First published: Tue Jul 11 2023(Updated: )
During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <115.0.1 | 115.0.1 |
redhat/firefox | <115.0.2 | 115.0.2 |
redhat/thunderbird | <115.0.1 | 115.0.1 |
Mozilla Firefox | <115.0.2 | 115.0.2 |
Mozilla Firefox ESR | <115.0.2 | 115.0.2 |
Mozilla Firefox | <115.0.2 | |
Mozilla Firefox ESR | <115.0.2 | |
Mozilla Thunderbird | <115.0.1 | |
ubuntu/firefox | <115.0.2+ | 115.0.2+ |
ubuntu/firefox | <115.0.2-1 | 115.0.2-1 |
ubuntu/thunderbird | <1:115.3.1+ | 1:115.3.1+ |
ubuntu/thunderbird | <1:115.3.1+ | 1:115.3.1+ |
ubuntu/thunderbird | <1:115.3.1+ | 1:115.3.1+ |
ubuntu/thunderbird | <1:115.2.0+ | 1:115.2.0+ |
ubuntu/thunderbird | <1:115.2.0+ | 1:115.2.0+ |
ubuntu/thunderbird | <115.0.1 | 115.0.1 |
debian/firefox | 128.0.2-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.13.0-1~deb11u1 1:115.12.0-1~deb12u1 1:115.13.0-1~deb12u1 1:115.13.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2023-3600.
The severity of CVE-2023-3600 is high with a CVSS score of 8.8.
CVE-2023-3600 affects Firefox versions less than 115.0.2, Firefox ESR versions less than 115.0.2, and Thunderbird versions less than 115.0.1.
The use-after-free condition could potentially lead to a crash that can be exploited.
To fix CVE-2023-3600, update to Firefox 115.0.2, Firefox ESR 115.0.2, or Thunderbird 115.0.1 or later.