CVE-2023-5724Uncontrolled Resource Consumption in Mozilla Firefox

Severity
7.5HIGHNVD
OSV4.3
EPSS
0.8%
top 25.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateNov 14

Description

Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified119
NVDmozilla/firefox< 119.0
CVEListV5mozilla/firefox_esrunspecified115.4
NVDmozilla/firefox_esr< 115.4
Ubuntumozilla/firefox< 119.0+build2-0ubuntu0.20.04.1

Also affects: Debian Linux 10.0, 11.0

🔴Vulnerability Details

6
OSV
firefox regressions2023-11-14
OSV
thunderbird vulnerabilities2023-11-02
OSV
firefox vulnerabilities2023-10-30
GHSA
GHSA-hhqg-994q-93m3: Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash2023-10-25
OSV
CVE-2023-5724: Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash2023-10-25

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-11-02
Ubuntu
Firefox vulnerabilities2023-10-30
Red Hat
Mozilla: Large WebGL draw could have led to a crash2023-10-24
Debian
CVE-2023-5724: firefox - Drivers are not always robust to extremely large draw calls and in some cases th...2023
Mozilla
Mozilla Foundation Security Advisory 2023-47: CVE-2023-5724
CVE-2023-5724 — Uncontrolled Resource Consumption | cvebase