CVE-2023-37211: High severity Mozilla Thunderbird vulnerability
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Other sources
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-23/#CVE-2023-37211
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0-1 - Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0+ - Upgrade
Upgrade
ubuntu/thunderbirdto a version that resolves this vulnerability.Fixed in 1:102.13.0+ - Upgrade
Upgrade
ubuntu/mozjs102to a version that resolves this vulnerability.Fixed in 102.13.0-0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/mozjs102to a version that resolves this vulnerability.Fixed in 102.13.0-0ubuntu0.22.10.1 - Upgrade
Upgrade
ubuntu/mozjs102to a version that resolves this vulnerability.Fixed in 102.13.0-0ubuntu0.23.04.1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 102.13 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.13 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 123.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.8.0esr-1~deb10u1Fixed in 115.7.0esr-1~deb11u1Fixed in 115.8.0esr-1~deb11u1Fixed in 115.7.0esr-1~deb12u1Fixed in 115.8.0esr-1~deb12u1Fixed in 115.8.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.8.0-1~deb10u1Fixed in 1:115.7.0-1~deb11u1Fixed in 1:115.8.0-1~deb11u1Fixed in 1:115.7.0-1~deb12u1Fixed in 1:115.8.0-1~deb12u1Fixed in 1:115.7.0-1Fixed in 1:115.8.1-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 102.13 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 115 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 102.13
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-37211?
CVE-2023-37211 is a vulnerability related to memory safety bugs found in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12.
How severe is CVE-2023-37211?
CVE-2023-37211 has a severity rating of high.
Which software versions are affected by CVE-2023-37211?
CVE-2023-37211 affects Firefox versions less than 115, Firefox ESR versions less than 102.13, and Thunderbird versions less than 102.13.
How can I fix CVE-2023-37211?
To fix CVE-2023-37211, update Firefox to version 115 or later, Firefox ESR to version 102.13 or later, and Thunderbird to version 102.13 or later.
Where can I find more information about CVE-2023-37211?
More information about CVE-2023-37211 can be found on the Mozilla security advisories: mfsa2023-22 and mfsa2023-23.