CVE-2023-25746: High severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and Firefox ESR < 102.8.
Mozilla developers Philipp and Gabriele Svelto reported memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Mozilla developers Philipp and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-25746?
CVE-2023-25746 is a vulnerability that involves memory safety bugs present in Thunderbird and Firefox ESR, which could be exploited to run arbitrary code.
How severe is CVE-2023-25746?
CVE-2023-25746 has a severity score of 8.8 (high).
Which software versions are affected by CVE-2023-25746?
Versions up to exclusive 102.8 of Thunderbird, Firefox ESR 102.8, and specific versions of Red Hat, Ubuntu, and Debian packages are affected by CVE-2023-25746.
Where can I find more information about CVE-2023-25746?
You can find more information about CVE-2023-25746 in the Bugzilla and Mozilla security advisories links provided in the references.
What is the Common Weakness Enumeration (CWE) related to CVE-2023-25746?
The CWE related to CVE-2023-25746 is CWE-120 (Buffer Copy without Checking Size of Input).