CVE-2023-25738
Summary
| CVE | CVE-2023-25738 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-02 17:15:00 UTC |
| Updated | 2023-06-08 16:10:00 UTC |
| Description | Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377975 Mozilla Firefox Multiple Vulnerabilities (MFSA2023-05)
- 377976 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2023-06)
- 377993 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2023-07)
- 503455 Alpine Linux Security Update for firefox-esr
- 506063 Alpine Linux Security Update for firefox-esr
- 710735 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202305-36)
- 710739 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202305-35)
- 753724 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:0461-1)
- 753729 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:0466-1)
- 753731 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:0469-1)
- 754204 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:0469-1)