CVE-2023-4577Uncontrolled Resource Consumption in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.1%
top 72.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateOct 3

Description

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified117
NVDmozilla/firefox< 117.0
CVEListV5mozilla/firefox_esrunspecified115.2
NVDmozilla/firefox_esr< 115.2
CVEListV5mozilla/thunderbirdunspecified115.2

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2023-10-03
GHSA
GHSA-fm7w-6qfv-w35j: When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which2023-09-11
OSV
CVE-2023-4577: When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which2023-09-11
CVEList
Memory corruption in JIT UpdateRegExpStatics2023-09-11
OSV
firefox vulnerabilities2023-08-30

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-10-03
Ubuntu
Firefox vulnerabilities2023-08-30
Red Hat
Mozilla: Memory corruption in JIT UpdateRegExpStatics2023-08-29
Debian
CVE-2023-4577: firefox - When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could alre...2023
Mozilla
Mozilla Foundation Security Advisory 2023-38: CVE-2023-4577
CVE-2023-4577 — Uncontrolled Resource Consumption | cvebase