CVE-2023-4048: High severity thunderbird vulnerability
Published Aug 1, 2023
·Updated
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations.
Affected Software
21 affected componentsFixes available
redhat/firefox<102.14
102.14
redhat/firefox<115.1
115.1
redhat/thunderbird<102.14
102.14
redhat/thunderbird<115.1
115.1
Mozilla Thunderbird<102.14
102.14
Mozilla Thunderbird<115.1
115.1
Mozilla Firefox<116
116
Mozilla Firefox ESR<115.1
115.1
Mozilla Firefox ESR<102.14
102.14
Mozilla Firefox<116.0
Mozilla Firefox>=102.0<102.14
Mozilla Firefox>=115.0<115.1
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Mozilla Firefox ESR<102.14
Mozilla Firefox ESR>=102.0<102.14
Mozilla Firefox ESR>=115.0<115.1
debian/firefox
137.0.2-1
debian/firefox-esr
115.14.0esr-1~deb11u1128.9.0esr-1~deb11u1128.8.0esr-1~deb12u1128.9.0esr-1~deb12u1128.9.0esr-2
debian/thunderbird
1:115.12.0-1~deb11u11:128.9.0esr-1~deb11u11:128.8.0esr-1~deb12u11:128.9.0esr-1~deb12u11:128.9.0esr-1
Event History
Aug 1, 2023
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:24 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:16 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·02:08 PM
DescriptionAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-4048?
The severity of CVE-2023-4048 is high (severity value 7).
2
How does CVE-2023-4048 affect Firefox and Firefox ESR?
CVE-2023-4048 affects Firefox versions < 116 and Firefox ESR versions < 102.14.
3
How does CVE-2023-4048 affect Thunderbird?
CVE-2023-4048 affects Thunderbird versions < 115.1.
4
How do I fix CVE-2023-4048 in Firefox?
To fix CVE-2023-4048 in Firefox, update to version 116 or newer.
5
How do I fix CVE-2023-4048 in Thunderbird?
To fix CVE-2023-4048 in Thunderbird, update to version 115.1 or newer.