Impact
The vulnerability is a use‑after‑free flaw located in the audio/video component of Mozilla products. The flaw permits an attacker to free memory and later reference that same memory, potentially corrupting data in the application’s memory. The description does not specify a concrete exploitation outcome, but use‑after‑free is intrinsically capable of affecting program stability and behavior. Based on typical use‑after‑free exploitation patterns, it is inferred that an attacker could supply crafted media content to trigger the flaw.
Affected Systems
Susceptible builds include Mozilla Firefox versions earlier than 155, as well as the ESR153.2, and Mozilla Thunderbird versions earlier than 155, including the ESR releases before 140.15 and 153.2. Only releases 155 and newer (or ESR 140.15/153.2) contain the fix.
Risk and Exploitability
The CVSS score of 5. of < 1% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker delivering crafted media content that causes the application to free and subsequently access deallocated memory. Exact conditions for exploitation are not detailed, but the use‑after‑free weakness could lead to memory corruption and potential execution of arbitrary code if a suitable attacker-controlled payload is produced.
OpenCVE Enrichment
Debian DLA
Debian DSA