CVE-2023-25737: Incorrect Type Cast
An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25737
Other sources
An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior.
The Mozilla Foundation Security Advisory describes this flaw as: An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-25737?
CVE-2023-25737 is a vulnerability that allows for an invalid downcast from nsTextNode to SVGElement, leading to undefined behavior.
Which software versions are affected by CVE-2023-25737?
Firefox versions before 110, Thunderbird versions before 102.8, and Firefox ESR versions before 102.8 are affected by CVE-2023-25737.
How severe is CVE-2023-25737?
CVE-2023-25737 has a severity rating of 8.8, which is considered high.
What is the remedy for CVE-2023-25737?
To fix CVE-2023-25737, update to Firefox version 110 or later, Thunderbird version 102.8 or later, or Firefox ESR version 102.8 or later.
Where can I find more information about CVE-2023-25737?
You can find more information about CVE-2023-25737 in the Mozilla Security Advisory (MFSA2023-05) and the bug report (Bugzilla ID 1811464).