Impact
The vulnerability results from incorrect boundary conditions in the Audio/Video: GMP component, causing a buffer overflow that can corrupt the application’s memory. An attacker who can supply malicious audio or video data may exploit the flaw to execute arbitrary code, representing high risk if the vulnerability is triggered.
Affected Systems
Mozilla Firefox versions up to 152, and all older ESR releases before 115.38 and 140.13, are vulnerable, as are Mozilla Thunderbird versions up to 152 and ESR releases before 140.13. The fix is included in Firefox 153 and newer, including ESR 115.38 and ESR 140.13, and in Thunderbird 153 and newer, including ESR 140.13.
Risk and Exploitability
The CVSS score of 9.1 signifies critical severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. This vulnerability is not listed in CISA’s KEV catalog, so there is no known exploitation. The most probable exploit scenario involves the application processing malicious audio or video content—such as crafted files or streams—supplied by an attacker, which can lead to remote code execution when the flaw is triggered.
OpenCVE Enrichment
Debian DLA
Debian DSA