First published: Tue Feb 04 2025(Updated: )
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <135 | |
Mozilla Firefox ESR | <115.20<128.7 | |
Mozilla Thunderbird | <128.7<135 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2343760 is classified as potentially high due to the risk of crashes and exploitation.
To fix REDHAT-BUG-2343760, update to the latest versions of Firefox, Firefox ESR, or Thunderbird as specified in the vulnerability description.
REDHAT-BUG-2343760 affects Firefox versions earlier than 135, Firefox ESR versions earlier than 115.20 and 128.7, and Thunderbird versions earlier than 128.7 and 135.
An attacker could exploit REDHAT-BUG-2343760 to cause a use-after-free vulnerability potentially leading to a crash.
Yes, patches for REDHAT-BUG-2343760 are included in the latest updates for the affected software.