CVE-2023-49061
Es bestehen mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird. Diese Fehler bestehen in mehreren Komponenten wie dem WebGL2 blitFramebuffer oder dem MessagePort::Entangled, unter anderem aufgrund eines unzulässigen Speicherzugriffs, eines use-after-free, eines fehlerhaften Parsings von relativen URLs und Fehlern in der Speichersicherheit. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.20% · 41.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IGEL | IGEL OS | |
| Amazon | Amazon Linux 2 | |
| Ubuntu | Ubuntu Linux | |
| Fedora | Fedora Linux | |
| SUSE | SUSE openSUSE | |
| Mozilla | Mozilla Firefox ESR <115.5 | |
| Oracle | Oracle Linux | |
| SUSE | SUSE Linux | |
| Mozilla | Mozilla Firefox <120 | |
| Mozilla | Mozilla Thunderbird <115.5.0 | |
| Gentoo | Gentoo Linux | |
| Debian | Debian Linux | |
| Red Hat | Red Hat Enterprise Linux |
Timeline
- Nov 21, 2023 CVE Published
- Nov 22, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Jan 21, 2024 EPSS Score
- Feb 20, 2024 EPSS Score
- Mar 21, 2024 EPSS Score
- Apr 20, 2024 EPSS Score
- May 20, 2024 EPSS Score
- Jun 19, 2024 EPSS Score
- Jul 18, 2024 EPSS Score
- Aug 17, 2024 EPSS Score
- Sep 16, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2995.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2995 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-49/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-50/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-51/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-52/ advisory
- https://lists.debian.org/debian-security-announce/2023/msg00257.html advisory
- https://ubuntu.com/security/notices/USN-6509-1 advisory
- https://lists.debian.org/debian-lts-announce/2023/11/msg00017.html advisory
- https://ubuntu.com/security/notices/USN-6515-1 advisory
- https://lists.debian.org/debian-security-announce/2023/msg00262.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-bb021a4854 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-985a025a03 advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-November/017238.html advisory
- https://access.redhat.com/errata/RHSA-2023:7512 advisory
- https://access.redhat.com/errata/RHSA-2023:7511 advisory
- https://access.redhat.com/errata/RHSA-2023:7510 advisory
- https://access.redhat.com/errata/RHSA-2023:7509 advisory
- https://access.redhat.com/errata/RHSA-2023:7508 advisory
- https://access.redhat.com/errata/RHSA-2023:7507 advisory
…and 31 more