0285.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-5169, CVE-2023-5171, CVE-2023-5176, CVE-2023-5217 Description: Updated Firefox and Thunderbird packages fix security vulnerabilities: Out-of-bounds write in PathOps. (CVE-2023-5169) Use-after-free in Ion Compiler. (CVE-2023-5171) Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. (CVE-2023-5176) Heap buffer overflow in libvpx. (CVE-2023-5217) References: - https://bugs.mageia.org/show_bug.cgi?id=32337 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5169 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5171 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5176 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5217 - https://www.mozilla.org/en-US/firefox/115.3.0/releasenotes/ - https://www.thunderbird.net/en-US/thunderbird/115.3.0/rel... - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://www.mozilla.org/en-US/firefox/115.3.1/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5169 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5171 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5176 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5217 SRPMS: - 9/core/firefox-115.3.1-1.mga9 - 9/core/firefox-l10n-115.3.1-1.mga9 - 9/core/thunderbird-115.3.1-1.mga9 - 9/core/thunderbird-l10n-115.3.1-1.mga9