Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-29531
HistoryJun 19, 2023 - 12:00 a.m.

CVE-2023-29531

2023-06-1900:00:00
ubuntu.com
ubuntu.com
9
webgl security vulnerability
out of bounds access
memory corruption
exploitable crash
firefox
thunderbird
macos
cve-2023-29531

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

57.5%

An attacker could have caused an out of bounds memory access using WebGL
APIs, leading to memory corruption and a potentially exploitable crash.
This bug only affects Firefox and Thunderbird for macOS. Other operating
systems are unaffected.
This vulnerability affects Firefox < 112, Firefox
ESR < 102.10, and Thunderbird < 102.10.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap
rodrigo-zaiden macOS issue only

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

57.5%