Mozilla FireFox Security Updates – 13 September 2023

Mozilla has released an updated Firefox version 117.0.1, Firefox ESR versions 115.2.1, and 102.15.1 to fix a zero-day vulnerability exploited in the wild.

The addressed vulnerability could allow the remote attacker to exploit it through a malicious WebP image, when the victim opens the compromised image it could trigger a heap buffer overflow within the content process, potentially leading to arbitrary code execution or system compromise.

Mozilla Heap Buffer Overflow Vulnerability in Libwebp (CVE-2023-4863):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities

CVE-2023-4863

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox Security Advisory

References