CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback
Last updated 24 July 2024
Other sources
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4575?
CVE-2023-4575 is a vulnerability in Mozilla Thunderbird and Firefox that could lead to a use-after-free causing a potentially exploitable crash.
Which software is affected by CVE-2023-4575?
Mozilla Thunderbird versions up to exclusive 102.15, Mozilla Firefox versions up to exclusive 117, Firefox ESR versions up to exclusive 102.15 are affected by CVE-2023-4575.
How severe is CVE-2023-4575?
CVE-2023-4575 has a severity rating of 6.5 (high).
How can I fix CVE-2023-4575?
To fix CVE-2023-4575, update Mozilla Thunderbird to version 102.15 or later, update Mozilla Firefox to version 117 or later, or update Firefox ESR to version 102.15 or later.
Where can I find more information about CVE-2023-4575?
You can find more information about CVE-2023-4575 on the Mozilla Bugzilla website and the Mozilla Security Advisories page.