CVE-2023-4050: Buffer Overflow
In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4050?
The severity of CVE-2023-4050 is high.
Which software is affected by CVE-2023-4050?
CVE-2023-4050 affects Mozilla Thunderbird, Firefox, and Firefox ESR.
How can I fix CVE-2023-4050?
To fix CVE-2023-4050, update Mozilla Thunderbird to version 115.1, Firefox to version 116, or Firefox ESR to version 102.14.
Are there any references related to CVE-2023-4050?
Yes, you can find more information about CVE-2023-4050 at the following links: [Link1](https://www.mozilla.org/security/advisories/mfsa2023-30/), [Link2](https://www.mozilla.org/security/advisories/mfsa2023-31/), [Link3](https://bugzilla.mozilla.org/show_bug.cgi?id=1843038).
What is the Common Weakness Enumeration (CWE) for CVE-2023-4050?
The CWE for CVE-2023-4050 is CWE-787.