Mozilla FireFox Security Updates – 12 April 2023

Mozilla has released security updates to fix vulnerabilities in Firefox 112, and Firefox ESR 102.10.

The addressed vulnerabilities could allow the remote attacker to gain access, obtain sensitive information, conduct a spoofing attack, bypass security restrictions, and cause a denial of service attack on the affected products.

Sample of the addressed vulnerabilities:

1- Mozilla Firefox Security Bypass Vulnerability (CVE-2023-29550):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2- Mozilla Firefox Code Execution Vulnerability (CVE-2023-29551):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities
  •  CVE-2023-29531
  • CVE-2023-29532
  • CVE-2023-29533
  • CVE-2023-29534
  • CVE-2023-29535
  • CVE-2023-29536
  • CVE-2023-29537
  • CVE-2023-29538
  • CVE-2023-29539
  • CVE-2023-29540
  • CVE-2023-29541
  • CVE-2023-29542
  • CVE-2023-29543
  • CVE-2023-29544
  • CVE-2023-29545
  • CVE-2023-29546
  • CVE-2023-29547
  • CVE-2023-29548
  • CVE-2023-29549
  • CVE-2023-29550
  • CVE-2023-29551
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

References