First published: Tue Dec 19 2023(Updated: )
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <115.6 | 115.6 |
Mozilla Firefox ESR | <115.6 | 115.6 |
redhat/firefox | <115.6 | 115.6 |
redhat/thunderbird | <115.6 | 115.6 |
Mozilla Firefox | <121 | 121 |
Mozilla Firefox | <121.0 | |
Mozilla Firefox ESR | <115.6 | |
Mozilla Thunderbird | <115.6 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
ubuntu/firefox | <121.0+ | 121.0+ |
ubuntu/thunderbird | <1:115.6.0+ | 1:115.6.0+ |
ubuntu/thunderbird | <1:115.6.0+ | 1:115.6.0+ |
ubuntu/thunderbird | <1:115.6.0+ | 1:115.6.0+ |
ubuntu/thunderbird | <1:115.6.0+ | 1:115.6.0+ |
ubuntu/thunderbird | <1:115.6.0+ | 1:115.6.0+ |
debian/firefox | 130.0-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 115.14.0esr-1~deb12u1 115.14.0esr-1 115.15.0esr-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.14.0-1~deb11u1 1:115.12.0-1~deb12u1 1:115.14.0-1~deb12u1 1:115.13.0-1 1:128.1.1esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)