Lucene search

K
vulnrichmentMozillaVULNRICHMENT:CVE-2023-4573
HistorySep 11, 2023 - 7:59 a.m.

CVE-2023-4573

2023-09-1107:59:57
mozilla
github.com
1
rendering data
mstream
use-after-free
potentially exploitable
crash
firefox
thunderbird
vulnerability

AI Score

6.3

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*"
    ],
    "vendor": "mozilla",
    "product": "firefox",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "117",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:mozilla:firefox_esr:-:*:*:*:*:*:*:*"
    ],
    "vendor": "mozilla",
    "product": "firefox_esr",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "102.15",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "0",
        "lessThan": "115.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:mozilla:thunderbird:-:*:*:*:*:*:*:*"
    ],
    "vendor": "mozilla",
    "product": "thunderbird",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "102.15",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "0",
        "lessThan": "115.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]