Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1942

Опубликовано: 04 мар. 2025
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: When String.toUpperCase() causes a string to get longer, it is possible for uninitialized memory to be incorporated into the result string.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 9firefoxFix deferred
Red Hat Enterprise Linux 9firefox-flatpak-containerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2349791firefox: Disclosure of uninitialized memory when .toUpperCase() causes string to get longer

EPSS

Процентиль: 29%
0.00099
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

CVSS3: 9.8
nvd
4 месяца назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

CVSS3: 9.8
debian
4 месяца назад

When String.toUpperCase() caused a string to get longer it was possibl ...

CVSS3: 6.5
github
4 месяца назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.

CVSS3: 6.3
fstec
4 месяца назад

Уязвимость функции String.toUpperCase() браузера Mozilla Firefox и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 29%
0.00099
Низкий

6.3 Medium

CVSS3