CVE-2023-5171: Use After Free
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5171?
CVE-2023-5171 is a vulnerability that occurs during Ion compilation in Mozilla Firefox and Thunderbird, allowing an attacker to cause a potentially exploitable crash.
What is the severity of CVE-2023-5171?
CVE-2023-5171 has a severity level of high (7).
Which software products are affected by CVE-2023-5171?
The affected software products are Mozilla Firefox ESR up to version 115.3, Mozilla Firefox up to version 118, and Mozilla Thunderbird up to version 115.3.
How can an attacker exploit CVE-2023-5171?
An attacker can exploit CVE-2023-5171 by triggering a Garbage Collection during Ion compilation, resulting in a use-after-free condition.
Is there a remedy available for CVE-2023-5171?
The remedy for CVE-2023-5171 is to update Mozilla Firefox ESR to version 115.3 or later, Mozilla Firefox to version 118 or later, and Mozilla Thunderbird to version 115.3 or later.