Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 914073 (MFSA-2023-40) - <www-client/firefox[-system-webp]-{115.2.1,117.0.1} <www-client/firefox-bin-{115.2.1,117.0.1} <mail-client/thunderbird[-system-webp]-{102.15.1,115.2.2} <mail-client/thunderbird-bin-{102.15.1,115.2.2}: libwebp buffer overflow
Summary: <www-client/firefox[-system-webp]-{115.2.1,117.0.1} <www-client/firefox-bin-{...
Status: RESOLVED FIXED
Alias: MFSA-2023-40
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal critical (vote)
Assignee: Gentoo Security
URL: https://www.mozilla.org/en-US/securit...
Whiteboard: A2 [glsa+]
Keywords:
Depends on: 914205 914224
Blocks: CVE-2023-4863, CVE-2023-5129
  Show dependency tree
 
Reported: 2023-09-13 00:21 UTC by Sam James
Modified: 2024-01-07 09:40 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-09-13 00:21:48 UTC
See bug 914072. New releases have been made. Only affects USE=-system-webp with firefox itself.
Comment 1 Joonas Niilola gentoo-dev 2023-09-13 05:56:38 UTC
*deep sigh*
Comment 2 Larry the Git Cow gentoo-dev 2023-09-13 06:37:16 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b8e97e17f33ba89d760c433925fce93719fcb9d5

commit b8e97e17f33ba89d760c433925fce93719fcb9d5
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-13 06:36:55 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-13 06:36:55 +0000

    www-client/firefox-bin: drop 102.15.0, 115.2.0, 117.0
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox-bin/Manifest                    | 294 ----------------
 www-client/firefox-bin/firefox-bin-102.15.0.ebuild | 378 --------------------
 www-client/firefox-bin/firefox-bin-115.2.0.ebuild  | 378 --------------------
 www-client/firefox-bin/firefox-bin-117.0.ebuild    | 382 ---------------------
 4 files changed, 1432 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=688e55fe43ed0480e1ac3d443729bcc63226bf17

commit 688e55fe43ed0480e1ac3d443729bcc63226bf17
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-13 06:36:41 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-13 06:36:41 +0000

    www-client/firefox-bin: add 117.0.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox-bin/Manifest                   |  98 ++++++
 www-client/firefox-bin/firefox-bin-117.0.1.ebuild | 382 ++++++++++++++++++++++
 2 files changed, 480 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0b305c56b5b5f3107892b154fc9576bf3f2efa01

commit 0b305c56b5b5f3107892b154fc9576bf3f2efa01
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-13 06:36:26 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-13 06:36:26 +0000

    www-client/firefox-bin: add 115.2.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox-bin/Manifest                   |  98 ++++++
 www-client/firefox-bin/firefox-bin-115.2.1.ebuild | 378 ++++++++++++++++++++++
 2 files changed, 476 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d4a5cb0c1cf799fec9467a60f7c3de60888ddb8e

commit d4a5cb0c1cf799fec9467a60f7c3de60888ddb8e
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-13 06:36:05 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-13 06:36:05 +0000

    www-client/firefox-bin: add 102.15.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox-bin/Manifest                    |  98 ++++++
 www-client/firefox-bin/firefox-bin-102.15.1.ebuild | 378 +++++++++++++++++++++
 2 files changed, 476 insertions(+)
Comment 3 Alexey Mishustin 2023-09-14 09:59:29 UTC
Hello.

Why can't I see the packages of these commits in https://packages.gentoo.org/packages/www-client/firefox and either after emerge --syncing?

--
Best regards,
Alex
Comment 4 Joonas Niilola gentoo-dev 2023-09-14 10:09:24 UTC
(In reply to Alexey Mishustin from comment #3)
> Hello.
> 
> Why can't I see the packages of these commits in
> https://packages.gentoo.org/packages/www-client/firefox and either after
> emerge --syncing?
> 
> --
> Best regards,
> Alex

Those were only for firefox-bin. I'm doing the source version today and am nearing final runs for 117.0.1. 

Thunderbird will also be handled today after foxes.
Comment 5 Alexey Mishustin 2023-09-14 10:40:52 UTC
(In reply to Joonas Niilola from comment #4)
> Those were only for firefox-bin. I'm doing the source version today and am
> nearing final runs for 117.0.1. 
> 
> Thunderbird will also be handled today after foxes.

I got it. Thank you!

--
Best regards,
Alex
Comment 6 Larry the Git Cow gentoo-dev 2023-09-14 11:45:25 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fd4f8ec937ea9b37d6b78889dd98c79e5a986090

commit fd4f8ec937ea9b37d6b78889dd98c79e5a986090
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-14 11:44:15 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-14 11:45:22 +0000

    www-client/firefox: add 117.0.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox/Manifest               |  100 ++
 www-client/firefox/firefox-117.0.1.ebuild | 1488 +++++++++++++++++++++++++++++
 2 files changed, 1588 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=95a6eedd76df58e7c876eccc95bdf4710ee44e41

commit 95a6eedd76df58e7c876eccc95bdf4710ee44e41
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-14 09:44:39 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-14 11:45:22 +0000

    www-client/firefox: add 115.2.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox/Manifest               |  100 ++
 www-client/firefox/firefox-115.2.1.ebuild | 1407 +++++++++++++++++++++++++++++
 2 files changed, 1507 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d745adde10d94d306afd5435392fe59606aec4b9

commit d745adde10d94d306afd5435392fe59606aec4b9
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-14 05:00:52 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-14 11:45:22 +0000

    www-client/firefox: add 102.15.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox/Manifest                |   98 +++
 www-client/firefox/firefox-102.15.1.ebuild | 1290 ++++++++++++++++++++++++++++
 2 files changed, 1388 insertions(+)
Comment 7 Larry the Git Cow gentoo-dev 2023-09-14 14:24:59 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=834b01a7b07b9898283c239a81522858c5e3b70f

commit 834b01a7b07b9898283c239a81522858c5e3b70f
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-14 14:23:54 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-14 14:24:56 +0000

    mail-client/thunderbird: drop 115.2.0, 115.2.1
    
    Bug: https://bugs.gentoo.org/914073
    Bug: https://bugs.gentoo.org/910229
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                   |  130 --
 mail-client/thunderbird/thunderbird-115.2.0.ebuild | 1313 --------------------
 mail-client/thunderbird/thunderbird-115.2.1.ebuild | 1313 --------------------
 3 files changed, 2756 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4fa90f537e9795a1efaf5f69e9bab3892a62be02

commit 4fa90f537e9795a1efaf5f69e9bab3892a62be02
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-14 14:23:17 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-14 14:24:56 +0000

    mail-client/thunderbird: add 115.2.2
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                   |   65 +
 mail-client/thunderbird/thunderbird-115.2.2.ebuild | 1313 ++++++++++++++++++++
 2 files changed, 1378 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f214ad8c2f27f7a152b69663baf312793435284e

commit f214ad8c2f27f7a152b69663baf312793435284e
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-14 12:58:49 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-14 14:24:56 +0000

    mail-client/thunderbird: add 102.15.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                   |   65 ++
 .../thunderbird/thunderbird-102.15.1.ebuild        | 1190 ++++++++++++++++++++
 2 files changed, 1255 insertions(+)
Comment 8 Larry the Git Cow gentoo-dev 2023-09-14 14:26:05 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5136e6930fa1b9bbdf16da9f7cc1e003dcb97114

commit 5136e6930fa1b9bbdf16da9f7cc1e003dcb97114
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-14 14:25:25 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-14 14:25:25 +0000

    mail-client/thunderbird-bin: add 102.15.1
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird-bin/Manifest               |  66 +++++
 .../thunderbird-bin-102.15.1.ebuild                | 327 +++++++++++++++++++++
 2 files changed, 393 insertions(+)
Comment 9 Denis Tokarev 2023-09-15 08:36:00 UTC
Is there a reason why the patched versions are marked unstable?
I assume people (me included) want the officially invulnerable versions, even though it's only required for USE=-system-webp
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-09-15 08:37:02 UTC
(In reply to Denis Tokarev from comment #9)
> Is there a reason why the patched versions are marked unstable?
> I assume people (me included) want the officially invulnerable versions,
> even though it's only required for USE=-system-webp

> Joonas Niilola 2023-09-15 07:13:01 BST
> Depends on: 914205

although juippis does normally stable for amd64 but he didn't put it in the bug, so I'll just chuck it in
Comment 11 Joonas Niilola gentoo-dev 2023-09-15 10:30:54 UTC
(In reply to Denis Tokarev from comment #9)
> Is there a reason why the patched versions are marked unstable?
> I assume people (me included) want the officially invulnerable versions,
> even though it's only required for USE=-system-webp

Yes, it's because the work relies on humans doing them. It's not automated :) 


(In reply to Sam James from comment #10)
> (In reply to Denis Tokarev from comment #9)
> > Is there a reason why the patched versions are marked unstable?
> > I assume people (me included) want the officially invulnerable versions,
> > even though it's only required for USE=-system-webp
> 
> > Joonas Niilola 2023-09-15 07:13:01 BST
> > Depends on: 914205
> 
> although juippis does normally stable for amd64 but he didn't put it in the
> bug, so I'll just chuck it in

I was in the process of stabilizing it, while being away from my computer. But faster is better and I doubt there's _any_ chance of breakage with this update so no problem!
Comment 12 Denis Tokarev 2023-09-15 14:39:13 UTC
Thanks for your work guys!
Comment 13 Larry the Git Cow gentoo-dev 2023-09-16 08:05:05 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=844164cc11dfee7887fb062999be1eaae84f5898

commit 844164cc11dfee7887fb062999be1eaae84f5898
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-16 08:04:38 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-16 08:04:38 +0000

    www-client/firefox: drop 102.15.0, 115.2.0, 117.0
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 www-client/firefox/Manifest                |  298 ------
 www-client/firefox/firefox-102.15.0.ebuild | 1290 ------------------------
 www-client/firefox/firefox-115.2.0.ebuild  | 1407 --------------------------
 www-client/firefox/firefox-117.0.ebuild    | 1488 ----------------------------
 4 files changed, 4483 deletions(-)
Comment 14 Larry the Git Cow gentoo-dev 2023-09-17 05:43:39 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b29bbb4dd5d925684cbddfb53b8ac407067d86c6

commit b29bbb4dd5d925684cbddfb53b8ac407067d86c6
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-09-16 12:20:38 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-09-17 05:43:32 +0000

    mail-client/thunderbird: drop 102.15.0
    
    Bug: https://bugs.gentoo.org/914073
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 mail-client/thunderbird/Manifest                   |   65 --
 .../thunderbird/thunderbird-102.15.0.ebuild        | 1190 --------------------
 2 files changed, 1255 deletions(-)
Comment 15 Larry the Git Cow gentoo-dev 2024-01-07 09:39:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=22d7e8b6c0209c137d7f713d8d1e090906f7cf58

commit 22d7e8b6c0209c137d7f713d8d1e090906f7cf58
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-01-07 09:38:31 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-01-07 09:39:06 +0000

    [ GLSA 202401-10 ] Mozilla Firefox: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/908245
    Bug: https://bugs.gentoo.org/914073
    Bug: https://bugs.gentoo.org/918433
    Bug: https://bugs.gentoo.org/920507
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202401-10.xml | 134 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 134 insertions(+)