Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 891213 (CVE-2023-23597, CVE-2023-23600, CVE-2023-23604, CVE-2023-23606) - <www-client/firefox{-bin,}-{102.7.0,109.0}: multiple vulnerabilities
Summary: <www-client/firefox{-bin,}-{102.7.0,109.0}: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2023-23597, CVE-2023-23600, CVE-2023-23604, CVE-2023-23606
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa+]
Keywords:
Depends on: qt-5.15.8-stable
Blocks: CVE-2023-23598, CVE-2023-23599, CVE-2023-23601, CVE-2023-23602, CVE-2023-23603, CVE-2023-23605
  Show dependency tree
 
Reported: 2023-01-17 17:51 UTC by John Helmert III
Modified: 2023-05-03 09:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-01-17 17:51:15 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2023-01/
https://www.mozilla.org/en-US/security/advisories/mfsa2023-02/

Thanks for bumps! Please stabilize when ready.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-01-17 17:53:04 UTC
Mozilla also fixed CVE-2022-46871 and CVE-2022-46877 in ESR in this round, but we'll GLSA all of them together so wrangling
Comment 2 Joonas Niilola gentoo-dev 2023-01-23 06:34:13 UTC
109.0 needs a new patch set to compile on ppc64, and it has some problems with video/audio. They're both most likely related to updated webrtc. So gonna let 108.0.2 stay a bit longer, most likely until some 109.0.1 with fixes lands.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-01-25 19:28:00 UTC
GLSA request filed
Comment 4 Larry the Git Cow gentoo-dev 2023-01-30 06:16:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4aa2b54900bed2964dbcefa95d88a66c9a880939

commit 4aa2b54900bed2964dbcefa95d88a66c9a880939
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-01-30 06:14:54 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-01-30 06:16:33 +0000

    www-client/firefox: drop 102.6.0, 108.0.2
    
    Bug: https://bugs.gentoo.org/891213
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox/Manifest               |  197 -----
 www-client/firefox/firefox-102.6.0.ebuild | 1275 ---------------------------
 www-client/firefox/firefox-108.0.2.ebuild | 1331 -----------------------------
 3 files changed, 2803 deletions(-)
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-02-20 18:34:34 UTC
Thanks!
Comment 6 Larry the Git Cow gentoo-dev 2023-05-03 09:31:49 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=5f136da08cc28aa97d67b66cdaeb4c59046fd70d

commit 5f136da08cc28aa97d67b66cdaeb4c59046fd70d
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-05-03 09:15:03 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-05-03 09:31:46 +0000

    [ GLSA 202305-06 ] Mozilla Firefox: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/885813
    Bug: https://bugs.gentoo.org/891213
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202305-06.xml | 92 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 92 insertions(+)