CVE-2023-5171
27.09.2023, 15:19
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 118 |
mozilla | firefox_esr | 𝑥 < 115.3 |
mozilla | thunderbird | 𝑥 < 115.3 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
firefox-esr |
| ||||||||||||
thunderbird |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||
mozjs102 |
| ||||||||||||||||
mozjs38 |
| ||||||||||||||||
mozjs52 |
| ||||||||||||||||
mozjs68 |
| ||||||||||||||||
mozjs78 |
| ||||||||||||||||
mozjs91 |
| ||||||||||||||||
thunderbird |
|
Common Weakness Enumeration
References