CVE-2023-4573: Memory corruption in IPC CanvasTranslator
Last updated 24 July 2024
Other sources
When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-36/#CVE-2023-4573
— Red Hat
When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
— Launchpad
When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4573?
CVE-2023-4573 is a vulnerability in Mozilla Firefox and Thunderbird that could lead to a use-after-free causing a potentially exploitable crash.
Which software is affected by CVE-2023-4573?
CVE-2023-4573 affects Firefox versions less than 117, Firefox ESR versions less than 102.15, Thunderbird versions less than 102.15, and Thunderbird versions less than 115.2.
What is the severity of CVE-2023-4573?
CVE-2023-4573 has a severity rating of 6.5 (High).
How can I fix CVE-2023-4573?
To fix CVE-2023-4573, update your Mozilla Firefox or Thunderbird to the latest version, which is 117 or 102.15, respectively.
Where can I find more information about CVE-2023-4573?
You can find more information about CVE-2023-4573 on the Mozilla website and Bugzilla.