CVE-2023-5724 — Uncontrolled Resource Consumption in Mozilla Firefox
Severity
7.5HIGHNVD
OSV4.3
EPSS
0.8%
top 25.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateNov 14
Description
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages9 packages
Also affects: Debian Linux 10.0, 11.0
🔴Vulnerability Details
6GHSA▶
GHSA-hhqg-994q-93m3: Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash↗2023-10-25
OSV▶
CVE-2023-5724: Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash↗2023-10-25
📋Vendor Advisories
7Debian▶
CVE-2023-5724: firefox - Drivers are not always robust to extremely large draw calls and in some cases th...↗2023