MGASA-2023-0171

Source
https://advisories.mageia.org/MGASA-2023-0171.html
Import Source
https://advisories.mageia.org/MGASA-2023-0171.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0171
Related
Published
2023-05-16T19:17:40Z
Modified
2023-05-16T18:11:34Z
Summary
Updated firefox/nss/rootcerts packages fix security vulnerability
Details

In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks (CVE-2023-32205).

An out-of-bounds read could have led to a crash in the RLBox Expat driver (CVE-2023-32206).

A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions (CVE-2023-32207).

A type checking bug would have led to invalid wasm code being compiled, causing a content process crash (CVE-2023-32211).

An attacker could have positioned a datalist element to obscure the address bar (CVE-2023-32212).

When reading a file, an uninitialized value could have been used as read limit, causing memory corruption in FileReader::DoReadData() (CVE-2023-32213).

Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2023-32215).

References
Credits

Affected packages

Mageia:8 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
102.11.0-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
102.11.0-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / nss

Package

Name
nss
Purl
pkg:rpm/mageia/nss?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.89.1-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / rootcerts

Package

Name
rootcerts
Purl
pkg:rpm/mageia/rootcerts?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20230505.00-1.mga8

Ecosystem specific

{
    "section": "core"
}