<div class="container">
    <h1>Security update for MozillaFirefox</h1>

    <table class="table table-striped table-bordered">
        <tbody>
        <tr>
            <th>Announcement ID:</th>
            <td>SUSE-SU-2024:3518-1</td>
        </tr>
        <tr>
            <th>Release Date:</th>
            <td>2024-10-03T13:04:34Z</td>
        </tr>
        
        <tr>
            <th>Rating:</th>
            <td>important</td>
        </tr>
        <tr>
            <th>References:</th>
            <td>
                <ul>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1230979">bsc#1230979</a>
                        </li>
                    
                    
                </ul>
            </td>
        </tr>
        
        <tr>
            <th>Affected Products:</th>
            <td>
                <ul class="list-group">
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 12 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 12 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 12 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Software Development Kit 12 SP5</li>
                    
                </ul>
            </td>
        </tr>
        </tbody>
    </table>

    <p>An update that has one security fix can now be installed.</p>

    


    
        <h2>Description:</h2>
    
    <p>This update for MozillaFirefox fixes the following issues:</p>
<p>Update to Firefox Extended Support Release 128.3.0 ESR (MFSA-2024-47, bsc#1230979):</p>
<ul>
<li>CVE-2024-8900: Clipboard write permission bypass</li>
<li>CVE-2024-9392: Compromised content process can bypass site isolation</li>
<li>CVE-2024-9393: Cross-origin access to PDF contents through multipart responses</li>
<li>CVE-2024-9394: Cross-origin access to JSON contents through multipart responses</li>
<li>CVE-2024-9396: Potential memory corruption may occur when cloning certain objects</li>
<li>CVE-2024-9397: Potential directory upload bypass via clickjacking</li>
<li>CVE-2024-9398: External protocol handlers could be enumerated via popups</li>
<li>CVE-2024-9399: Specially crafted WebTransport requests could lead to denial of service</li>
<li>CVE-2024-9400: Potential memory corruption during JIT compilation</li>
<li>CVE-2024-9401: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3</li>
<li>CVE-2024-9402: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3</li>
</ul>



    

    <h2>Patch Instructions:</h2>
    <p>
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".<br/>

        Alternatively you can run the command listed for your product:
    </p>
    <ul class="list-group">
        
            <li class="list-group-item">
                SUSE Linux Enterprise High Performance Computing 12 SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3518=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server 12 SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3518=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Server for SAP Applications 12 SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3518=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                SUSE Linux Enterprise Software Development Kit 12 SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-3518=1</code>
                    
                    
                
            </li>
        
    </ul>

    <h2>Package List:</h2>
    <ul>
        
            
                <li>
                    SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64)
                    <ul>
                        
                            <li>MozillaFirefox-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-debugsource-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-debuginfo-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-translations-common-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
                <li>
                    SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch)
                    <ul>
                        
                            <li>MozillaFirefox-devel-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64)
                    <ul>
                        
                            <li>MozillaFirefox-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-debugsource-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-debuginfo-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-translations-common-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
                <li>
                    SUSE Linux Enterprise Server 12 SP5 (noarch)
                    <ul>
                        
                            <li>MozillaFirefox-devel-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64)
                    <ul>
                        
                            <li>MozillaFirefox-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-debugsource-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-debuginfo-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-translations-common-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
                <li>
                    SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch)
                    <ul>
                        
                            <li>MozillaFirefox-devel-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64)
                    <ul>
                        
                            <li>MozillaFirefox-debugsource-128.3.0-112.228.1</li>
                        
                            <li>MozillaFirefox-debuginfo-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
                <li>
                    SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch)
                    <ul>
                        
                            <li>MozillaFirefox-devel-128.3.0-112.228.1</li>
                        
                    </ul>
                </li>
            
        
    </ul>

    
        <h2>References:</h2>
        <ul>
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1230979">https://bugzilla.suse.com/show_bug.cgi?id=1230979</a>
                    </li>
                
            
        </ul>
    
</div>