CVE-2023-37209: Use After Free
A use-after-free condition existed in NotifyOnHistoryReload where a LoadingSessionHistoryEntry object was freed and a reference to that object remained. This resulted in a potentially exploitable condition when the reference to that object was later reused. This vulnerability affects Firefox < 115.
Other sources
A use-after-free condition existed in NotifyOnHistoryReload where a LoadingSessionHistoryEntry object was freed and a reference to that object remained. This resulted in a potentially exploitable condition when the reference to that object was later reused.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0-1 - Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0+ - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 123.0-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 115
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-37209?
CVE-2023-37209 is a vulnerability in Firefox that allows for a use-after-free condition to occur, potentially leading to exploitation.
How does CVE-2023-37209 affect Firefox?
CVE-2023-37209 affects Firefox versions up to and including 115.0-1 on Ubuntu and 115.0+ on Ubuntu focal, as well as Debian Firefox version 117.0.1-1.
What is the severity of CVE-2023-37209?
CVE-2023-37209 has a severity level of medium with a score of 4.
How can I fix CVE-2023-37209 in Firefox?
To fix CVE-2023-37209 in Firefox, update to version 115.0 or higher on Ubuntu, version 117.0.1-1 on Debian, or the latest version available for your operating system.
Where can I find more information about CVE-2023-37209?
More information about CVE-2023-37209 can be found in the Mozilla Bugzilla report (https://bugzilla.mozilla.org/show_bug.cgi?id=1837993) and the Mozilla Security Advisories (https://www.mozilla.org/security/advisories/mfsa2023-22/).