UBUNTU-CVE-2023-4863

Affected packages

Ubuntu:20.04:LTS
firefox

Package

Name
firefox
Purl
pkg:deb/ubuntu/firefox@117.0.1+build2-0ubuntu0.20.04.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
117.0.1+build2-0ubuntu0.20.04.1

Affected versions

69.*
69.0.3+build1-0ubuntu1
70.*
70.0+build2-0ubuntu1
70.0+build2-0ubuntu2
70.0.1+build1-0ubuntu2
71.*
71.0+build2-0ubuntu2
71.0+build5-0ubuntu1
72.*
72.0.1+build1-0ubuntu1
72.0.2+build1-0ubuntu1
73.*
73.0+build1-0ubuntu1
73.0+build2-0ubuntu1
73.0+build3-0ubuntu1
73.0.1+build1-0ubuntu1
74.*
74.0+build1-0ubuntu1
74.0+build2-0ubuntu1
74.0+build2-0ubuntu2
74.0+build3-0ubuntu1
75.*
75.0+build3-0ubuntu1
76.*
76.0+build2-0ubuntu0.20.04.1
76.0.1+build1-0ubuntu0.20.04.1
77.*
77.0.1+build1-0ubuntu0.20.04.1
78.*
78.0.1+build1-0ubuntu0.20.04.1
78.0.2+build2-0ubuntu0.20.04.1
79.*
79.0+build1-0ubuntu0.20.04.1
80.*
80.0+build2-0ubuntu0.20.04.1
80.0.1+build1-0ubuntu0.20.04.1
81.*
81.0+build2-0ubuntu0.20.04.1
81.0.2+build1-0ubuntu0.20.04.1
82.*
82.0+build2-0ubuntu0.20.04.1
82.0.2+build1-0ubuntu0.20.04.1
82.0.3+build1-0ubuntu0.20.04.1
83.*
83.0+build2-0ubuntu0.20.04.1
84.*
84.0+build3-0ubuntu0.20.04.1
84.0.1+build1-0ubuntu0.20.04.1
84.0.2+build1-0ubuntu0.20.04.1
85.*
85.0+build1-0ubuntu0.20.04.1
85.0.1+build1-0ubuntu0.20.04.1
86.*
86.0+build3-0ubuntu0.20.04.1
86.0.1+build1-0ubuntu0.20.04.1
87.*
87.0+build3-0ubuntu0.20.04.2
88.*
88.0+build2-0ubuntu0.20.04.1
88.0.1+build1-0ubuntu0.20.04.2
89.*
89.0+build2-0ubuntu0.20.04.2
89.0.1+build1-0ubuntu0.20.04.1
89.0.2+build1-0ubuntu0.20.04.1
90.*
90.0+build1-0ubuntu0.20.04.1
90.0.2+build1-0ubuntu0.20.04.1
91.*
91.0+build2-0ubuntu0.20.04.1
91.0.1+build1-0ubuntu0.20.04.1
91.0.2+build1-0ubuntu0.20.04.1
92.*
92.0+build3-0ubuntu0.20.04.1
93.*
93.0+build1-0ubuntu0.20.04.1
94.*
94.0+build3-0ubuntu0.20.04.1
95.*
95.0+build1-0ubuntu0.20.04.1
95.0.1+build2-0ubuntu0.20.04.1
96.*
96.0+build2-0ubuntu0.20.04.1
97.*
97.0+build2-0ubuntu0.20.04.1
97.0.2+build1-0ubuntu0.20.04.1
98.*
98.0+build3-0ubuntu0.20.04.2
98.0.1+build2-0ubuntu0.20.04.1
98.0.2+build1-0ubuntu0.20.04.1
99.*
99.0+build2-0ubuntu0.20.04.2
100.*
100.0+build2-0ubuntu0.20.04.1
100.0.2+build1-0ubuntu0.20.04.1
101.*
101.0.1+build1-0ubuntu0.20.04.1
102.*
102.0+build2-0ubuntu0.20.04.1
103.*
103.0+build1-0ubuntu0.20.04.1
104.*
104.0+build3-0ubuntu0.20.04.1
105.*
105.0+build2-0ubuntu0.20.04.1
106.*
106.0.2+build1-0ubuntu0.20.04.1
106.0.5+build1-0ubuntu0.20.04.1
107.*
107.0+build2-0ubuntu0.20.04.1
108.*
108.0+build2-0ubuntu0.20.04.1
108.0.1+build1-0ubuntu0.20.04.1
108.0.2+build1-0ubuntu0.20.04.1
109.*
109.0+build2-0ubuntu0.20.04.1
109.0.1+build1-0ubuntu0.20.04.2
110.*
110.0+build3-0ubuntu0.20.04.1
110.0.1+build2-0ubuntu0.20.04.1
111.*
111.0+build2-0ubuntu0.20.04.1
111.0.1+build2-0ubuntu0.20.04.1
112.*
112.0+build2-0ubuntu0.20.04.1
112.0.1+build1-0ubuntu0.20.04.1
112.0.2+build1-0ubuntu0.20.04.1
113.*
113.0+build2-0ubuntu0.20.04.1
113.0.1+build1-0ubuntu0.20.04.1
113.0.2+build1-0ubuntu0.20.04.1
114.*
114.0+build3-0ubuntu0.20.04.1
114.0.1+build1-0ubuntu0.20.04.1
114.0.2+build1-0ubuntu0.20.04.1
115.*
115.0+build2-0ubuntu0.20.04.3
115.0.2+build1-0ubuntu0.20.04.1
116.*
116.0+build2-0ubuntu0.20.04.2
116.0.2+build1-0ubuntu0.20.04.1
116.0.3+build2-0ubuntu0.20.04.1
117.*
117.0+build2-0ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "117.0.1+build2-0ubuntu0.20.04.1",
            "binary_name": "firefox"
        },
        {
            "binary_version": "117.0.1+build2-0ubuntu0.20.04.1",
            "binary_name": "firefox-dev"
        },
        {
            "binary_version": "117.0.1+build2-0ubuntu0.20.04.1",
            "binary_name": "firefox-geckodriver"
        },
        {
            "binary_version": "117.0.1+build2-0ubuntu0.20.04.1",
            "binary_name": "firefox-mozsymbols"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4863.json"
libwebp

Package

Name
libwebp
Purl
pkg:deb/ubuntu/libwebp@0.6.1-2ubuntu0.20.04.3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.1-2ubuntu0.20.04.3

Affected versions

0.*
0.6.1-2
0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.6.1-2ubuntu0.20.04.3",
            "binary_name": "libwebp-dev"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.20.04.3",
            "binary_name": "libwebp6"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.20.04.3",
            "binary_name": "libwebpdemux2"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.20.04.3",
            "binary_name": "libwebpmux3"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.20.04.3",
            "binary_name": "webp"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4863.json"
thunderbird

Package

Name
thunderbird
Purl
pkg:deb/ubuntu/thunderbird@1:102.15.1+build1-0ubuntu0.20.04.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:102.15.1+build1-0ubuntu0.20.04.1

Affected versions

1:68.*
1:68.1.2+build1-0ubuntu1
1:68.1.2+build1-0ubuntu2
1:68.2.1+build1-0ubuntu1
1:68.2.2+build1-0ubuntu1
1:68.3.0+build2-0ubuntu1
1:68.3.1+build1-0ubuntu2
1:68.4.1+build1-0ubuntu1
1:68.4.2+build2-0ubuntu1
1:68.5.0+build1-0ubuntu1
1:68.6.0+build2-0ubuntu1
1:68.7.0+build1-0ubuntu1
1:68.7.0+build1-0ubuntu2
1:68.8.0+build2-0ubuntu0.20.04.2
1:68.10.0+build1-0ubuntu0.20.04.1
1:78.*
1:78.7.1+build1-0ubuntu0.20.04.1
1:78.8.1+build1-0ubuntu0.20.04.1
1:78.11.0+build1-0ubuntu0.20.04.2
1:78.13.0+build1-0ubuntu0.20.04.2
1:78.14.0+build1-0ubuntu0.20.04.1
1:78.14.0+build1-0ubuntu0.20.04.2
1:91.*
1:91.5.0+build1-0ubuntu0.20.04.1
1:91.7.0+build2-0ubuntu0.20.04.1
1:91.8.1+build1-0ubuntu0.20.04.1
1:91.9.1+build1-0ubuntu0.20.04.1
1:91.11.0+build2-0ubuntu0.20.04.1
1:102.*
1:102.2.2+build1-0ubuntu0.20.04.1
1:102.4.2+build2-0ubuntu0.20.04.1
1:102.7.1+build2-0ubuntu0.20.04.1
1:102.8.0+build2-0ubuntu0.20.04.1
1:102.9.0+build1-0ubuntu0.20.04.1
1:102.10.0+build2-0ubuntu0.20.04.1
1:102.11.0+build1-0ubuntu0.20.04.1
1:102.13.0+build1-0ubuntu0.20.04.1
1:102.15.0+build1-0ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.20.04.1",
            "binary_name": "thunderbird"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.20.04.1",
            "binary_name": "thunderbird-dev"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.20.04.1",
            "binary_name": "thunderbird-gnome-support"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.20.04.1",
            "binary_name": "thunderbird-mozsymbols"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.20.04.1",
            "binary_name": "xul-ext-calendar-timezones"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.20.04.1",
            "binary_name": "xul-ext-gdata-provider"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.20.04.1",
            "binary_name": "xul-ext-lightning"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4863.json"
Ubuntu:22.04:LTS
libwebp

Package

Name
libwebp
Purl
pkg:deb/ubuntu/libwebp@1.2.2-2ubuntu0.22.04.2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.2-2ubuntu0.22.04.2

Affected versions

0.*
0.6.1-2.1
0.6.1-2.1build1
1.*
1.2.1-6
1.2.1-7
1.2.2-2
1.2.2-2ubuntu0.22.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.2.2-2ubuntu0.22.04.2",
            "binary_name": "libwebp-dev"
        },
        {
            "binary_version": "1.2.2-2ubuntu0.22.04.2",
            "binary_name": "libwebp7"
        },
        {
            "binary_version": "1.2.2-2ubuntu0.22.04.2",
            "binary_name": "libwebpdemux2"
        },
        {
            "binary_version": "1.2.2-2ubuntu0.22.04.2",
            "binary_name": "libwebpmux3"
        },
        {
            "binary_version": "1.2.2-2ubuntu0.22.04.2",
            "binary_name": "webp"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4863.json"
thunderbird

Package

Name
thunderbird
Purl
pkg:deb/ubuntu/thunderbird@1:102.15.1+build1-0ubuntu0.22.04.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:102.15.1+build1-0ubuntu0.22.04.1

Affected versions

1:91.*
1:91.1.2+build1-0ubuntu1
1:91.3.0+build2-0ubuntu1
1:91.3.1+build1-0ubuntu1
1:91.3.2+build1-0ubuntu1
1:91.4.0+build1.1-0ubuntu1
1:91.4.0+build2-0ubuntu1
1:91.5.0+build1-0ubuntu1
1:91.5.1+build1-0ubuntu1
1:91.6.1+build1-0ubuntu1
1:91.7.0+build1-0ubuntu1
1:91.7.0+build2-0ubuntu1
1:91.8.0+build2-0ubuntu1
1:91.9.1+build1-0ubuntu0.22.04.1
1:91.11.0+build2-0ubuntu0.22.04.1
1:102.*
1:102.2.2+build1-0ubuntu0.22.04.1
1:102.4.2+build2-0ubuntu0.22.04.1
1:102.7.1+build2-0ubuntu0.22.04.1
1:102.8.0+build2-0ubuntu0.22.04.1
1:102.9.0+build1-0ubuntu0.22.04.1
1:102.10.0+build2-0ubuntu0.22.04.1
1:102.11.0+build1-0ubuntu0.22.04.1
1:102.13.0+build1-0ubuntu0.22.04.1
1:102.15.0+build1-0ubuntu0.22.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.22.04.1",
            "binary_name": "thunderbird"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.22.04.1",
            "binary_name": "thunderbird-dev"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.22.04.1",
            "binary_name": "thunderbird-gnome-support"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.22.04.1",
            "binary_name": "thunderbird-mozsymbols"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.22.04.1",
            "binary_name": "xul-ext-calendar-timezones"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.22.04.1",
            "binary_name": "xul-ext-gdata-provider"
        },
        {
            "binary_version": "1:102.15.1+build1-0ubuntu0.22.04.1",
            "binary_name": "xul-ext-lightning"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4863.json"
Ubuntu:Pro:18.04:LTS
libwebp

Package

Name
libwebp
Purl
pkg:deb/ubuntu/libwebp@0.6.1-2ubuntu0.18.04.2+esm1?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.1-2ubuntu0.18.04.2+esm1

Affected versions

0.*
0.6.0-3
0.6.0-4
0.6.1-1
0.6.1-2
0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.6.1-2ubuntu0.18.04.2+esm1",
            "binary_name": "libwebp-dev"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.18.04.2+esm1",
            "binary_name": "libwebp6"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.18.04.2+esm1",
            "binary_name": "libwebpdemux2"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.18.04.2+esm1",
            "binary_name": "libwebpmux3"
        },
        {
            "binary_version": "0.6.1-2ubuntu0.18.04.2+esm1",
            "binary_name": "webp"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4863.json"