CVE-2023-5171

CVSS v3.1 6.5 (Medium)
65% Progress
EPSS 0.09 % (40th)
0.09% Progress
Affected Products 5
Advisories 31

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2023-09-27 15:19:42
(11 months ago)
Updated Date
2023-10-12 02:52:09
(11 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 118 version cpe:2.3:a:mozilla:firefox < 118
  Mozilla Firefox Esr prior 115.3 version cpe:2.3:a:mozilla:firefox_esr < 115.3
  Mozilla Thunderbird prior 115.3 version cpe:2.3:a:mozilla:thunderbird < 115.3

Configuration #2

    CPE23 From Up To
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
  Debian Linux 11.0 cpe:2.3:o:debian:debian_linux:11.0
  Debian Linux 12.0 cpe:2.3:o:debian:debian_linux:12.0

Configuration #3

    CPE23 From Up To
  Fedoraproject Fedora 39 cpe:2.3:o:fedoraproject:fedora:39
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...