First published: Tue Feb 04 2025(Updated: )
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <135 | |
Mozilla Firefox ESR | <115.20<128.7 | |
Mozilla Thunderbird | <128.7<135 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2343750 is classified as potentially exploitable due to a use-after-free vulnerability.
To fix REDHAT-BUG-2343750, update to Mozilla Firefox version 135 or later, Firefox ESR version 115.20 or later, or Thunderbird version 128.7 or later.
REDHAT-BUG-2343750 affects Firefox versions below 135, Firefox ESR versions below 115.20 and 128.7, and Thunderbird versions below 128.7 and 135.
The potential risks of REDHAT-BUG-2343750 include application crashes and the possibility of remote code execution due to the use-after-free vulnerability.
Currently, the best approach is to immediately update the affected software since there are no documented workarounds for REDHAT-BUG-2343750.