Impact
Memory safety bugs were found in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. The bugs caused memory corruption and could, with sufficient effort, allow arbitrary code execution. The issue is a classic buffer overrun vulnerability (CWE-119).
Affected Systems
Mozilla Firefox and Thunderbird. Vulnerable releases are Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. The vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144 and Thunderbird ESR 140.4.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score of less than 1% means that the likelihood of exploitation observed in the wild is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. The exploitation path would likely involve a malicious webpage or content that triggers the buffer overrun, leading to arbitrary code execution at the surface level of the browser or mail client.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN