Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6865

Опубликовано: 19 дек. 2023
Источник: redhat
CVSS3: 7.5

Описание

EncryptingOutputStream was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

The Mozilla Foundation Security Advisory describes this flaw as: EncryptingOutputStream was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdNot affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9thunderbirdNot affected
Red Hat Enterprise Linux 7firefoxFixedRHSA-2024:002602.01.2024
Red Hat Enterprise Linux 8firefoxFixedRHSA-2024:001202.01.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportfirefoxFixedRHSA-2024:002302.01.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicefirefoxFixedRHSA-2024:002302.01.2024
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsfirefoxFixedRHSA-2024:002302.01.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-908
https://bugzilla.redhat.com/show_bug.cgi?id=2255361Mozilla: Potential exposure of uninitialized data in <code>EncryptingOutputStream</code>

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

CVSS3: 6.5
nvd
больше 1 года назад

`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

CVSS3: 6.5
debian
больше 1 года назад

`EncryptingOutputStream` was susceptible to exposing uninitialized dat ...

CVSS3: 6.5
github
больше 1 года назад

`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость режима инкогнито браузеров Mozilla Firefox, Firefox ESR, связанная с использованием неинициализированных переменных, позволяющая нарушителю раскрыть защищаемую информацию

7.5 High

CVSS3