First published: Tue Apr 29 2025(Updated: )
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.10 and Thunderbird ESR < 128.10.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox ESR | <128.10 | |
Thunderbird | <128.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2362915 is considered high due to evidence of memory corruption that could potentially allow for arbitrary code execution.
To fix REDHAT-BUG-2362915, update to Firefox ESR 128.10 and Thunderbird ESR 128.10 or later.
Firefox ESR versions lower than 128.10 and Thunderbird ESR versions lower than 128.10 are affected by REDHAT-BUG-2362915.
There are no recommended workarounds for REDHAT-BUG-2362915; the best action is to apply the update.
While exploitation of REDHAT-BUG-2362915 is not confirmed, the evidence of memory corruption suggests that it could potentially be exploited with sufficient effort.