REDHAT-BUG-2362904: Medium severity firefox vulnerability
A vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird ESR < 128.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2362904?
The severity of REDHAT-BUG-2362904 is critical due to the potential for memory corruption and out-of-bounds read access.
How do I fix REDHAT-BUG-2362904?
To fix REDHAT-BUG-2362904, upgrade to Firefox version 138 or higher, Firefox ESR version 128.10 or higher, or equivalent updates for Thunderbird.
Which versions are affected by REDHAT-BUG-2362904?
REDHAT-BUG-2362904 affects Firefox versions below 138, Firefox ESR versions below 128.10, and their corresponding Thunderbird versions.
What types of products are impacted by REDHAT-BUG-2362904?
REDHAT-BUG-2362904 affects Mozilla Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR.
What are the potential risks associated with REDHAT-BUG-2362904?
The potential risks include undefined behavior that could lead to memory corruption, which may expose or compromise user data.