First published: Tue Feb 04 2025(Updated: )
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <135 | |
Mozilla Firefox ESR | <128.7 | |
Mozilla Thunderbird | <135<128.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2343748 is critical due to the potential for arbitrary code execution through memory safety bugs.
To fix REDHAT-BUG-2343748, update your Mozilla Firefox, Firefox ESR, and Thunderbird to the latest versions released by Mozilla.
REDHAT-BUG-2343748 affects Mozilla Firefox versions earlier than 135, Firefox ESR versions earlier than 128.7, and Thunderbird versions earlier than 135 and 128.7.
REDHAT-BUG-2343748 poses risks of memory corruption that could allow attackers to execute arbitrary code on affected systems.
There are no recommended workarounds for REDHAT-BUG-2343748; the best course of action is to apply the necessary updates.