Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:01814-1

Опубликовано: 04 июн. 2025
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Update to Mozilla Firefox ESR 128.11 (MFSA 2025-44, bsc#1243353):

  • MFSA-TMP-2025-0001: Double-free in libvpx encoder (bmo#1962421)
  • CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (bmo#1960745)
  • CVE-2025-5264: Potential local code execution in 'Copy as cURL' command (bmo#1950001)
  • CVE-2025-5265: Potential local code execution in 'Copy as cURL' command (bmo#1962301)
  • CVE-2025-5266: Script element events leaked cross-origin resource status (bmo#1965628)
  • CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (bmo#1954137)
  • CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 (bmo#1950136, bmo#1958121, bmo#1960499, bmo#1962634)
  • CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11 (bmo#1924108)

Список пакетов

Container suse/kiosk/firefox-esr:latest
MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP6
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Server 15 SP3-LTSS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Server 15 SP4-LTSS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Server 15 SP5-LTSS
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1
openSUSE Leap 15.6
MozillaFirefox-128.11.0-150200.152.185.1
MozillaFirefox-branding-upstream-128.11.0-150200.152.185.1
MozillaFirefox-devel-128.11.0-150200.152.185.1
MozillaFirefox-translations-common-128.11.0-150200.152.185.1
MozillaFirefox-translations-other-128.11.0-150200.152.185.1

Описание

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-devel-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-translations-common-128.11.0-150200.152.185.1

Ссылки

Описание

Due to insufficient escaping of the newline character in the "Copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-devel-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-translations-common-128.11.0-150200.152.185.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-devel-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-translations-common-128.11.0-150200.152.185.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-devel-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-translations-common-128.11.0-150200.152.185.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-devel-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-translations-common-128.11.0-150200.152.185.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-devel-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-translations-common-128.11.0-150200.152.185.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
Container suse/kiosk/firefox-esr:latest:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-devel-128.11.0-150200.152.185.1
SUSE Enterprise Storage 7.1:MozillaFirefox-translations-common-128.11.0-150200.152.185.1

Ссылки
Уязвимость SUSE-SU-2025:01814-1