On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-firefox-esr | Aug 22, 2024 | Sep 11, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-client-thunderbirdgentoo-linux-upgrade-mail-client-thunderbird-bin | Feb 21, 2024 | Sep 11, 2023 | |
| Mfsa2023 34 | mozilla-firefox-upgrade-117_0 | Aug 30, 2023 | Aug 29, 2023 | |
| Mfsa2023 35 | mozilla-firefox-esr-upgrade-102_15 | Aug 30, 2023 | Aug 29, 2023 | |
| Mfsa2023 36 | mozilla-firefox-esr-upgrade-115_2 | Aug 30, 2023 | Aug 29, 2023 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-115_2 | Sep 5, 2023 | Aug 29, 2023 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Sep 6, 2023 | Sep 5, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub