An update for firefox is now available for openEuler-22.03-LTS Security Advisory openeuler-security@openeuler.org openEuler security committee openEuler-SA-2023-1715 Final 1.0 1.0 2023-10-13 Initial 2023-10-13 2023-10-13 openEuler SA Tool V1.0 2023-10-13 firefox security update An update for firefox is now available for openEuler-22.03-LTS. Mozilla Firefox is a standalone web browser, designed for standards compliance and performance. Its functionality can be enhanced via a plethora of extensions. Security Fix(es): When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.(CVE-2023-4573) When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.(CVE-2023-4574) When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.(CVE-2023-4575) Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.(CVE-2023-4581) Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.(CVE-2023-4584) Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)(CVE-2023-4863) An update for firefox is now available for openEuler-22.03-LTS. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. High firefox https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1715 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-4573 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-4574 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-4575 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-4581 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-4584 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-4863 https://nvd.nist.gov/vuln/detail/CVE-2023-4573 https://nvd.nist.gov/vuln/detail/CVE-2023-4574 https://nvd.nist.gov/vuln/detail/CVE-2023-4575 https://nvd.nist.gov/vuln/detail/CVE-2023-4581 https://nvd.nist.gov/vuln/detail/CVE-2023-4584 https://nvd.nist.gov/vuln/detail/CVE-2023-4863 openEuler-22.03-LTS firefox-debuginfo-102.15.0-2.oe2203.aarch64.rpm firefox-102.15.0-2.oe2203.aarch64.rpm firefox-debugsource-102.15.0-2.oe2203.aarch64.rpm firefox-102.15.0-2.oe2203.src.rpm firefox-102.15.0-2.oe2203.x86_64.rpm firefox-debugsource-102.15.0-2.oe2203.x86_64.rpm firefox-debuginfo-102.15.0-2.oe2203.x86_64.rpm When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. 2023-10-13 CVE-2023-4573 openEuler-22.03-LTS Medium 6.5 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H firefox security update 2023-10-13 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1715 When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. 2023-10-13 CVE-2023-4574 openEuler-22.03-LTS Medium 6.5 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H firefox security update 2023-10-13 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1715 When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. 2023-10-13 CVE-2023-4575 openEuler-22.03-LTS Medium 6.5 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H firefox security update 2023-10-13 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1715 Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. 2023-10-13 CVE-2023-4581 openEuler-22.03-LTS Medium 4.3 AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N firefox security update 2023-10-13 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1715 Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. 2023-10-13 CVE-2023-4584 openEuler-22.03-LTS High 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H firefox security update 2023-10-13 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1715 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) 2023-10-13 CVE-2023-4863 openEuler-22.03-LTS High 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H firefox security update 2023-10-13 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1715