First published: Tue Oct 01 2024(Updated: )
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <131 | |
Firefox ESR | <128.3 | |
Thunderbird | <128.3<131 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2315945 is classified as a denial of service vulnerability that can crash the Firefox process.
To fix REDHAT-BUG-2315945, update Firefox, Firefox ESR, or Thunderbird to the latest versions beyond the affected versions.
REDHAT-BUG-2315945 affects Firefox versions below 131, Firefox ESR versions below 128.3, and Thunderbird versions below 128.3 and 131.
The potential impact of REDHAT-BUG-2315945 is a denial of service that can disrupt normal browser operations.
Currently, the best workaround for REDHAT-BUG-2315945 is to refrain from initiating WebTransport sessions until the software is updated.