[MFSA-2023-40] Security Vulnerability fixed in Firefox 117.0.1, Firefox ESR 115.2.1, Firefox ESR 102.15.1, Thunderbird 102.15.1, and Thunderbird 115.2.2

Severity Critical
Affected Packages 5
Fixed Packages 5
CVEs 1
  • CVE-2023-4863: Heap buffer overflow in libwebp (critical) Opening a malicious WebP image could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild. Note: This advisory was previously also tracked as CVE-2023-5129.
ID
MFSA-2023-40
Severity
critical
URL
https://www.mozilla.org/en-US/security/advisories/mfsa2023-40
Published
2023-09-12T00:00:00
(12 months ago)
Modified
2023-09-12T00:00:00
(12 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 102.15.1
Fixed pkg:mozilla/Thunderbird Thunderbird = 102.15.1
Affected pkg:mozilla/Thunderbird Thunderbird < 115.2.2
Fixed pkg:mozilla/Thunderbird Thunderbird = 115.2.2
Affected pkg:mozilla/Firefox%20ESR Firefox ESR < 115.2.1
Fixed pkg:mozilla/Firefox%20ESR Firefox ESR = 115.2.1
Affected pkg:mozilla/Firefox%20ESR Firefox ESR < 102.15.1
Fixed pkg:mozilla/Firefox%20ESR Firefox ESR = 102.15.1
Affected pkg:mozilla/Firefox Firefox < 117.0.1
Fixed pkg:mozilla/Firefox Firefox = 117.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...