Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-29536
HistoryApr 12, 2023 - 12:00 a.m.

CVE-2023-29536

2023-04-1200:00:00
ubuntu.com
ubuntu.com
16
memory manager
pointer freeing
exploitable crash
firefox
focus for android
firefox esr
thunderbird
mozilla
javascript engine
ubuntu
snap package
vulnerability
memory corruption

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.5%

An attacker could cause the memory manager to incorrectly free a pointer
that addresses attacker-controlled memory, resulting in an assertion,
memory corruption, or a potentially exploitable crash. This vulnerability
affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10,
Firefox for Android < 112, and Thunderbird < 102.10.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfirefox< 112.0+build2-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchfirefox< 112.0+build2-0ubuntu0.20.04.1UNKNOWN
ubuntu22.04noarchmozjs102< 102.11.0-0ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchmozjs102< 102.11.0-0ubuntu0.22.10.1UNKNOWN
ubuntu23.04noarchmozjs102< 102.11.0-0ubuntu0.23.04.1UNKNOWN
ubuntu18.04noarchmozjs38< anyUNKNOWN
ubuntu18.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs68< anyUNKNOWN
ubuntu22.04noarchmozjs78< anyUNKNOWN
Rows per page:
1-10 of 151

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.5%