CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation
On Windows, an integer overflow could occur in RecordedSourceSurfaceCreation which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. This bug only affects Firefox on Windows. Other operating systems are unaffected. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
Other sources
On Windows, an integer overflow could occur in RecordedSourceSurfaceCreation which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape.This bug only affects Firefox on Windows. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4576?
CVE-2023-4576 is a vulnerability in Mozilla Firefox and Thunderbird on Windows that allows an integer overflow, resulting in a heap buffer overflow and potential data leakage that could lead to a sandbox escape.
Which operating systems are affected by CVE-2023-4576?
This vulnerability only affects Firefox and Thunderbird on Windows. Other operating systems are unaffected.
What is the severity of CVE-2023-4576?
CVE-2023-4576 has a severity score of 8.6 (high).
How can I fix CVE-2023-4576?
To fix CVE-2023-4576, users should update Mozilla Firefox or Thunderbird to the recommended versions provided by Mozilla.
Where can I find more information about CVE-2023-4576?
You can find more information about CVE-2023-4576 on the Mozilla website and the bugzilla.mozilla.org website.