PT-2023-31880 · Mozilla+3 · Firefox+5

Sonakkbi

·

Publicado

2023-09-26

·

Atualizado

2024-12-12

·

CVE-2023-5168

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 118 Firefox ESR versions prior to 115.3 Thunderbird versions prior to 115.3
Description A compromised content process could have provided malicious data to FilterNodeD2D1 resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This bug only affects Firefox on Windows, with other operating systems being unaffected.
Recommendations For Firefox versions prior to 118, update to version 118 or later. For Firefox ESR versions prior to 115.3, update to version 115.3 or later. For Thunderbird versions prior to 115.3, update to version 115.3 or later.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-5908
ALT-PU-2023-5991
ALT-PU-2023-6200
ALT-PU-2023-6436
ALT-PU-2024-14035
ALT-PU-2024-3614
ALT-PU-2024-3860
ALT-PU-2024-4241
ALT-PU-2024-4748
CVE-2023-5168
OPENSUSE-SU-2023_3898-1
OPENSUSE-SU-2023_4016-1
OPENSUSE-SU-2024:13268-1
OPENSUSE-SU-2024:13272-1
OPENSUSE-SU-2024:13288-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2023:3837-1
SUSE-SU-2023:3898-1
SUSE-SU-2023:3899-1
SUSE-SU-2023:4016-1
SUSE-SU-2023_3837-1
SUSE-SU-2023_3898-1
SUSE-SU-2023_3899-1

Produtos afetados

Alt Linux
Astra Linux
Firefox
Firefox Esr
Suse
Thunderbird