{"id":"MGASA-2023-0056","summary":"Updated firefox packages fix security vulnerability","details":"An attacker could construct a PKCS 12 cert bundle in such a way that could\nallow for arbitrary memory writes via PKCS 12 Safe Bag attributes being\nmishandled (CVE-2023-0767).\n\nThe Content-Security-Policy-Report-Only header could allow an attacker to leak\na child iframe's unredacted URI when interaction with that iframe triggers a\nredirect (CVE-2023-25728).\n\nPermission prompts for opening external schemes were only shown for\nContentPrincipals resulting in extensions being able to open them without user\ninteraction via ExpandedPrincipals. This could lead to further malicious\nactions such as downloading files or interacting with software already\ninstalled on the system (CVE-2023-25729).\n\nA background script invoking requestFullscreen and then blocking the main\nthread could force the browser into fullscreen mode indefinitely, resulting in\npotential user confusion or spoofing attacks (CVE-2023-25730).\n\nIn EncodeInputStream, wen encoding data from an inputStream in xpcom the size\nof the input being encoded was not correctly calculated potentially leading\nto an out of bounds memory write (CVE-2023-25732).\n\nIn SpiderMonkey, cross-compartment wrappers wrapping a scripted proxy could\nhave caused objects from other compartments to be stored in the main\ncompartment resulting in a use-after-free after unwrapping the proxy\n(CVE-2023-25735).\n\nAn invalid downcast from nsTextNode to SVGElement in\nSVGUtils::SetupStrokeGeometry could have lead to undefined behavior\n(CVE-2023-25737).\n\nModule load requests that failed were not being checked as to whether or not\nthey were cancelled causing a use-after-free in\nmozilla::dom::ScriptLoadContext::~ScriptLoadContext (CVE-2023-25739).\n\nIn Web Crypto, when importing a SPKI RSA public key as ECDSA P-256, the key\nwould be handled incorrectly causing the tab to crash (CVE-2023-25742).\n\nMozilla developers Philipp and Gabriele Svelto, Kershaw Chang, and the Mozilla\nFuzzing Team reported memory safety bugs present in Firefox ESR 102.7. Some of\nthese bugs showed evidence of memory corruption and we presume that with\nenough effort some of these could have been exploited to run arbitrary code\n(CVE-2023-25744, CVE-2023-25746).\n","modified":"2026-04-16T04:42:43.178540841Z","published":"2023-02-20T21:25:36Z","upstream":["CVE-2023-0767","CVE-2023-25728","CVE-2023-25729","CVE-2023-25730","CVE-2023-25732","CVE-2023-25735","CVE-2023-25737","CVE-2023-25739","CVE-2023-25742","CVE-2023-25744","CVE-2023-25746"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0056.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=31556"},{"type":"WEB","url":"https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/hSYAJS__-rw"},{"type":"WEB","url":"https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/zleRGChurmo"},{"type":"WEB","url":"https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_88.html"},{"type":"WEB","url":"https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_88_1.html"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/"}],"affected":[{"package":{"name":"firefox","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.8.0-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0056.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.8.0-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0056.json"}},{"package":{"name":"nss","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.88.1-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0056.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}