CVE-2023-34417: Critical severity Mozilla Firefox vulnerability
Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.
Other sources
Mozilla developers and community members Andrew McCreight, Randell Jesup, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 114.0+ - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 123.0-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 114
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-34417?
The severity of CVE-2023-34417 is high.
Who reported the memory safety bugs in Mozilla Firefox 113?
The memory safety bugs in Mozilla Firefox 113 were reported by Mozilla developers and community members Andrew McCreight, Randell Jesup, and the Mozilla Fuzzing Team.
Is there evidence of memory corruption in CVE-2023-34417?
Yes, there is evidence of memory corruption in CVE-2023-34417.
Is there a fix available for CVE-2023-34417?
Yes, a fix is available for CVE-2023-34417 in Mozilla Firefox version 114 or higher.
Where can I find more information about CVE-2023-34417?
You can find more information about CVE-2023-34417 at the following references: - Bugzilla: https://bugzilla.mozilla.org/buglist.cgi?bug_id=1746447%2C1820903%2C1832832 - Mozilla Security Advisories: https://www.mozilla.org/security/advisories/mfsa2023-20/ - Launchpad: https://launchpad.net/bugs/cve/CVE-2023-34417