CVE-2023-28176: High severity thunderbird vulnerability
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory described the issue in which Mozilla developers Timothy Nikkel, Andrew McCreight, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 110 and ESR 102.8. Some of these bugs showed evidence of memory corruption, and we presume that with enough effort, some of these could have been exploited to run arbitrary code.
Other sources
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Mozilla developers Timothy Nikkel, Andrew McCreight, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Mozilla developers Timothy Nikkel, Andrew McCreight, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-28176?
CVE-2023-28176 is a vulnerability in Mozilla that allows memory corruption.
What is the severity of CVE-2023-28176?
The severity of CVE-2023-28176 is high.
Which software is affected by CVE-2023-28176?
CVE-2023-28176 affects Mozilla Firefox (up to version 111) and Mozilla Thunderbird (up to version 102.9).
How can I fix CVE-2023-28176?
To fix CVE-2023-28176, update Mozilla Firefox to version 111 or higher, and update Mozilla Thunderbird to version 102.9 or higher.
Where can I find more information about CVE-2023-28176?
You can find more information about CVE-2023-28176 on the Mozilla Foundation Security Advisory page.