CVE-2023-25733Unchecked Return Value in Mozilla Firefox

Severity
7.5HIGHNVD
OSV8.8
EPSS
0.3%
top 50.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19

Description

The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference. This vulnerability affects Firefox < 110.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/firefox< firefox 110.0-1 (sid)
CVEListV5mozilla/firefoxunspecified110
NVDmozilla/firefox< 110.0
Ubuntumozilla/firefox< 110.0+build3-0ubuntu0.18.04.1+3
mozillamozilla/firefox

🔴Vulnerability Details

4
GHSA
GHSA-v2f4-j72x-qfx5: The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference2023-06-19
OSV
firefox regressions2023-03-01
OSV
firefox vulnerabilities2023-02-20
OSV
CVE-2023-25733: The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference2023-02-15

📋Vendor Advisories

5
Ubuntu
Firefox regressions2023-03-01
Ubuntu
Firefox vulnerabilities2023-02-20
Red Hat
Mozilla: Possible null pointer dereference in TaskbarPreviewCallback2023-02-14
Debian
CVE-2023-25733: firefox - The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified whic...2023
Mozilla
Mozilla Foundation Security Advisory 2023-05: CVE-2023-25733