CVE-2023-5169: Medium severity thunderbird vulnerability
A compromised content process could have provided malicious data in a PathRecording resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-42/#CVE-2023-5169
Other sources
A compromised content process could have provided malicious data in a PathRecording resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
— Launchpad
A compromised content process could have provided malicious data in a PathRecording resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.
— Mozilla
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5169?
CVE-2023-5169 is a vulnerability in Mozilla Firefox and Firefox ESR that could allow a compromised content process to cause an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.
What software is affected by CVE-2023-5169?
Mozilla Firefox, Firefox ESR, and Thunderbird versions up to and including 115.3 and 118 are affected by CVE-2023-5169.
How severe is CVE-2023-5169?
CVE-2023-5169 has a severity level of 'high' with a CVSS score of 7.
How can I fix CVE-2023-5169?
To fix CVE-2023-5169, update Mozilla Firefox, Firefox ESR, or Thunderbird to a version higher than 115.3 and 118 respectively.
Where can I find more information about CVE-2023-5169?
You can find more information about CVE-2023-5169 in the Mozilla Security Advisory MFSA2023-42 and MFSA2023-41.