PT-2023-4145 · Mozilla · Firefox

Artem Chaykin

·

Published

2023-07-04

·

Updated

2024-11-07

·

CVE-2023-37456

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 115
Description The issue is related to insufficient input validation, which can lead to a denial-of-service (DoS) attack by a remote attacker. Specifically, the session restore helper crashes when no parameter is sent to the message handler.
Recommendations For Firefox for iOS versions prior to 115, update to version 115 or later to resolve the issue. As a temporary workaround, consider restricting the use of the session restore helper until a patch is available.

Fix

RCE

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2023-04456
CVE-2023-37456

Affected Products

Firefox