REDHAT-BUG-2367016: High severity firefox esr vulnerability
Published May 17, 2025
·Updated
An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object. This vulnerability affects Firefox ESR < 115.23.1.
Affected Software
1 affected component
Mozilla Firefox ESR<115.23.1
Event History
May 17, 2025
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2367016?
The severity of REDHAT-BUG-2367016 is categorized as moderate due to the potential for an attacker to exploit the out-of-bounds read or write.
2
How do I fix REDHAT-BUG-2367016?
To fix REDHAT-BUG-2367016, users should update their Firefox ESR to version 115.23.1 or later.
3
What versions of Firefox ESR are affected by REDHAT-BUG-2367016?
Firefox ESR versions lower than 115.23.1 are affected by REDHAT-BUG-2367016.
4
What type of vulnerability is REDHAT-BUG-2367016?
REDHAT-BUG-2367016 is an out-of-bounds read or write vulnerability affecting JavaScript Promise objects.
5
Who is the vendor responsible for REDHAT-BUG-2367016?
The vendor responsible for REDHAT-BUG-2367016 is Mozilla, the creator of Firefox ESR.