CVE-2023-25751: Code Injection
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of invalidating JIT code while following an iterator. The newly generated code could be overwritten incorrectly, leading to a potentially exploitable crash.
Other sources
Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-25751?
The severity of CVE-2023-25751 is high (7).
Which products are affected by CVE-2023-25751?
Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9 are affected by CVE-2023-25751.
How can I fix CVE-2023-25751 in Firefox?
You can fix CVE-2023-25751 in Firefox by updating to version 111 or higher.
How can I fix CVE-2023-25751 in Firefox ESR?
You can fix CVE-2023-25751 in Firefox ESR by updating to version 102.9 or higher.
How can I fix CVE-2023-25751 in Thunderbird?
You can fix CVE-2023-25751 in Thunderbird by updating to version 102.9 or higher.