Vulnerability CVE-2023-4573: Information

Description

When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Published: Sept. 11, 2023
Modified: Sept. 13, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus117.0-alt1125.0.2-alt1ALT-PU-2023-5213-2328245Fixed
firefoxsisyphus_riscv64117.0.1-alt0.port124.0.1-alt0.portALT-PU-2023-5803-1-Fixed
firefoxp10118.0.2-alt0.p10.1118.0.2-alt0.p10.1ALT-PU-2024-4241-4342418Fixed
firefox-esrsisyphus115.2.1-alt1115.10.0-alt1ALT-PU-2023-5754-2329883Fixed
firefox-esrp10115.3.1-alt4115.10.0-alt1ALT-PU-2023-6436-2330014Fixed
firefox-esrc10f1115.8.0-alt0.c10.1115.9.1-alt0.c10.1ALT-PU-2024-3614-2340631Fixed
thunderbirdsisyphus115.2.2-alt1115.9.0-alt1ALT-PU-2023-5836-3328494Fixed
thunderbirdp10115.8.1-alt1115.9.0-alt1ALT-PU-2024-3860-2342581Fixed
thunderbirdc10f1115.8.1-alt0.c10.1115.9.0-alt0.c10.1ALT-PU-2024-4748-2343092Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      End excliding
      115.2

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      Start including
      115.0
      End excliding
      115.2

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      End excliding
      102.15

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      117.0