Security update for MozillaFirefox
| Announcement ID: | SUSE-SU-2025:01769-1 | 
|---|---|
| Release Date: | 2025-05-30T09:30:34Z | 
| Rating: | important | 
| References: | |
| Cross-References: | |
| CVSS scores: | 
                    
  | 
            
| Affected Products: | 
                
  | 
        
An update that solves seven vulnerabilities can now be installed.
Description:
This update for MozillaFirefox fixes the following issues:
Update to Mozilla Firefox ESR 128.11 (MFSA 2025-44, bsc#1243353):
- MFSA-TMP-2025-0001: Double-free in libvpx encoder (bmo#1962421)
 - CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (bmo#1960745)
 - CVE-2025-5264: Potential local code execution in "Copy as cURL" command (bmo#1950001)
 - CVE-2025-5265: Potential local code execution in "Copy as cURL" command (bmo#1962301)
 - CVE-2025-5266: Script element events leaked cross-origin resource status (bmo#1965628)
 - CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (bmo#1954137)
 - CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 (bmo#1950136, bmo#1958121, bmo#1960499, bmo#1962634)
 - CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11 (bmo#1924108)
 
Patch Instructions:
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".
        Alternatively you can run the command listed for your product:
    
- 
                SUSE Linux Enterprise Server 12 SP5 LTSS
                
                    
                        
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-1769=1 - 
                SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
                
                    
                        
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1769=1 
Package List:
- 
                    SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64)
                    
- MozillaFirefox-translations-common-128.11.0-112.262.1
 - MozillaFirefox-debuginfo-128.11.0-112.262.1
 - MozillaFirefox-128.11.0-112.262.1
 - MozillaFirefox-debugsource-128.11.0-112.262.1
 
 - 
                    SUSE Linux Enterprise Server 12 SP5 LTSS (noarch)
                    
- MozillaFirefox-devel-128.11.0-112.262.1
 
 - 
                    SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64)
                    
- MozillaFirefox-translations-common-128.11.0-112.262.1
 - MozillaFirefox-debuginfo-128.11.0-112.262.1
 - MozillaFirefox-128.11.0-112.262.1
 - MozillaFirefox-debugsource-128.11.0-112.262.1
 
 - 
                    SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch)
                    
- MozillaFirefox-devel-128.11.0-112.262.1
 
 
References:
- https://www.suse.com/security/cve/CVE-2025-5263.html
 - https://www.suse.com/security/cve/CVE-2025-5264.html
 - https://www.suse.com/security/cve/CVE-2025-5265.html
 - https://www.suse.com/security/cve/CVE-2025-5266.html
 - https://www.suse.com/security/cve/CVE-2025-5267.html
 - https://www.suse.com/security/cve/CVE-2025-5268.html
 - https://www.suse.com/security/cve/CVE-2025-5269.html
 - https://bugzilla.suse.com/show_bug.cgi?id=1243353