PT-2023-6803 · Mozilla+9 · Firefox+11

Lukas Bernhard

·

Published

2023-09-26

·

Updated

2025-03-14

·

CVE-2023-5171

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 118 Firefox ESR versions prior to 115.3 Thunderbird versions prior to 115.3
Description The issue is related to a use-after-free condition that could occur during Ion compilation due to Garbage Collection, potentially allowing an attacker to write two NUL bytes and cause a crash. This could result in a denial of service.
Recommendations For Firefox versions prior to 118, update to version 118 or later. For Firefox ESR versions prior to 115.3, update to version 115.3 or later. For Thunderbird versions prior to 115.3, update to version 115.3 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:5434
ALSA-2023:5435
ALT-PU-2023-5908
ALT-PU-2023-5991
ALT-PU-2023-6200
ALT-PU-2023-6436
ALT-PU-2024-13898
ALT-PU-2024-14035
ALT-PU-2024-3614
ALT-PU-2024-3860
ALT-PU-2024-4241
ALT-PU-2024-4748
BDU:2023-07671
CESA-2023_5428
CESA-2023_5433
CVE-2023-5171
DLA-3587-1
DLA-3601-1
DSA-5506-1
DSA-5513-1
MGASA-2023-0285
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2023_3898-1
OPENSUSE-SU-2023_4016-1
OPENSUSE-SU-2024:13268-1
OPENSUSE-SU-2024:13272-1
OPENSUSE-SU-2024:13288-1
OPENSUSE-SU-2024:14572-1
RHSA-2023:5426
RHSA-2023:5427
RHSA-2023:5428
RHSA-2023:5429
RHSA-2023:5430
RHSA-2023:5432
RHSA-2023:5433
RHSA-2023:5434
RHSA-2023:5435
RHSA-2023:5436
RHSA-2023:5437
RHSA-2023:5438
RHSA-2023:5439
RHSA-2023:5440
RHSA-2023:5475
RHSA-2023:5477
RHSA-2023_5428
RHSA-2023_5433
RHSA-2023_5434
RHSA-2023_5435
RHSA-2023_5475
RHSA-2023_5477
RLSA-2023:5428
RLSA-2023:5435
ROSA-SA-2024-2371
SUSE-SU-2023:3837-1
SUSE-SU-2023:3898-1
SUSE-SU-2023:3899-1
SUSE-SU-2023:4016-1
USN-6404-1
USN-6404-2
USN-6405-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Suse
Thunderbird
Ubuntu