Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5169

Опубликовано: 27 сент. 2023
Источник: debian

Описание

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed118.0-1package
firefox-esrfixed115.3.0esr-1package
thunderbirdfixed1:115.3.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-41/#CVE-2023-5169

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-42/#CVE-2023-5169

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-43/#CVE-2023-5169

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
redhat
больше 1 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
nvd
больше 1 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
github
больше 1 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость веб-браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании