CVE-2023-25732: High severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
The Mozilla Foundation Security Advisory describes this flaw as: When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write.
When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25732
— Red Hat
When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this security vulnerability?
The vulnerability ID for this security vulnerability is CVE-2023-25732.
Which software is affected by this vulnerability?
This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
What is the severity of CVE-2023-25732?
The severity of CVE-2023-25732 is rated as high with a score of 8.8.
How does CVE-2023-25732 impact the affected software?
CVE-2023-25732 can potentially lead to an out of bounds memory write when encoding data from an inputStream in xpcom.
Where can I find more information about CVE-2023-25732?
You can find more information about CVE-2023-25732 at the following references: - [Mozilla Security Advisory](https://www.mozilla.org/security/advisories/mfsa2023-05/) - [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1804564) - [Mozilla Security Advisory](https://www.mozilla.org/security/advisories/mfsa2023-07/)