CERT-In Vulnerability Note
CIVN-2023-0378
Multiple Vulnerabilities in Mozilla Firefox
Original Issue Date:December 21, 2023
Severity Rating: HIGH
Software Affected
- Mozilla Firefox versions prior to 121
Overview
Multiple vulnerabilities have been reported in Mozilla Firefox which could allow a remote attacker to perform remote code execution, Information Disclosure, security restriction bypass and cause denial of service condition on the targeted system.
Description
These vulnerabilities exist in Mozilla Firefox due to Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with Mesa VM driver, NSS susceptible to "Minerva" attack, Potential exposure of uninitialized data in EncryptingOutputStream, Symlinks may resolve to smaller than expected buffers, Heap buffer overflow in nsTextFragment, Use-after-free in PR_GetIdentitiesLayer, TypedArrays lack sufficient exception handling, Potential sandbox escape due to VideoBridge lack of texture validation, Clickjacking permission prompts using the popup transition, Heap buffer overflow affected nsWindow::PickerOpen(void) in headless mode, WebPush requests on Firefox for Android did not require VAPID key, Content can paint outside of sandboxed iframe, Android Toast notifications may obscure fullscreen event notifications, Lack of protocol handler warning in some instances, Browsing history leaked to syslogs via GNOME, Undefined behavior in ShutdownObserver() and Memory safety bugs. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially-crafted Web site.
Successful exploitation of these vulnerabilities could allow a remote attacker to perform remote code execution, Information Disclosure, security restriction bypass and cause denial of service condition on the targeted system.
Solution
Apply appropriate fixes issued by the vendor:
https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/
Vendor Information
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/
CVE Name
CVE-2023-6135
CVE-2023-6856
CVE-2023-6857
CVE-2023-6858
CVE-2023-6859
CVE-2023-6860
CVE-2023-6861
CVE-2023-6863
CVE-2023-6864
CVE-2023-6865
CVE-2023-6866
CVE-2023-6867
CVE-2023-6868
CVE-2023-6869
CVE-2023-6870
CVE-2023-6871
CVE-2023-6872
CVE-2023-6873
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|