Back

MEDIUM

Mozilla: Potential out-of-bounds when accessing throttled streams

Published Jun 2, 2023

Description

When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jun 2, 2023
Updated Jan 9, 2025
Reserved Feb 13, 2023
CISA Vulnrichment
Updated Jan 9, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 14, 2023
ENISA EUVD
Assigner mozilla
Published Jun 2, 2023
Updated Jan 9, 2025
Exploited since n/a
EUVD-2023-29659