Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1942

Опубликовано: 04 мар. 2025
Источник: redhat
CVSS3: 6.3

Описание

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: When String.toUpperCase() causes a string to get longer, it is possible for uninitialized memory to be incorporated into the result string.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10firefox-flatpak-containerFix deferred
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 9firefoxFix deferred
Red Hat Enterprise Linux 9firefox-flatpak-containerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2349791firefox: Disclosure of uninitialized memory when .toUpperCase() causes string to get longer

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 месяцев назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

CVSS3: 9.8
nvd
5 месяцев назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.

CVSS3: 9.8
debian
5 месяцев назад

When String.toUpperCase() caused a string to get longer it was possibl ...

CVSS3: 6.5
github
5 месяцев назад

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136.

CVSS3: 6.3
fstec
5 месяцев назад

Уязвимость функции String.toUpperCase() браузера Mozilla Firefox и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

6.3 Medium

CVSS3