PT-2023-2797 · Mozilla+3 · Firefox Esr+5

Dohyun Lee

·

Published

2023-04-11

·

Updated

2024-12-12

·

CVE-2023-29531

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 112 Firefox ESR versions prior to 102.10 Thunderbird versions prior to 102.10
Description An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. This issue affects Firefox and Thunderbird for macOS, with other operating systems being unaffected. The vulnerability may allow a remote attacker to execute arbitrary code by tricking the victim into visiting a specially crafted website, initiating a buffer overflow, and executing arbitrary code in the target system.
Recommendations For Firefox versions prior to 112, update to version 112 or later to resolve the issue. For Firefox ESR versions prior to 102.10, update to version 102.10 or later to resolve the issue. For Thunderbird versions prior to 102.10, update to version 102.10 or later to resolve the issue. As a temporary workaround, consider disabling the WebGL API until a patch is available. Restrict access to potentially vulnerable websites to minimize the risk of exploitation. Avoid using untrusted input data in the WebGL API to prevent buffer overflows.

Fix

UI Misrepresentation of Critical Information

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1621
ALT-PU-2023-1648
ALT-PU-2023-1649
ALT-PU-2023-1758
ALT-PU-2023-1765
ALT-PU-2023-1783
ALT-PU-2023-1797
ALT-PU-2023-1817
ALT-PU-2023-4365
ALT-PU-2023-4366
ALT-PU-2023-5202
BDU:2023-02695
BDU:2023-03004
CVE-2023-29531
OPENSUSE-SU-2024:12852-1
OPENSUSE-SU-2024:12856-1
OPENSUSE-SU-2024:12882-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2023:1817-1
SUSE-SU-2023:1819-1
SUSE-SU-2023:1855-1
SUSE-SU-2023:2064-1

Affected Products

Alt Linux
Firefox
Firefox Esr
Red Os
Suse
Thunderbird