Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-32206
HistoryMay 10, 2023 - 12:00 a.m.

CVE-2023-32206

2023-05-1000:00:00
ubuntu.com
ubuntu.com
12
cve-2023-32206
vulnerability
out-of-bound read
rlbox expat
firefox
thunderbird
firefox esr

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.4%

An out-of-bound read could have led to a crash in the RLBox Expat driver.
This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and
Thunderbird < 102.11.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfirefox< 113.0+build2-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchfirefox< 113.0+build2-0ubuntu0.20.04.1UNKNOWN
ubuntu18.04noarchmozjs38< anyUNKNOWN
ubuntu18.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs68< anyUNKNOWN
ubuntu22.04noarchmozjs78< anyUNKNOWN
ubuntu22.04noarchmozjs91< anyUNKNOWN
ubuntu18.04noarchthunderbird< 1:102.11.0+build1-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchthunderbird< 1:102.11.0+build1-0ubuntu0.20.04.1UNKNOWN
Rows per page:
1-10 of 131

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.4%