First published: Tue Nov 21 2023(Updated: )
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <115.5 | 115.5 |
redhat/thunderbird | <115.5 | 115.5 |
ubuntu/firefox | <120.0+ | 120.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
Mozilla Thunderbird | <115.5 | 115.5 |
Mozilla Firefox ESR | <115.5 | 115.5 |
Mozilla Firefox | <120.0 | |
Mozilla Firefox ESR | <115.5.0 | |
Mozilla Thunderbird | <115.5 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
debian/firefox | 123.0-1 | |
debian/firefox-esr | <=91.12.0esr-1~deb10u1 | 115.8.0esr-1~deb10u1 115.7.0esr-1~deb11u1 115.8.0esr-1~deb11u1 115.7.0esr-1~deb12u1 115.8.0esr-1~deb12u1 115.8.0esr-1 |
debian/thunderbird | <=1:91.12.0-1~deb10u1 | 1:115.8.0-1~deb10u1 1:115.7.0-1~deb11u1 1:115.8.0-1~deb11u1 1:115.7.0-1~deb12u1 1:115.8.0-1~deb12u1 1:115.7.0-1 1:115.8.1-1 |
Mozilla Firefox | <120 | 120 |
Debian | =10.0 | |
Debian | =11.0 | |
Debian | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2023-6212 is a vulnerability that affects Mozilla Firefox and Thunderbird versions prior to 115.5 and 120 respectively, allowing potential memory corruption and arbitrary code execution.
CVE-2023-6212 is classified as high severity with a severity value of 7.
CVE-2023-6212 affects Mozilla Firefox versions prior to 115.5 and Mozilla Thunderbird versions prior to 120.
CVE-2023-6212 can be exploited by exploiting memory corruption bugs in affected Firefox and Thunderbird versions to potentially run arbitrary code.
Yes, the fix for CVE-2023-6212 is available in Mozilla Firefox version 115.5 and higher, and Mozilla Thunderbird version 120 and higher. It is recommended to update to the latest version to mitigate the vulnerability.