[MFSA-2023-44] Security Vulnerability fixed in Firefox 118.0.1, Firefox ESR 115.3.1, Firefox for Android 118.1.0, Firefox Focus for Android 118.1.0, and Thunderbird 115.3.1.

Severity Critical
Affected Packages 5
Fixed Packages 5
CVEs 1
  • CVE-2023-5217: Heap buffer overflow in libvpx (critical) Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Thunderbird Thunderbird < 115.3.1
Fixed pkg:mozilla/Thunderbird Thunderbird = 115.3.1
Affected pkg:mozilla/Firefox?os=android Firefox < 118.1.0
Fixed pkg:mozilla/Firefox?os=android Firefox = 118.1.0
Affected pkg:mozilla/Firefox%20Focus?os=android Firefox Focus < 118.1.0
Fixed pkg:mozilla/Firefox%20Focus?os=android Firefox Focus = 118.1.0
Affected pkg:mozilla/Firefox%20ESR Firefox ESR < 115.3.1
Fixed pkg:mozilla/Firefox%20ESR Firefox ESR = 115.3.1
Affected pkg:mozilla/Firefox Firefox < 118.0.1
Fixed pkg:mozilla/Firefox Firefox = 118.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...