CVE-2023-6857 — Race Condition in Mozilla Firefox
Severity
5.3MEDIUMNVD
OSV4.3
EPSS
0.2%
top 59.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19
Latest updateJan 11
Description
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.
*This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6
Affected Packages9 packages
Also affects: Debian Linux 10.0, 11.0, 12.0
🔴Vulnerability Details
6CVEList▶
CVE-2023-6857: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary↗2023-12-19
GHSA▶
GHSA-8fq6-p869-285x: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary↗2023-12-19
📋Vendor Advisories
7Debian▶
CVE-2023-6857: firefox - When resolving a symlink, a race may occur where the buffer passed to `readlink`...↗2023