9 Star 1 Fork 28

src-openEuler/mozjs78

 / 详情

CVE-2023-29534

已完成
CVE和安全问题
创建于  
2024-12-05 06:00

一、漏洞信息
漏洞编号:CVE-2023-29534
漏洞归属组件:mozjs78
漏洞归属的版本:78.15.0,78.4.0,91.6.0
CVSS V3.0分值:
BaseScore:9.1 Critical
Vector:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
漏洞简述:
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
漏洞公开时间:2023-06-19 19:15:09
漏洞创建时间:2024-12-05 06:00:27
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2023-29534

更多参考(点击展开)
参考来源 参考链接 来源链接
security.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1816007
security.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1816059
security.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1821155
security.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1821576
security.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1821906
security.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1822298
security.mozilla.org https://bugzilla.mozilla.org/show_bug.cgi?id=1822305
security.mozilla.org https://www.mozilla.org/security/advisories/mfsa2023-13/
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.mozilla.org/show_bug.cgi?id=1816007
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.mozilla.org/show_bug.cgi?id=1816059
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.mozilla.org/show_bug.cgi?id=1821155
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.mozilla.org/show_bug.cgi?id=1821576
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.mozilla.org/show_bug.cgi?id=1821906
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.mozilla.org/show_bug.cgi?id=1822298
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.mozilla.org/show_bug.cgi?id=1822305
af854a3a-2127-422b-91ae-364da2661108 https://www.mozilla.org/security/advisories/mfsa2023-13/
suse_bugzilla http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29534 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://www.cve.org/CVERecord?id=CVE-2023-29534 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://bugzilla.mozilla.org/show_bug.cgi?id=1816007 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://bugzilla.mozilla.org/show_bug.cgi?id=1816059 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://bugzilla.mozilla.org/show_bug.cgi?id=1821155 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://bugzilla.mozilla.org/show_bug.cgi?id=1821576 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://bugzilla.mozilla.org/show_bug.cgi?id=1821906 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://bugzilla.mozilla.org/show_bug.cgi?id=1822298 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://bugzilla.mozilla.org/show_bug.cgi?id=1822305 https://bugzilla.suse.com/show_bug.cgi?id=1212529
suse_bugzilla https://www.mozilla.org/security/advisories/mfsa2023-13/ https://bugzilla.suse.com/show_bug.cgi?id=1212529
ubuntu https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29534 https://ubuntu.com/security/CVE-2023-29534
ubuntu https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/#CVE-2023-29534 https://ubuntu.com/security/CVE-2023-29534
ubuntu https://nvd.nist.gov/vuln/detail/CVE-2023-29534 https://ubuntu.com/security/CVE-2023-29534
ubuntu https://launchpad.net/bugs/cve/CVE-2023-29534 https://ubuntu.com/security/CVE-2023-29534
ubuntu https://security-tracker.debian.org/tracker/CVE-2023-29534 https://ubuntu.com/security/CVE-2023-29534
debian https://security-tracker.debian.org/tracker/CVE-2023-29534
firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1816059 https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1816007 https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1821155 https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1821576 https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1821906 https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1822298 https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
firefox https://bugzilla.mozilla.org/show_bug.cgi?id=1822305 https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
anolis https://anas.openanolis.cn/cves/detail/CVE-2023-29534
cve_search https://bugzilla.mozilla.org/show_bug.cgi?id=1816059
cve_search https://www.mozilla.org/security/advisories/mfsa2023-13/
cve_search https://bugzilla.mozilla.org/show_bug.cgi?id=1822298
cve_search https://bugzilla.mozilla.org/show_bug.cgi?id=1821906
cve_search https://bugzilla.mozilla.org/show_bug.cgi?id=1821576
cve_search https://bugzilla.mozilla.org/show_bug.cgi?id=1821155
cve_search https://bugzilla.mozilla.org/show_bug.cgi?id=1822305
cve_search https://bugzilla.mozilla.org/show_bug.cgi?id=1816007
amazon_linux_explore https://access.redhat.com/security/cve/CVE-2023-29534 https://explore.alas.aws.amazon.com/CVE-2023-29534.html
amazon_linux_explore https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29534 https://explore.alas.aws.amazon.com/CVE-2023-29534.html

漏洞分析指导链接:
https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
漏洞数据来源:
其它
漏洞补丁信息:

详情(点击展开)
影响的包 修复版本 修复补丁 问题引入补丁 来源
https://bugzilla.mozilla.org/attachment.cgi?id=9322970 bugzilla
https://bugzilla.mozilla.org/attachment.cgi?id=9322994 bugzilla
https://bugzilla.mozilla.org/show_bug.cgi?id=1816007 nvd
https://bugzilla.mozilla.org/show_bug.cgi?id=1816059 nvd
https://bugzilla.mozilla.org/show_bug.cgi?id=1821155 nvd
https://bugzilla.mozilla.org/show_bug.cgi?id=1821576 nvd
https://bugzilla.mozilla.org/show_bug.cgi?id=1821906 nvd
https://bugzilla.mozilla.org/show_bug.cgi?id=1822298 nvd
https://bugzilla.mozilla.org/show_bug.cgi?id=1822305 nvd
https://www.mozilla.org/security/advisories/mfsa2023-13/ nvd

二、漏洞分析结构反馈
影响性分析说明:
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
openEuler评分:
9.1
Vector:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
受影响版本排查(受影响/不受影响):
1.master(91.6.0):不受影响
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响
6.openEuler-24.03-LTS:不受影响
7.openEuler-24.03-LTS-Next:不受影响
8.openEuler-24.03-LTS-SP1:不受影响

修复是否涉及abi变化(是/否):
1.master(91.6.0):是
2.openEuler-20.03-LTS-SP4(78.4.0):是
3.openEuler-22.03-LTS-SP1(91.6.0):是
4.openEuler-22.03-LTS-SP3(91.6.0):是
5.openEuler-22.03-LTS-SP4(91.6.0):是
6.openEuler-24.03-LTS:否
7.openEuler-24.03-LTS-Next:否
8.openEuler-24.03-LTS-SP1:否

原因说明:
1.master(91.6.0):不受影响-组件不存在
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响-组件不存在
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响-组件不存在
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响-组件不存在
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响-组件不存在
6.openEuler-24.03-LTS:不受影响-组件不存在
7.openEuler-24.03-LTS-Next:不受影响-组件不存在
8.openEuler-24.03-LTS-SP1:不受影响-组件不存在

评论 (6)

majun-bot 创建了CVE和安全问题 5个月前
majun-bot 添加了
 
CVE/UNFIXED
标签
5个月前
展开全部操作日志
openeuler-ci-bot 添加了
 
sig/Desktop
标签
5个月前
openeuler-ci-bot 计划开始日期设置为2024-12-05 5个月前
openeuler-ci-bot 计划截止日期设置为2025-01-04 5个月前
openeuler-ci-bot 优先级设置为严重 5个月前
openeuler-ci-bot 修改了描述 5个月前
liyajie 负责人t.feng 修改为sun_hai 5个月前

影响性分析说明:Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

openEuler评分: 9.1
Vector:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

受影响版本排查(受影响/不受影响):
1.master(91.6.0):不受影响
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响
6.openEuler-24.03-LTS:不受影响
7.openEuler-24.03-LTS-Next:不受影响
8.openEuler-24.03-LTS-SP1:不受影响

修复是否涉及abi变化(是/否):
1.master(91.6.0):是
2.openEuler-20.03-LTS-SP4(78.4.0):是
3.openEuler-22.03-LTS-SP1(91.6.0):是
4.openEuler-22.03-LTS-SP3(91.6.0):是
5.openEuler-22.03-LTS-SP4(91.6.0):是
6.openEuler-24.03-LTS:否
7.openEuler-24.03-LTS-Next:否
8.openEuler-24.03-LTS-SP1:否

原因说明:
1.master(91.6.0):不受影响-组件不存在
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响-组件不存在
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响-组件不存在
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响-组件不存在
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响-组件不存在
6.openEuler-24.03-LTS:不受影响-组件不存在
7.openEuler-24.03-LTS-Next:不受影响-组件不存在
8.openEuler-24.03-LTS-SP1:不受影响-组件不存在

sun_hai 任务状态待办的 修改为已完成 5个月前
liyajie 任务状态已完成 修改为待办的 4个月前

影响性分析说明:Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

openEuler评分: 9.1
Vector:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

受影响版本排查(受影响/不受影响):
1.master(91.6.0):不受影响
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响
6.openEuler-24.03-LTS:不受影响
7.openEuler-24.03-LTS-Next:不受影响
8.openEuler-24.03-LTS-SP1:不受影响

修复是否涉及abi变化(是/否):
1.master(91.6.0):是
2.openEuler-20.03-LTS-SP4(78.4.0):是
3.openEuler-22.03-LTS-SP1(91.6.0):是
4.openEuler-22.03-LTS-SP3(91.6.0):是
5.openEuler-22.03-LTS-SP4(91.6.0):是
6.openEuler-24.03-LTS:否
7.openEuler-24.03-LTS-Next:否
8.openEuler-24.03-LTS-SP1:否

原因说明:
1.master(91.6.0):不受影响-组件不存在
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响-组件不存在
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响-组件不存在
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响-组件不存在
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响-组件不存在
6.openEuler-24.03-LTS:不受影响-组件不存在
7.openEuler-24.03-LTS-Next:不受影响-组件不存在
8.openEuler-24.03-LTS-SP1:不受影响-组件不存在

影响性分析说明:Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

openEuler评分: 9.1
Vector:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

受影响版本排查(受影响/不受影响):
1.master(91.6.0):不受影响
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响
6.openEuler-24.03-LTS:不受影响
7.openEuler-24.03-LTS-Next:不受影响
8.openEuler-24.03-LTS-SP1:不受影响

修复是否涉及abi变化(是/否):
1.master(91.6.0):是
2.openEuler-20.03-LTS-SP4(78.4.0):是
3.openEuler-22.03-LTS-SP1(91.6.0):是
4.openEuler-22.03-LTS-SP3(91.6.0):是
5.openEuler-22.03-LTS-SP4(91.6.0):是
6.openEuler-24.03-LTS:否
7.openEuler-24.03-LTS-Next:否
8.openEuler-24.03-LTS-SP1:否

原因说明:
1.master(91.6.0):不受影响-组件不存在
2.openEuler-20.03-LTS-SP4(78.4.0):不受影响-组件不存在
3.openEuler-22.03-LTS-SP1(91.6.0):不受影响-组件不存在
4.openEuler-22.03-LTS-SP3(91.6.0):不受影响-组件不存在
5.openEuler-22.03-LTS-SP4(91.6.0):不受影响-组件不存在
6.openEuler-24.03-LTS:不受影响-组件不存在
7.openEuler-24.03-LTS-Next:不受影响-组件不存在
8.openEuler-24.03-LTS-SP1:不受影响-组件不存在

openeuler-ci-bot 修改了描述 4个月前
sun_hai 任务状态待办的 修改为已完成 4个月前
openeuler-ci-bot 移除了
 
CVE/UNFIXED
标签
4个月前
openeuler-ci-bot 移除了
 
sig/Desktop
标签
4个月前
openeuler-ci-bot 添加了
 
CVE/UNAFFECTED
标签
4个月前
openeuler-ci-bot 添加了
 
sig/Desktop
标签
4个月前
openeuler-ci-bot 添加了
 
abi-changed
标签
4个月前
openeuler-ci-bot 计划开始日期2024-12-05 修改为2025-01-21 4个月前
openeuler-ci-bot 计划截止日期2025-01-04 修改为2025-01-28 4个月前

登录 后才可以发表评论

状态
负责人
项目
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
预计工期 (小时)
开始日期   -   截止日期
-
置顶选项
优先级
里程碑
分支
参与者(5)
5329419 openeuler ci bot 1632792936 sun_hai-sun_hai_10 liyajie-yajieli weiwei123-weiwei123444 majun-bot-openMajun_admin
1
https://gitee.com/src-openeuler/mozjs78.git
git@gitee.com:src-openeuler/mozjs78.git
src-openeuler
mozjs78
mozjs78

搜索帮助