First published: Tue Feb 14 2023(Updated: )
An invalid downcast from `nsTextNode` to `SVGElement` could have lead to undefined behavior. External Reference: <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25737">https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25737</a>
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <0:102.8.0-2.el7_9 | 0:102.8.0-2.el7_9 |
redhat/thunderbird | <0:102.8.0-2.el7_9 | 0:102.8.0-2.el7_9 |
redhat/firefox | <0:102.8.0-2.el8_7 | 0:102.8.0-2.el8_7 |
redhat/thunderbird | <0:102.8.0-2.el8_7 | 0:102.8.0-2.el8_7 |
redhat/firefox | <0:102.8.0-2.el8_1 | 0:102.8.0-2.el8_1 |
redhat/thunderbird | <0:102.8.0-2.el8_1 | 0:102.8.0-2.el8_1 |
redhat/firefox | <0:102.8.0-2.el8_2 | 0:102.8.0-2.el8_2 |
redhat/thunderbird | <0:102.8.0-2.el8_2 | 0:102.8.0-2.el8_2 |
redhat/firefox | <0:102.8.0-2.el8_4 | 0:102.8.0-2.el8_4 |
redhat/thunderbird | <0:102.8.0-2.el8_4 | 0:102.8.0-2.el8_4 |
redhat/firefox | <0:102.8.0-2.el8_6 | 0:102.8.0-2.el8_6 |
redhat/thunderbird | <0:102.8.0-2.el8_6 | 0:102.8.0-2.el8_6 |
redhat/firefox | <0:102.8.0-2.el9_1 | 0:102.8.0-2.el9_1 |
redhat/thunderbird | <0:102.8.0-2.el9_1 | 0:102.8.0-2.el9_1 |
redhat/firefox | <0:102.8.0-2.el9_0 | 0:102.8.0-2.el9_0 |
redhat/thunderbird | <0:102.8.0-2.el9_0 | 0:102.8.0-2.el9_0 |
Mozilla Thunderbird | <102.8 | 102.8 |
Mozilla Firefox ESR | <102.8 | 102.8 |
redhat/firefox | <102.8 | 102.8 |
redhat/thunderbird | <102.8 | 102.8 |
Mozilla Firefox | <110 | 110 |
Mozilla Firefox | <110.0 | |
Mozilla Firefox ESR | <102.8 | |
Mozilla Thunderbird | <102.8 | |
debian/firefox | 131.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.16.0esr-1~deb11u1 1:115.12.0-1~deb12u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2023-25737 is a vulnerability that allows for an invalid downcast from nsTextNode to SVGElement, leading to undefined behavior.
Firefox versions before 110, Thunderbird versions before 102.8, and Firefox ESR versions before 102.8 are affected by CVE-2023-25737.
CVE-2023-25737 has a severity rating of 8.8, which is considered high.
To fix CVE-2023-25737, update to Firefox version 110 or later, Thunderbird version 102.8 or later, or Firefox ESR version 102.8 or later.
You can find more information about CVE-2023-25737 in the Mozilla Security Advisory (MFSA2023-05) and the bug report (Bugzilla ID 1811464).