CVE-2023-25738
published 2023-06-02CVE-2023-25738: Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.64%
46.8th percentile
Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 110.0 | 110.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 110 | 110 |
| mozilla | firefox_esr | < 102.8 | 102.8 |
| mozilla | firefox_esr | >= unspecified < 102.8 | 102.8 |
| mozilla | thunderbird | < 102.8 | 102.8 |
| mozilla | thunderbird | >= unspecified < 102.8 | 102.8 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Printing on Windows could potentially crash Firefox with some device drivers
vendor_redhat·2023-02-14·CVSS 6.5
CVE-2023-25738 [MEDIUM] CWE-119 Mozilla: Printing on Windows could potentially crash Firefox with some device drivers
Mozilla: Printing on Windows could potentially crash Firefox with some device drivers
Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
The Mozilla Foundation Security Advisory describes this flaw as:
Members of the `DEVMODEW` struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.
*This bug only affects Firefo
Debian
CVE-2023-25738: firefox - Members of the <code>DEVMODEW</code> struct set by the printer device driver wer...
vendor_debian·2023·CVSS 6.5
CVE-2023-25738 [MEDIUM] CVE-2023-25738: firefox - Members of the <code>DEVMODEW</code> struct set by the printer device driver wer...
Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-05: CVE-2023-25738
vendor_mozilla·CVSS 6.5
CVE-2023-25738 [MEDIUM] Mozilla Foundation Security Advisory 2023-05: CVE-2023-25738
Mozilla Foundation Security Advisory 2023-05
CVE: CVE-2023-25738
Product: Firefox
Impact: high
Fixed in: Firefox 110
Mozilla
Mozilla Foundation Security Advisory 2023-07: CVE-2023-25738
vendor_mozilla·CVSS 6.5
CVE-2023-25738 [MEDIUM] Mozilla Foundation Security Advisory 2023-07: CVE-2023-25738
Mozilla Foundation Security Advisory 2023-07
CVE: CVE-2023-25738
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.8
Mozilla
Mozilla Foundation Security Advisory 2023-06: CVE-2023-25738
vendor_mozilla·CVSS 6.5
CVE-2023-25738 [MEDIUM] Mozilla Foundation Security Advisory 2023-06: CVE-2023-25738
Mozilla Foundation Security Advisory 2023-06
CVE: CVE-2023-25738
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.8
GHSA
GHSA-5wxj-v52j-4fmh: Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would
ghsa_unreviewed·2023-06-02
CVE-2023-25738 [MEDIUM] CWE-125 GHSA-5wxj-v52j-4fmh: Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would
Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1811852https://www.mozilla.org/security/advisories/mfsa2023-05/https://www.mozilla.org/security/advisories/mfsa2023-06/https://www.mozilla.org/security/advisories/mfsa2023-07/https://bugzilla.mozilla.org/show_bug.cgi?id=1811852https://www.mozilla.org/security/advisories/mfsa2023-05/https://www.mozilla.org/security/advisories/mfsa2023-06/https://www.mozilla.org/security/advisories/mfsa2023-07/https://bugzilla.mozilla.org/show_bug.cgi?id=1811852
2023-06-02
Published