CERT-In Vulnerability Note
CIVN-2023-0076
Remote Code Execution Vulnerability in Mozilla Firefox
Original Issue Date:March 14, 2023
Severity Rating: HIGH
Software Affected
- Mozilla Firefox versions prior to 110.1.0 for Android
Overview
A vulnerability has been reported in Mozilla Firefox which could allow a remote attacker to perform arbitrary code execution on the targeted system.
Description
This vulnerability exists in Mozilla Firefox due to use-after-free error in libaudio when used on Android API below version 30. A remote attacker can exploit this vulnerability by persuading a victim to visit a specially crafted Web site.
Successful exploitation of this vulnerability could allow a remote attacker to perform arbitrary code execution on the targeted system.
Solution
- Upgrade to Mozilla Firefox version 110.1.0
Vendor Information
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2023-08/
References
Mozilla Firefox
https://www.mozilla.org/en-US/security/advisories/mfsa2023-08/
CVE Name
CVE-2023-25747
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|