An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1824892 | permissions required issue tracking vendor advisory |
https://security.gentoo.org/glsa/202312-03 | vendor advisory |
https://security.gentoo.org/glsa/202401-10 | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-16/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-17/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-18/ | vendor advisory |