CVE-2023-3600Use After Free in Mozilla Firefox

CWE-416Use After Free12 documents9 sources
Severity
8.8HIGHNVD
EPSS
0.2%
top 60.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateOct 3

Description

During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified115.0.2
NVDmozilla/firefox< 115.0.2
CVEListV5mozilla/firefox_esrunspecified115.0.2
NVDmozilla/firefox_esr< 115.0.2
Ubuntumozilla/firefox< 115.0.2+build1-0ubuntu0.20.04.1

🔴Vulnerability Details

4
OSV
thunderbird vulnerabilities2023-10-03
OSV
CVE-2023-3600: During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash2023-07-12
GHSA
GHSA-f7m4-v8xh-mj88: During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash2023-07-12
CVEList
Use-after-free in workers2023-07-12

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-10-03
Ubuntu
Firefox vulnerability2023-07-12
Microsoft
During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.22023-07-11
Red Hat
firefox: use-after-free in workers2023-07-11
Debian
CVE-2023-3600: firefox - During the worker lifecycle, a use-after-free condition could have occurred, whi...2023
CVE-2023-3600 — Use After Free in Mozilla Firefox | cvebase