First published: Tue Sep 26 2023(Updated: )
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <115.3 | 115.3 |
Mozilla Thunderbird | <115.3 | 115.3 |
redhat/firefox | <115.3 | 115.3 |
Mozilla Firefox | <118 | 118 |
Mozilla Firefox | <118 | |
Mozilla Firefox ESR | <115.3 | |
Mozilla Thunderbird | <115.3 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
Fedoraproject Fedora | =39 | |
debian/firefox | 132.0.2-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.4.0esr-1~deb11u1 128.3.1esr-1~deb12u1 128.4.0esr-1~deb12u1 128.3.1esr-2 128.4.0esr-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.4.3esr-1~deb11u1 1:115.16.0esr-1~deb12u1 1:128.4.0esr-1~deb12u1 1:128.4.2esr-1 1:128.4.3esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-5171 is a vulnerability that occurs during Ion compilation in Mozilla Firefox and Thunderbird, allowing an attacker to cause a potentially exploitable crash.
CVE-2023-5171 has a severity level of high (7).
The affected software products are Mozilla Firefox ESR up to version 115.3, Mozilla Firefox up to version 118, and Mozilla Thunderbird up to version 115.3.
An attacker can exploit CVE-2023-5171 by triggering a Garbage Collection during Ion compilation, resulting in a use-after-free condition.
The remedy for CVE-2023-5171 is to update Mozilla Firefox ESR to version 115.3 or later, Mozilla Firefox to version 118 or later, and Mozilla Thunderbird to version 115.3 or later.