Mozilla FireFox Security Updates 15 February 2023

Mozilla has released security updates to fix vulnerabilities in Firefox 110 and Firefox ESR 102.8.

The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform spoofing attacks, bypass security restrictions, execute arbitrary code, or cause a denial of service attack on the affected products.

Sample of the addressed vulnerabilities:

1. Mozilla Firefox Weak Security (CVE-2023-25737):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Gain Access

2. Mozilla Firefox Code Execution (CVE-2023-25745):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Gain Access

Vulnerabilities
  • CVE-2023-25728
  • CVE-2023-25730
  • CVE-2023-25743
  • CVE-2023-0767
  • CVE-2023-25735
  • CVE-2023-25737
  • CVE-2023-25738
  • CVE-2023-25739
  • CVE-2023-25729
  • CVE-2023-25732
  • CVE-2023-25734
  • CVE-2023-25742
  • CVE-2023-25744
  • CVE-2023-25746
  • CVE-2023-25740
  • CVE-2023-25731
  • CVE-2023-25733
  • CVE-2023-25736
  • CVE-2023-25741
  • CVE-2023-25745
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox 110 Security Advisory

Mozilla Firefox ESR 102.8 Security Advisory

References