MFSA-RESERVE-2025-3: Medium severity firefox vulnerability
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of MFSA-RESERVE-2025-3?
The severity is considered high due to potential memory corruption that could allow execution of arbitrary code.
How do I fix MFSA-RESERVE-2025-3?
To fix MFSA-RESERVE-2025-3, update to Firefox version 138 or Thunderbird versions 128.10 or 138.
What products are affected by MFSA-RESERVE-2025-3?
Affected products include Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird ESR 128.9.
What types of issues are associated with MFSA-RESERVE-2025-3?
MFSA-RESERVE-2025-3 is associated with memory safety bugs that may lead to memory corruption.
Can MFSA-RESERVE-2025-3 be exploited?
Yes, with sufficient effort, some memory safety bugs in MFSA-RESERVE-2025-3 could potentially be exploited.