Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-4582

Опубликовано: 11 сент. 2023
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS3: 8.8

Описание

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating too much private shader memory on mac OS. This bug only affects Firefox on macOS. Other operating systems are unaffected. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

only affects macOS
esm-infra/focal

DNE

focal

not-affected

only affects macOS
jammy

not-affected

only affects macOS
lunar

not-affected

only affects macOS
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

only affects macOS
esm-infra/focal

DNE

focal

DNE

jammy

not-affected

only affects macOS
lunar

not-affected

only affects macOS
trusty

DNE

upstream

ignored

only affects macOS
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps/bionic

not-affected

only affects macOS
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

trusty

DNE

upstream

ignored

only affects macOS
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps/focal

not-affected

only affects macOS
esm-infra/bionic

not-affected

only affects macOS
focal

not-affected

only affects macOS
jammy

DNE

lunar

DNE

trusty

DNE

upstream

ignored

only affects macOS
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

not-affected

only affects macOS
focal

not-affected

only affects macOS
jammy

DNE

lunar

DNE

trusty

DNE

upstream

ignored

only affects macOS
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/jammy

not-affected

only affects macOS
esm-infra/focal

DNE

focal

DNE

jammy

not-affected

only affects macOS
lunar

not-affected

only affects macOS
trusty

DNE

upstream

ignored

only affects macOS
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

not-affected

only affects macOS
lunar

DNE

trusty

DNE

upstream

ignored

only affects macOS
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

only affects macOS
esm-infra/focal

DNE

focal

not-affected

only affects macOS
jammy

not-affected

only affects macOS
lunar

not-affected

only affects macOS
trusty

ignored

end of standard support
upstream

ignored

only affects macOS
xenial

ignored

end of standard support

Показывать по

Ссылки на источники

EPSS

Процентиль: 69%
0.00617
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
почти 2 года назад

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 8.8
nvd
почти 2 года назад

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 8.8
debian
почти 2 года назад

Due to large allocation checks in Angle for glsl shaders being too len ...

CVSS3: 8.8
github
почти 2 года назад

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occured when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 7.3
fstec
почти 2 года назад

Уязвимость функции glGetProgramiv браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 69%
0.00617
Низкий

8.8 High

CVSS3

Уязвимость CVE-2023-4582