Bug 2236082 (CVE-2023-4583) - CVE-2023-4583 Mozilla: Browsing Context potentially not cleared when closing Private Window
Summary: CVE-2023-4583 Mozilla: Browsing Context potentially not cleared when closing ...
Keywords:
Status: NEW
Alias: CVE-2023-4583
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2234841 2234842 2234843 2234844 2234845 2234846 2234847 2234848 2234849 2234850 2234853 2234854 2234855 2234856 2234857 2234858 2234859 2234860 2234861 2234862 2234864 2234865
Blocks: 2234838
TreeView+ depends on / blocked
 
Reported: 2023-08-30 09:45 UTC by Dhananjay Arunesh
Modified: 2024-03-29 03:35 UTC (History)
7 users (show)

Fixed In Version: firefox 115.2, thunderbird 115.2
Doc Type: ---
Doc Text:
The Mozilla Foundation Security Advisory describes this flaw as: When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:4945 0 None None None 2023-09-04 15:53:43 UTC
Red Hat Product Errata RHSA-2023:4946 0 None None None 2023-09-04 15:50:05 UTC
Red Hat Product Errata RHSA-2023:4947 0 None None None 2023-09-04 15:49:39 UTC
Red Hat Product Errata RHSA-2023:4948 0 None None None 2023-09-04 15:51:04 UTC
Red Hat Product Errata RHSA-2023:4949 0 None None None 2023-09-04 15:50:56 UTC
Red Hat Product Errata RHSA-2023:4950 0 None None None 2023-09-04 15:49:31 UTC
Red Hat Product Errata RHSA-2023:4951 0 None None None 2023-09-04 15:49:55 UTC
Red Hat Product Errata RHSA-2023:4952 0 None None None 2023-09-04 15:57:50 UTC
Red Hat Product Errata RHSA-2023:4953 0 None None None 2023-09-04 15:56:18 UTC
Red Hat Product Errata RHSA-2023:4954 0 None None None 2023-09-04 15:57:57 UTC
Red Hat Product Errata RHSA-2023:4955 0 None None None 2023-09-04 15:55:14 UTC
Red Hat Product Errata RHSA-2023:4956 0 None None None 2023-09-04 15:56:33 UTC
Red Hat Product Errata RHSA-2023:4957 0 None None None 2023-09-04 15:56:25 UTC
Red Hat Product Errata RHSA-2023:4958 0 None None None 2023-09-04 15:55:06 UTC
Red Hat Product Errata RHSA-2023:4959 0 None None None 2023-09-04 15:56:11 UTC
Red Hat Product Errata RHSA-2023:5019 0 None None None 2023-09-07 11:38:33 UTC

Description Dhananjay Arunesh 2023-08-30 09:45:55 UTC
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended.

External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2023-36/#CVE-2023-4583

Comment 1 errata-xmlrpc 2023-09-04 15:49:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Extended Update Support

Via RHSA-2023:4950 https://access.redhat.com/errata/RHSA-2023:4950

Comment 2 errata-xmlrpc 2023-09-04 15:49:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Extended Update Support

Via RHSA-2023:4947 https://access.redhat.com/errata/RHSA-2023:4947

Comment 3 errata-xmlrpc 2023-09-04 15:49:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support
  Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.2 Telecommunications Update Service

Via RHSA-2023:4951 https://access.redhat.com/errata/RHSA-2023:4951

Comment 4 errata-xmlrpc 2023-09-04 15:50:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support
  Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.2 Telecommunications Update Service

Via RHSA-2023:4946 https://access.redhat.com/errata/RHSA-2023:4946

Comment 5 errata-xmlrpc 2023-09-04 15:50:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2023:4949 https://access.redhat.com/errata/RHSA-2023:4949

Comment 6 errata-xmlrpc 2023-09-04 15:51:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2023:4948 https://access.redhat.com/errata/RHSA-2023:4948

Comment 7 errata-xmlrpc 2023-09-04 15:53:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2023:4945 https://access.redhat.com/errata/RHSA-2023:4945

Comment 8 errata-xmlrpc 2023-09-04 15:55:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:4958 https://access.redhat.com/errata/RHSA-2023:4958

Comment 9 errata-xmlrpc 2023-09-04 15:55:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:4955 https://access.redhat.com/errata/RHSA-2023:4955

Comment 10 errata-xmlrpc 2023-09-04 15:56:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2023:4959 https://access.redhat.com/errata/RHSA-2023:4959

Comment 11 errata-xmlrpc 2023-09-04 15:56:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2023:4953 https://access.redhat.com/errata/RHSA-2023:4953

Comment 12 errata-xmlrpc 2023-09-04 15:56:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2023:4957 https://access.redhat.com/errata/RHSA-2023:4957

Comment 13 errata-xmlrpc 2023-09-04 15:56:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2023:4956 https://access.redhat.com/errata/RHSA-2023:4956

Comment 14 errata-xmlrpc 2023-09-04 15:57:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:4952 https://access.redhat.com/errata/RHSA-2023:4952

Comment 15 errata-xmlrpc 2023-09-04 15:57:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:4954 https://access.redhat.com/errata/RHSA-2023:4954

Comment 16 errata-xmlrpc 2023-09-07 11:38:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2023:5019 https://access.redhat.com/errata/RHSA-2023:5019


Note You need to log in before you can comment on or make changes to this bug.