CVE-2023-28177: High severity firefox vulnerability
Last updated 24 July 2024
Other sources
Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111.
— Launchpad
Mozilla developers and community members Calixte Denizet, Gabriele Svelto, Andrew McCreight, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-28177?
The severity of CVE-2023-28177 is high.
Which software is affected by CVE-2023-28177?
Mozilla Firefox versions up to exclusive 111.0+ on Ubuntu and Debian, including Ubuntu bionic, Ubuntu focal, and Debian.
What is the remedy for CVE-2023-28177 on Mozilla Firefox?
Upgrade Mozilla Firefox to version 111.0+.
Where can I find more information about CVE-2023-28177?
You can find more information about CVE-2023-28177 in the references provided: [Mozilla Bugzilla](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1803109%2C1808832%2C1809542%2C1817336), [Mozilla Security Advisory](https://www.mozilla.org/security/advisories/mfsa2023-09/), and [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-28177).