CVE-2023-5170: High severity firefox vulnerability
Published Sep 26, 2023
·Updated
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<118
118
Mozilla Firefox<118.0
debian/firefox
137.0.2-1
Event History
Sep 26, 2023
CVE Published
via Mozilla·12:00 AM
Sep 27, 2023
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:28 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:17 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·04:43 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-5170?
The severity of CVE-2023-5170 is high.
2
How does CVE-2023-5170 affect Mozilla Firefox?
CVE-2023-5170 affects Mozilla Firefox versions up to exclusive version 118.
3
What is the potential risk of CVE-2023-5170?
CVE-2023-5170 could lead to a memory leak of a privileged process and potentially be used for sandbox escape.
4
How can the vulnerability be fixed in Mozilla Firefox?
To fix CVE-2023-5170, update Mozilla Firefox to version 118 or later.
5
Where can I find more information about CVE-2023-5170?
You can find more information about CVE-2023-5170 on the Mozilla Bugzilla website and the Mozilla security advisories page.