Mozilla FireFox Security Update – 01 October 2023

Mozilla has released an updated Firefox version 118.0.1, and Firefox ESR version 115.3.1 to fix a zero-day vulnerability exploited in the wild.

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website.

Mozilla Firefox Heap Buffer Overflow Vulnerability in libvpx (CVE-2023-5217):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities

CVE-2023-5217

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox Security Advisory

References