CVE-2023-4057: Critical severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4057?
The severity of CVE-2023-4057 is critical with a score of 9.8.
Which versions of Firefox and Thunderbird are affected by CVE-2023-4057?
Versions Firefox < 116, Firefox ESR < 115.1, Thunderbird < 115.1 are affected by CVE-2023-4057.
Are there any known exploits for CVE-2023-4057?
There is evidence that with enough effort, the memory corruption bugs in CVE-2023-4057 could be exploited to run arbitrary code.
How can I fix CVE-2023-4057?
To fix CVE-2023-4057, update Firefox to version 116 or later, Firefox ESR to version 115.1 or later, and Thunderbird to version 115.1 or later.
Where can I find more information about CVE-2023-4057?
You can find more information about CVE-2023-4057 in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1841682), [Mozilla Advisory](https://www.mozilla.org/security/advisories/mfsa2023-29/), [Mozilla Advisory](https://www.mozilla.org/security/advisories/mfsa2023-31/).