MFSA-RESERVE-2025-1952465: Medium severity firefox esr vulnerability
A vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption.
Other sources
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of MFSA-RESERVE-2025-1952465?
The severity of MFSA-RESERVE-2025-1952465 is high due to the potential for out-of-bounds read access and memory corruption.
Which software is affected by MFSA-RESERVE-2025-1952465?
Affected software includes Firefox ESR up to version 128.10, Thunderbird ESR up to version 128.10, Firefox up to version 138, and Thunderbird up to version 138.
How do I fix MFSA-RESERVE-2025-1952465?
To fix MFSA-RESERVE-2025-1952465, update your Firefox or Thunderbird to versions 128.10 or 138, respectively.
What kind of vulnerability is MFSA-RESERVE-2025-1952465?
MFSA-RESERVE-2025-1952465 is a vulnerability related to XPath parsing that can cause undefined behavior due to missing null checks.
Can MFSA-RESERVE-2025-1952465 lead to user data exposure?
Yes, MFSA-RESERVE-2025-1952465 can potentially lead to memory corruption, which may expose user data.