Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3600

Опубликовано: 11 июл. 2023
Источник: redhat
CVSS3: 8.8

Описание

During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.

The Mozilla Foundation Security Advisory describes this flaw as: During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2023:547505.10.2023
Red Hat Enterprise Linux 7firefoxFixedRHSA-2023:547705.10.2023
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2023:542804.10.2023
Red Hat Enterprise Linux 8firefoxFixedRHSA-2023:543304.10.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsthunderbirdFixedRHSA-2023:543804.10.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsfirefoxFixedRHSA-2023:544004.10.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportfirefoxFixedRHSA-2023:542604.10.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupportthunderbirdFixedRHSA-2023:543204.10.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2222652firefox: use-after-free in workers

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 2 года назад

During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.

CVSS3: 8.8
nvd
почти 2 года назад

During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.

CVSS3: 8.8
debian
почти 2 года назад

During the worker lifecycle, a use-after-free condition could have occ ...

suse-cvrf
почти 2 года назад

Security update for MozillaFirefox

suse-cvrf
почти 2 года назад

Security update for MozillaFirefox

8.8 High

CVSS3