🛡️ MGASA-2023-0146 — firefox

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Updated firefox packages fix security vulnerability

Updated firefox and libwebp packages fix security vulnerabilities:

Unexpected data returned from the Safe Browsing API could have led to memory

corruption and a potentially exploitable crash (CVE-2023-1945).

A website could have obscured the fullscreen notification by using a

combination of window.open, fullscreen requests, window.name assignments, and

setInterval calls. This could have led to user confusion and possible spoofing

attacks (CVE-2023-29533).

Following a Garbage Collector compaction, weak maps may have been accessed

before they were correctly traced. This resulted in memory corruption and a

potentially exploitable crash (CVE-2023-29535).

An attacker could, via JavaScript code, cause the memory manager to

incorrectly free a pointer that addresses attacker-controlled memory,

resulting in an assertion, memory corruption, or a potentially exploitable

crash (CVE-2023-29536).

When handling the filename directive in the Content-Disposition header, the

filename would be truncated if the filename contained a NULL character. This

could have led to reflected file download attacks potentially tricking users

to install malware (CVE-2023-29539).

Firefox did not properly handle downloads of files ending in .desktop, which

can be interpreted to run attacker-controlled commands (CVE-2023-29541).

Mozilla developers Andrew Osmond, Sebastian Hengst, Andrew McCreight, and the

Mozilla Fuzzing Team reported memory safety bugs present in Firefox ESR 102.9.

Some of these bugs showed evidence of memory corruption and we presume that

with enough effort some of these could have been exploited to run arbitrary

code (CVE-2023-29550).

A double-free in libwebp could have led to memory corruption and a

potentially exploitable crash (MFSA-TMP-2023-0001).

Affected software

MGASA-2023-0146 is recorded against 3 packages.

  • firefox (fixed in 102.10.0-1.mga8)
  • firefox-l10n (fixed in 102.10.0-1.mga8)
  • libwebp (fixed in 1.1.0-2.1.mga8)

Timeline and source

Published on 15 April 2023 and last revised on 16 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
www.mozilla.org (Advisory)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-04-15
Updated 2026-08-12
Modified 2026-04-16
Fix URL N/A

Affected Packages

Software From version Fixed in
firefox 102.10.0-1.mga8
firefox-l10n 102.10.0-1.mga8
libwebp 1.1.0-2.1.mga8

Similar Threats

Free Vulnerability Check

Is your site affected by MGASA-2023-0146?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2023-0146 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.