Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5169

Опубликовано: 27 сент. 2023
Источник: debian
EPSS Низкий

Описание

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed118.0-1package
firefox-esrfixed115.3.0esr-1package
thunderbirdfixed1:115.3.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-41/#CVE-2023-5169

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-42/#CVE-2023-5169

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-43/#CVE-2023-5169

EPSS

Процентиль: 50%
0.00267
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
redhat
почти 2 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
nvd
почти 2 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
github
почти 2 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость веб-браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 50%
0.00267
Низкий