CVE-2023-25752: Medium severity thunderbird vulnerability
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue that when accessing throttled streams, the count of available bytes needs to be checked in the calling function to be within bounds. This may have led future code to be incorrect and vulnerable.
Other sources
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-25752?
CVE-2023-25752 is a vulnerability in Mozilla that occurs when accessing throttled streams and can lead to incorrect and vulnerable code.
Which software products are affected by CVE-2023-25752?
Mozilla Thunderbird versions up to 102.9, Mozilla Firefox versions up to 111, and certain versions of Red Hat Firefox and Thunderbird packages are affected.
What is the severity of CVE-2023-25752?
CVE-2023-25752 has a severity rating of 6.1.
How can I fix CVE-2023-25752?
To fix CVE-2023-25752, update to the latest version of Mozilla Thunderbird or Mozilla Firefox, and ensure you have the latest security patches for Red Hat Firefox and Thunderbird packages.
Where can I find more information about CVE-2023-25752?
You can find more information about CVE-2023-25752 in the Mozilla Foundation Security Advisory and Bugzilla.