UBUNTU-CVE-2023-4575
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-4575
UBUNTU-CVE-2023-4575
Summary:
Details: When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
References: https://ubuntu.com/security/CVE-2023-4575, https://ubuntu.com/security/notices/USN-6320-1, https://ubuntu.com/security/notices/USN-6368-1, https://www.cve.org/CVERecord?id=CVE-2023-4575
Affected packages
Package
Name: mozjs52
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
