Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1942

Опубликовано: 04 мар. 2025
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: When String.toUpperCase() causes a string to get longer, it is possible for uninitialized memory to be incorporated into the result string.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10firefox-flatpak-containerFix deferred
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 9firefoxFix deferred
Red Hat Enterprise Linux 9firefox-flatpak-containerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2349791firefox: Disclosure of uninitialized memory when .toUpperCase() causes string to get longer

EPSS

Процентиль: 38%
0.00465
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

CVSS3: 9.8
nvd
больше 1 года назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

CVSS3: 9.8
debian
больше 1 года назад

When String.toUpperCase() caused a string to get longer it was possibl ...

CVSS3: 6.5
github
больше 1 года назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.

CVSS3: 6.3
fstec
больше 1 года назад

Уязвимость функции String.toUpperCase() браузера Mozilla Firefox и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 38%
0.00465
Низкий

6.3 Medium

CVSS3