First published: Tue Feb 04 2025(Updated: )
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <135 | |
Mozilla Firefox ESR | <115.20<128.7 | |
Mozilla Thunderbird | <128.7<135 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2343765 is high due to the potential for a use-after-free vulnerability.
To fix REDHAT-BUG-2343765, update your Firefox, Firefox ESR, or Thunderbird to the latest version available that addresses this vulnerability.
REDHAT-BUG-2343765 affects Firefox versions below 135, Firefox ESR versions below 115.20 and 128.7, and Thunderbird versions below 128.7 and 135.
The potential consequences of REDHAT-BUG-2343765 include possible arbitrary code execution and system instability due to a use-after-free condition.
There are no known effective workarounds for REDHAT-BUG-2343765, so updating to a patched version is recommended.